Purple Team - Lead Cloud Security Engineer
TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We help organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team consists of industry experts with deep experience in cybersecurity, automation, and AI-driven solutions. Backed by leading investors such as Crosspoint Capital Partners, Shield Capital, DTCP, Deepwork Capital, and the Florida Opportunity Fund, we are rapidly growing and seeking top talent to join our mission. As an early employee, you’ll play a key role in defining and building our culture.
About the Opportunity
TENEX runs an Adversary Research Team that studies how real attackers operate and turns that into stronger detection and response for our customers. As Lead Security Engineer on the purple team, you will close the loop between offense and defense. You will emulate current adversary techniques against our detection stack, measure how well we catch and respond to them, and feed the gaps back into detection engineering and the SOC. This is a hands-on role for someone equally comfortable on the red side (building and running emulations) and the blue side (reading telemetry and writing detections).
Responsibilities
- Identify and address gaps in detection coverage, research and design detection use-cases, and validate through testing.
- Develop detection strategies from scratch for high-blast-radius technologies, crown-jewel systems, and high-risk areas where public research is lacking.
- Track adversaries, malware, and tooling active against our customers’ verticals, dissecting their tradecraft for detection and emulation.
- Design and recreate real attacks to test and validate detections and controls, using outcomes to improve detections and tooling in customer environments.
- Develop reporting that clearly communicates detection effectiveness to leadership and customers.
Requirements
- 7+ years in offensive security, detection engineering, or a blend of the two, with hands-on purple team or adversary emulation experience.
- Strong red-side skills: adversary tradecraft, command and control, evasion, and building emulation plans that reflect real intrusions.
- Strong blue-side skills: writing and tuning detections and analyzing endpoint, network, and cloud telemetry in a SIEM or EDR.
- Ability to measure detection effectiveness and communicate results clearly to engineers, analysts, and leadership.
Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, or Engineering, or a related field (or equivalent experience).
- Relevant certifications such as OSCP, OSEP, CRTO, GIAC (GPEN, GCFA, or GCDA), or CISSP are a plus.
- Bonus points for experience with emulation and purple team tooling (Caldera, Atomic Red Team, Prelude, Scythe, or similar).
- Bonus points for experience in an MDR/MSSP or high-growth startup environment.
- Bonus points for detection content development or threat-hunting background.
Benefits
- Own the purple team at an MDR company, working directly with adversary research, detection engineering, and the SOC to improve detection of real attacks.
- Collaborate with a talented and innovative team focused on continuously improving security operations.
- Competitive salary and benefits package.
- A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.