Staff Threat Hunter
Lead proactive threat hunts across multi-tenant MDR telemetry in Google SecOps
As Staff Threat Hunter at TENEX.AI, you will lead hypothesis-driven hunts across SIEM, EDR, network, and identity telemetry to surface threats missed by automated detection. You will own the hunt methodology by building, documenting, and refining playbooks that the team executes. You will partner with detection engineering to convert hunt findings into production rules and analytics in Google SecOps / Chronicle, and operationalize threat intel...
Why This Role?
Set the technical direction for how hunting works at TENEX as a senior IC reporting to the VP of Security
Key Responsibilities
- Lead proactive, hypothesis-driven hunts across SIEM, EDR, network, and identity telemetry
- Own and refine hunt methodology by building documenting and refining team playbooks
- Drive detection engineering partnership to turn hunt findings into production rules in Google SecOps Chronicle
- Operationalize threat intelligence by tracking adversary TTPs and prioritizing what matters for customer base
- Decide what gets hunted on what cadence and how findings convert into permanent detections
Requirements
- Experience leading hypothesis-driven threat hunts in enterprise environments
- Proficiency with SIEM EDR network and identity telemetry analysis
- Experience building documenting and refining threat hunting playbooks
- Experience partnering with detection engineering to convert findings into production detections
- Knowledge of adversary TTPs and threat intelligence operationalization
- Experience working in Google SecOps / Chronicle or similar cloud SIEM platforms
Required Skills
Keywords
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
Company Overview: TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape. We're a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you'll play a meaningful role in defining and building our culture. Get in on the ground floor. We're a small but well-funded team that just raised a substantial round – joining now comes with limited risk and unlimited upside. Culture is one of the most important things at TENEX.AI http://TENEX.AI—explore our culture deck at culture.tenex.ai http://culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in-person work. About the Opportunity: As Staff Threat Hunter, you'll own how TENEX hunts — the methodology, the tooling, the hypotheses, and the conversion of hunt findings into production detections. You'll work across multi-tenant MDR telemetry in Google SecOps / Chronicle, partnering with detection engineering to close the gaps automated alerting misses. This is a senior IC role — you set the technical direction for how hunting works at TENEX. Reports to the VP, Security. What You'll Do: - Lead proactive, hypothesis-driven hunts. Run investigations across SIEM, EDR, network, and identity telemetry to surface the threats automated detection misses. - Own the hunt methodology. Build, document, and refine the playbooks the team runs from. Decide what gets hunted, on what cadence, and how findings convert into permanent detections. - Drive the detection engineering partnership. Work directly with detection engineers to turn hunt findings into production rules and analytics in Google SecOps / Chronicle. - Operationalize Threat Intelligence. Track adversary TTPs relevant to our customer base, prioritize what matters, and translate intel into hunt hypotheses. - Mentor SOC analysts and junior hunters. Pair on investigations, lead technical deep-dives, and grow the team's hunt capability. - Lead complex incident investigations. When a hunt surfaces a real intrusion, run the technical investigation alongside incident response through containment. - Report on program outcomes. Communicate findings to customers and internal stakeholders — what was found, what was contained, where the detection coverage gap was, and what we changed. What You Bring: - 8+ years in threat hunting, SOC, or incident response, with at least 3 in a senior/lead capacity - Deep hands-on experience running hypothesis-driven hunts across SIEM and EDR telemetry in enterprise or MDR environments - Hands-on hunting experience in Google SecOps / Chronicle, or equivalent cloud-native SIEM (Sentinel, Splunk Cloud) with willingness to standardize on Chronicle - Strong command of attacker TTPs and MITRE ATT&CK — you can map an intrusion from initial access through impact and explain the detection gap at each stage - Scripting fluency in Python and/or PowerShell for hunt tooling, telemetry parsing, and detection automation Bonus Points: - Microsoft security stack (Sentinel, Defender) depth - SOAR platform experience (Tines, XSOAR, Chronicle SOAR) - Cloud security depth in AWS, Azure, or GCP, including cloud-native attack patterns - Published research, conference talks, or open-source contributions in threat hunting or detection engineering Education & Certifications: - Bachelor's degree in Computer Science, Cybersecurity, or Engineering, or a related field (or equivalent experience). - Relevant certifications such as GCIH, GCFA, GCDA, OSCP, CISSP, AWS / GCP, or Splunk / Chronicle / Sentinel certifications are a plus. Why Join Us? - Opportunity to define the threat hunting practice at an automation-first MDR provider — your methodology becomes the standard our customers run on. - Collaborate with a talented and innovative team focused on continuously improving security operations. - Competitive salary and benefits package. - A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
Frequently asked questions
- Is Staff Threat Hunter at TENEX.AI a remote job?
- This role is based in Remote. See the listing for remote/onsite details.
- What type of employment is Staff Threat Hunter at TENEX.AI?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at TENEX.AI.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- Senior Tech Roles Remote Salaries June 2026In-depth analysis of 7 senior tech role remote salaries from Vercel, Airbnb, Stripe, to Notion. Compare with local market and negotiation strategies.
- Sourcing Specialist: The Complete GlobalCurious about becoming a remote Sourcing Specialist? Learn the essential skills, tools, and how to land a USD-paying job—no matter where you live.
- Remote Mobile Developer Jobs July 2026A roundup of USD-paying remote mobile developer jobs from Loker Dollar. Analyze trends and get application tips.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume