SOC Engineer

TENEX.AI

Overland Park (KS)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TENEX.AI, based in Overland Park, Kansas, is seeking a skilled expert in Managed Detection and Response (MDR). The role involves leading complex incident responses, assessing telemetry quality, and supporting automation initiatives. A strong background in security operations, cloud security, and scripting expertise is essential.

Join a rapidly growing team dedicated to revolutionizing cybersecurity through advanced threat detection and response, backed by industry-leading investors.

Qualifications

  • 5+ years in security operations, incident response, or detection engineering.
  • Strong fluency in logging and telemetry evaluation.
  • Hands-on experience with SIEM platforms.
  • Solid understanding of response automation.
  • Working knowledge of cloud security architecture.
  • Scripting proficiency in Python or PowerShell.
  • Familiarity with AI or LLM-based security workflows.
  • Clear communication with technical and non-technical audiences.

Responsibilities

  • Handle complex incident response and escalation.
  • Assess and improve telemetry and logging coverage.
  • Ensure SIEM and detection quality.
  • Contribute to response automation quality.
  • Support technical needs across the organization.
  • Improve SOC tooling and operational workflows.

Skills

Security operations
Incident response
Detection engineering
Logging and telemetry evaluation
SIEM platforms
Response automation
Cloud security architecture
Scripting in Python or PowerShell
AI tooling in security workflows
Clear communication

Education

Bachelor’s degree in Computer Science
Relevant security certifications

Tools

Google Chronicle
Microsoft Sentinel
Splunk
Terraform
CloudFormation

Job description

Overview

TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation, and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the MDR landscape.

Responsibilities
  • Handle complex incident response and escalation. Take ownership of high-severity and technically complex incidents — leading investigation, driving containment decisions, and communicating findings clearly when it counts.
  • Assess and improve telemetry and logging coverage. Automate evaluation of customer environments for logging gaps and deficiencies across endpoint, network, identity, and cloud. Specify what\'s needed for effective detection and investigation, and work with customers and internal teams to close the gaps.
  • Ensure SIEM and detection quality. Apply deep platform knowledge to evaluate detection fidelity, data normalization, parser quality, and alert logic — identifying where coverage or quality falls short and partnering with detection engineering to address it.
  • Contribute to response automation quality. Work closely with the SOAR team to review enrichment logic, containment playbooks, and automation design — bringing an incident responder\'s perspective to what works under pressure and what doesn\'t.
  • Support technical needs across the organization. Serve as a knowledgeable resource for forward-deployed engineers, onboarding teams, and customers on questions spanning telemetry, investigation, platform behavior, and response — representing the SOC\'s technical depth across functions.
  • Improve SOC tooling and operational workflows. Identify friction in how analysts triage, investigate, and respond. Partner on tooling improvements, process changes, and reference content that raise consistency and quality across the team.
What You Bring
  • 5+ years in security operations, incident response, or detection engineering with demonstrated depth across multiple domains.
  • Strong fluency in logging and telemetry — able to evaluate an environment\'s coverage posture, identify deficiencies, and articulate what\'s needed for effective detection and investigation.
  • Hands-on experience with SIEM platforms (Google Chronicle, Microsoft Sentinel, and/or Splunk a plus) — enough to understand data modeling, rule architecture, and parser quality, and recognize when a deployment falls short of what our MDR SOC requires.
  • Solid understanding of response automation — enrichment pipelines, SOAR playbook structure, containment logic — and the judgment to evaluate whether automation is working as intended.
  • Working knowledge of cloud security architecture in at least one major cloud (AWS, Azure, or GCP), including native log sources and their value for investigation.
  • Scripting proficiency in Python or PowerShell for automation support, and integration work.
  • Familiarity applying AI or LLM-based tooling to security workflows — investigation assistance, alert triage, log analysis, or automation — is a strong plus.
  • Clear, confident communicator across technical and non-technical audiences — customers, engineers, and analysts alike.
Bonus Points
  • Multi-cloud breadth across AWS, Azure, and GCP security tooling and telemetry.
  • Experience with IaC (Terraform, CloudFormation) and DevSecOps practices.
  • Familiarity authoring detection runbooks, investigation guides, or SOC operating procedures.
  • Splunk Enterprise Security depth — ES notable events, risk-based alerting, correlation search architecture.
  • Container and Kubernetes security monitoring exposure.
  • Experience building or evaluating AI-assisted security tooling, agentic workflows, or LLM-augmented investigation and response.
Education & Certifications
  • Bachelor’s degree in Computer Science, Information Security, or a related field, OR equivalent work experience.
  • Relevant certifications — CISSP, GCIH, GCFE, GCDA, GREM, AWS/GCP security, or SIEM platform certifications — are a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Engineer
SOC Engineer

TENEX.AI • Sarasota (FL)

On-site
USD 90,000 - 120,000
SOC Engineer
SOC Engineer

Tenex • Sarasota (FL), Scottsdale (AZ), Kansas City (MO)

On-site
USD 90,000 - 140,000
SOC Engineer
SOC Engineer

TENEX.AI • United States

On-site
USD 100,000 - 130,000
SOC Engineer
SOC Engineer

TENEX.AI • Missouri

On-site
USD 100,000 - 130,000
Competitive salary and benefits package
Opportunities for growth and development
Collaboration with innovative team
SOC Engineer
SOC Engineer

TENEX.AI • Town of Florida (NY)

On-site
USD 100,000 - 130,000
SOC Director
SOC Director

TENEX.AI • United States

On-site
USD 180,000 - 250,000
Competitive salary and benefits
SOC Director
SOC Director

TENEX.AI • Overland Park (KS)

On-site
USD 180,000 - 250,000
SOC Director
SOC Director

Tenex.Ai • Sarasota (FL)

On-site
USD 180,000 - 240,000
Competitive salary
Benefits package
Growth opportunities
SOC Engineer
SOC Engineer

No Limit Staffing, Inc. • United States

On-site
USD 90,000 - 120,000
SOC Director
SOC Director

TENEX.AI • Town of Florida (NY)

On-site
USD 150,000 - 190,000