Skip to content

Open nowPosted 10 hours ago

Forward Deployed Security Automation Engineer

TENEX.AI42 open roles

Where
San Jose, CA
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowForward Deployed Security Automation EngineerTENEX.AI · San Jose, CA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on TENEX.AI's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. TENEX.AI postings stay open a median of 25 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 10 hours ago

TENEX.AI median: 25 days open

The posting

COMPANY OVERVIEW:

TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape.

We’re a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you’ll play a meaningful role in defining and building our culture. Get in on the ground floor. We’re a small but well-funded team that just raised a substantial round – joining now comes with limited risk and unlimited upside.

Culture is one of the most important things at TENEX.AI http://TENEX.AI—explore our culture deck at culture.tenex.ai http://culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in-person work.

Reporting to Software Engineering, the Forward Deployed Security Automation Engineer owns the integration layer between our AI agents and the security platforms they work with. You will deploy and maintain SIEM, SOAR, and EDR environments across a wide range of vendors, and build the software, automated response workflows, and internal tooling that connect them.

Location: San Jose, CA or Overland Park, KS. We will require 4 days onsite M-TH.

You will:

- Operate security platforms across vendors: Deploy, configure, and maintain sandboxes of SIEM, SOAR, and EDR environments across vendors such as CrowdStrike, SentinelOne, Microsoft Defender, Splunk, Microsoft Sentinel, and Google SecOps. Manage prevention policies, host groups, custom IOAs, and exclusions on EDR platforms, detection content on SIEM platforms, and connectors on SOAR platforms.

- Resolve platform issues: Troubleshoot and resolve EDR agent problems across our environments, managing performance impacts, kernel or driver conflicts, upgrade rollouts, and false positive tuning.

- Build production software: Develop, test, and deploy production Python services (not just scripts). Manage the full lifecycle including APIs, workers, queues, tests, CI, and containers.

- Automate detection and response: Partner with other teams in engineering to build automated containment or remediation workflows, including host isolation, process kills, file quarantine, account disabling, and ticket creation.

- Design safety guardrails: Architect strict guardrails on automated response actions—this is the strongest signal of success in the role. You will build approval thresholds, allow lists for critical hosts, rate limits on isolation actions, audit trails, and safe release or rollback paths.

- Own the platform in production: Take end-to-end ownership of the platform's reliability and latency outcomes (such as time from alert to containment), and participate in the on-call rotation for security tooling.

- Build internal tooling: Create and maintain tools utilized by other teams, ensuring they are observable by debugging your own software with logging, metrics, or alerting you put in place.

Requirements:

- Deep, hands-on experience operating multiple SIEM/SOAR/EDR platforms

- Proven software engineering experience building and maintaining production Python services and APIs.

- Experience integrating with complex vendor APIs and managing auth, rate limits, and retries.

- Demonstrated experience building automated detection and response workflows with carefully designed safety guardrails.

- Track record of taking end-to-end production ownership of a platform, rather than just a component.

Nice-to-haves:

- Experience managing multi-tenant EDR structures

- Proficiency in Go and/or Python

- Detection-as-code experience (rules in version control, testing, CI deployment).

- Background working at MDR/MSSP providers, SOAR vendors, EDR vendor engineering teams, or on the detection and response teams of security-mature technology companies.

EDUCATION & CERTIFICATIONS

- Bachelor’s or Master’s degree in Computer Science, Engineering, or a related field.

- Relevant certifications (AWS/GCP Professional Engineer, Kubernetes, or security-related credentials) are a plus.

Why Join Us?

- Opportunity to work with cutting-edge AI-driven cybersecurity technologies and Google SecOps solutions.

- Collaborate with a talented and innovative team focused on continuously improving security operations.

- Competitive salary and benefits package.

- A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.

If you're passionate about combining cybersecurity expertise with artificial intelligence and have experience with Google SecOps and Chronicle, we encourage you to apply!

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against TENEX.AI's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on TENEX.AI's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    TENEX.AI's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.