Forward Deployed Security Automation Engineer

TENEX.AI•San Jose, CA
•Hybrid

About The Position

TENEX is seeking a Forward Deployed Security Automation Engineer to join their team. This role focuses on the integration layer between AI agents and security platforms. The engineer will be responsible for deploying and maintaining SIEM, SOAR, and EDR environments across various vendors, and developing software, automated response workflows, and internal tooling to connect them. As an early employee in a rapidly growing, well-funded startup, this position offers the opportunity to significantly impact the company's culture and direction.

Requirements

  • Deep, hands-on experience operating multiple SIEM/SOAR/EDR platforms
  • Proven software engineering experience building and maintaining production Python services and APIs.
  • Experience integrating with complex vendor APIs and managing auth, rate limits, and retries.
  • Demonstrated experience building automated detection and response workflows with carefully designed safety guardrails.
  • Track record of taking end-to-end production ownership of a platform, rather than just a component.

Nice To Haves

  • Experience managing multi-tenant EDR structures
  • Proficiency in Go and/or Python
  • Detection-as-code experience (rules in version control, testing, CI deployment).
  • Background working at MDR/MSSP providers, SOAR vendors, EDR vendor engineering teams, or on the detection and response teams of security-mature technology companies.

Responsibilities

  • Operate security platforms across vendors: Deploy, configure, and maintain SIEM, SOAR, and EDR environments across vendors such as CrowdStrike, SentinelOne, Microsoft Defender, Splunk, Microsoft Sentinel, and Google SecOps. Manage prevention policies, host groups, custom IOAs, and exclusions on EDR platforms, detection content on SIEM platforms, and connectors on SOAR platforms.
  • Resolve platform issues: Troubleshoot and resolve EDR agent problems across environments, managing performance impacts, kernel or driver conflicts, upgrade rollouts, and false positive tuning.
  • Build production software: Develop, test, and deploy production Python services. Manage the full lifecycle including APIs, workers, queues, tests, CI, and containers.
  • Automate detection and response: Partner with other teams in engineering to build automated containment or remediation workflows, including host isolation, process kills, file quarantine, account disabling, and ticket creation.
  • Design safety guardrails: Architect strict guardrails on automated response actions, including approval thresholds, allow lists for critical hosts, rate limits on isolation actions, audit trails, and safe release or rollback paths.
  • Own the platform in production: Take end-to-end ownership of the platform's reliability and latency outcomes, and participate in the on-call rotation for security tooling.
  • Build internal tooling: Create and maintain tools utilized by other teams, ensuring they are observable by debugging your own software with logging, metrics, or alerting.

Benefits

  • Competitive salary and benefits package.
  • A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service