SOC Engineer
Handle complex incident response and escalation for high-severity threats
As a SOC Engineer at TENEX.AI, you will operate across incident response, platform quality, and operational improvement. You'll take ownership of high-severity and technically complex incidents, leading investigation and driving containment decisions. You'll also assess and improve telemetry and logging coverage across endpoint, network, identity, and cloud environments, ensuring SIEM and detection quality through deep platform knowledge and a...
Why This Role?
Direct founder access and real impact from day one as an early employee in a well-funded startup
Key Responsibilities
- Handle complex incident response and escalation for high-severity threats
- Assess and improve telemetry and logging coverage across customer environments
- Ensure SIEM and detection quality by evaluating detection fidelity and parser quality
- Automate evaluation of customer environments for logging gaps and deficiencies
- Specify needed improvements for effective detection and investigation
- Work with customers and internal teams to close telemetry and detection gaps
Requirements
- Experience in incident response and handling high-severity escalations
- Knowledge of telemetry and logging across endpoint, network, identity, and cloud
- Understanding of SIEM platforms, detection engineering, and alert logic
- Ability to evaluate data normalization and parser quality
- Experience working with internal engineering teams and customers
- Familiarity with automation and AI-driven solutions in cybersecurity
Required Skills
Keywords
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
COMPANY OVERVIEW: TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation, and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the MDR landscape. We’re a fast growing startup backed by industry experts and top tier investor Andreessen Horowitz. As an early employee, you’ll play a meaningful role in defining and building our culture. Get in on the ground floor. We’re a small but well-funded team that just raised a substantial round – joining now comes with limited risk and unlimited upside. Culture is one of the most important things at TENEX.AI http://TENEX.AI—explore our culture deck at culture.tenex.ai http://culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in-person work. As a SOC Engineer, you'll operate across incident response, platform quality, and operational improvement — evaluating telemetry coverage, shaping response automation, handling high-severity escalations, and ensuring the tooling and workflows analysts depend on are fit for purpose. The role carries direct engagement across internal engineering teams and customers, and no shortage of hard problems to solve. We default to automation and AI wherever they produce better outcomes — and we want engineers who think the same way. WHAT YOU'LL DO - Handle complex incident response and escalation. Take ownership of high-severity and technically complex incidents — leading investigation, driving containment decisions, and communicating findings clearly when it counts. - Assess and improve telemetry and logging coverage. Automate evaluation of customer environments for logging gaps and deficiencies across endpoint, network, identity, and cloud. Specify what's needed for effective detection and investigation, and work with customers and internal teams to close the gaps. - Ensure SIEM and detection quality. Apply deep platform knowledge to evaluate detection fidelity, data normalization, parser quality, and alert logic — identifying where coverage or quality falls short and partnering with detection engineering to address it. - Contribute to response automation quality. Work closely with the SOAR team to review enrichment logic, containment playbooks, and automation design — bringing an incident responder's perspective to what works under pressure and what doesn't. - Support technical needs across the organization. Serve as a knowledgeable resource for forward-deployed engineers, onboarding teams, and customers on questions spanning telemetry, investigation, platform behavior, and response — representing the SOC's technical depth across functions. - Improve SOC tooling and operational workflows. Identify friction in how analysts triage, investigate, and respond. Partner on tooling improvements, process changes, and reference content that raise consistency and quality across the team. WHAT YOU BRING - 5+ years in security operations, incident response, or detection engineering with demonstrated depth across multiple domains. - Strong fluency in logging and telemetry — able to evaluate an environment's coverage posture, identify deficiencies, and articulate what's needed for effective detection and investigation. - Hands-on experience with SIEM platforms (Google Chronicle, Microsoft Sentinel, and/or Splunk a plus) — enough to understand data modeling, rule architecture, and parser quality, and recognize when a deployment falls short of what our MDR SOC requires. - Solid understanding of response automation — enrichment pipelines, SOAR playbook structure, containment logic — and the judgment to evaluate whether automation is working as intended. - Working knowledge of cloud security architecture in at least one major cloud (AWS, Azure, or GCP), including native log sources and their value for investigation. - Scripting proficiency in Python or PowerShell for automation support, and integration work. - Familiarity applying AI or LLM-based tooling to security workflows — investigation assistance, alert triage, log analysis, or automation — is a strong plus. - Clear, confident communicator across technical and non-technical audiences — customers, engineers, and analysts alike. BONUS POINTS - Multi-cloud breadth across AWS, Azure, and GCP security tooling and telemetry. - Experience with IaC (Terraform, CloudFormation) and DevSecOps practices. - Familiarity authoring detection runbooks, investigation guides, or SOC operating procedures. - Splunk Enterprise Security depth — ES notable events, risk-based alerting, correlation search architecture. - Container and Kubernetes security monitoring exposure. - Experience building or evaluating AI-assisted security tooling, agentic workflows, or LLM-augmented investigation and response. EDUCATION & CERTIFICATIONS - Bachelor’s degree in Computer Science, Information Security, or a related field, OR equivalent work experience. - Relevant certifications — CISSP, GCIH, GCFE, GCDA, GREM, AWS/GCP security, or SIEM platform certifications — are a plus.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
Frequently asked questions
- Is SOC Engineer at TENEX.AI a remote job?
- This role is based in Remote. See the listing for remote/onsite details.
- What type of employment is SOC Engineer at TENEX.AI?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at TENEX.AI.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- Senior Tech Roles Remote Salaries June 2026In-depth analysis of 7 senior tech role remote salaries from Vercel, Airbnb, Stripe, to Notion. Compare with local market and negotiation strategies.
- Sourcing Specialist: The Complete GlobalCurious about becoming a remote Sourcing Specialist? Learn the essential skills, tools, and how to land a USD-paying job—no matter where you live.
- Remote Mobile Developer Jobs July 2026A roundup of USD-paying remote mobile developer jobs from Loker Dollar. Analyze trends and get application tips.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume