Purple Team - Lead Cloud Security Engineer

TENEX.AIOverland Park, KS
Onsite

About The Position

TENEX runs an Adversary Research Team that studies how real attackers operate and turns that into stronger detection and response for our customers. As Lead Security Engineer on the purple team, you sit with that team and close the loop between offense and defense. You will emulate current adversary techniques against our detection stack, measure how well we catch and respond to them, and feed the gaps back into detection engineering and the SOC. This is a hands-on role for someone equally comfortable on the red side, building and running emulations, and on the blue side, reading telemetry and writing detections.

Requirements

  • 7+ years in offensive security, detection engineering, or a blend of the two, with hands-on purple team or adversary emulation experience.
  • Strong red-side skills: adversary tradecraft, command and control, evasion, and building emulation plans that reflect how real intrusions unfold.
  • Strong blue-side skills: writing and tuning detections and analyzing endpoint, network, and cloud telemetry in a SIEM or EDR.
  • Ability to measure detection effectiveness and communicate results clearly to engineers, analysts, and leadership.

Nice To Haves

  • Experience with emulation and purple team tooling (Caldera, Atomic Red Team, Prelude, Scythe, or similar).
  • Experience in an MDR/MSSP or high-growth startup environment.
  • Detection content development or threat-hunting background.

Responsibilities

  • Identify and address gaps. Find where coverage falls short, research and design detection use-cases to close it, and validate through testing where that is merited.
  • Detection engineering research. Where public detection research is thin or nonexistent, develop detection strategies from scratch for high-blast-radius technologies, crown-jewel systems, and areas of high risk or exposure.
  • Adversary research. Track the actors, malware, and tooling active against our customers’ verticals, and dissect their tradecraft down to the behaviors that matter for detection and emulation.
  • Adversary emulation. Design and recreate real attacks to test and validate detections and controls. Use the outcomes to improve detections and tooling in customer environments.
  • Track and report results. Develop reporting that gives leadership and customers a straight answer on where our defenses stand.

Benefits

  • Competitive salary and benefits package.
  • A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service