freehire launches on Product Hunt on 26 August.

Follow →

Director of Forward Deployed Engineering

Open 57d posting dated last week

Summary

Lead a team to deploy, integrate, and manage AI-driven security platforms (Google SecOps, Microsoft Sentinel, Tenex) for customers, ensuring fast, repeatable MDR service delivery at scale.

Company Overview

TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We combine cutting-edge AI with human expertise to deliver security operations that are better, faster, and more cost-effective than traditional approaches.

We're a fast-growing startup backed by industry experts and top-tier investors led by Crosspoint Capital. Our team is mission-driven, customer-obsessed, and building something that matters — a new standard for how security operations should work.

Culture is one of the most important things at — explore our culture deck at to witness how we embody our values every day.

This role is perfect for those already in the Scottsdale, AZ, Sarasota, FL or Kansas City, MO metro area, or eager to join us. Immerse yourself in a high-performance environment built on integrity, innovation, and a relentless drive to protect our customers.

About the Role

is the AI-native, human-led MDR provider. This Director owns the foundational delivery of our MDR service: how we build, deploy, manage, and integrate the platforms our service runs on: Google SecOps, Microsoft Sentinel, and the Tenex Platform. The mandate is time-to-protection and repeatable, high-quality multi-SIEM delivery at scale, standing platforms up cleanly, wiring in the customer's data and tooling, operationalizing detection content and context, and keeping it all running well across the portfolio.

This is an engineering leadership role, not an advisory or product-building one. The team implements and manages the platforms and works closely with the teams that deliver advisory engagements and develop agentic use cases; deploying and integrating what they produce and relaying field context back to them.

What You'll Do

  • Own time-to-protection across our supported platforms — the speed and repeatability of standing up Google SecOps, Microsoft Sentinel, and the Tenex Platform in customer environments for example.

  • Lead multi-SIEM engineering — build, deploy, and manage pipelines, parsers, detections, playbooks and other configuration across Google SecOps, Microsoft Sentinel, and the Tenex Platform.

  • Own integrations — data-source onboarding, connector/API work, and normalization that wire the customer's environment and security tooling into the SIEMs and the Tenex Platform; build integration patterns that get reused, not rebuilt.

  • Own context engineering — the data mappings, entity resolution, tuning, and environment knowledge that make the platforms actually perform per customer.

  • Own ongoing platform management — health, optimization, and lifecycle of deployed platforms across the book of business.

  • Build the repeatable delivery machine — playbooks, intake, quality gates, and a capacity model that let the team scale against pipeline instead of heroics.

  • Lead and scale the team — hire, coach, and develop the engineers responsible for platform implementation, content, and integration; manage capacity against the customer pipeline; own delivery quality, SLOs, and OKRs.

  • Run the cross-team interfaces — partner with customer success, product management, threat intelligence, and cyber defense across the delivery lifecycle, and maintain clean support/relay channels with the advisory and agentic engineering functions.

What You Bring

Must-have

  • 8+ years in security engineering, security operations, or detection engineering, with 3+ years managing engineers (ideally managing leads/managers).

  • Hands-on depth across both major SIEMs: Google SecOps (Chronicle — ingestion, parsers/CBN, YARA-L, entity graph) and Microsoft Sentinel (KQL, analytics rules, data connectors, Log Analytics) — or deep in one and strongly credible in the other, with clear ability to lead both.

  • Integration engineering — data-source onboarding, connector/API development, and normalization across platforms.

  • Demonstrated track record building repeatable delivery at scale — playbooks, quality gates, capacity planning — not just running individual projects.

  • Strong customer-facing communication; can own a delivery relationship with a customer security team.

  • Comfort with multi-tenant delivery and content-as-code / CI/CD workflows.

Nice-to-have

  • SOAR / automation (Chronicle SOAR, Sentinel automation rules & playbooks).

  • Pipeline and telemetry tooling (Bindplane, Logstash, or equivalent).

  • Terraform / IaC for repeatable environment standup.

  • Prior MSSP / MDR / managed security services experience.

  • Experience operating alongside agentic and advisory functions without absorbing their scope.

What Success Looks Like

  • 90-day: Multi-SIEM delivery playbooks and quality gates in place. Time-to-protection baseline measured across SecOps and Sentinel deployments. Team capacity model built against pipeline. Support/relay interfaces with the advisory and agentic engineering functions defined and agreed.

  • 6-month: Measurable reduction in time-to-protection across both SIEMs. Integration patterns reused rather than rebuilt. Ongoing platform management running to a defined health/optimization cadence. Team staffed to plan.

  • 12-month: A repeatable, metric-driven multi-platform delivery machine that scales sub-linearly to customer growth. Managed platforms healthy across the book. The "we support, they own" interfaces to the advisory and agentic engineering functions running smoothly, with no scope drift in either direction.

Education & Certifications

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field (or equivalent practical experience)

  • Relevant certifications such as CISSP, CISM, GIAC certifications, Google Cloud Professional, Microsoft SC-200/AZ-500, or AWS Certified Solutions Architect are a plus

Why Join Us?

  • Opportunity to work with cutting-edge AI-driven cybersecurity technologies and next-generation security platforms

  • Collaborate with a talented and innovative team focused on continuously improving security operations

  • Competitive salary and benefits package

  • A culture of growth and development, with opportunities to expand your expertise in AI, cybersecurity, and engineering

  • Be part of building something new — TENEX's Forward Deployed Engineering organization is a greenfield opportunity to define how enterprise security is delivered at scale

What this application asks

ashby

Legal Name, Email, Location, Upload your resume

  • Phone
  • Are you legally authorized to work in the United States? yes / no
  • Will you now or in the future require sponsorship? yes / no
  • If you have any questions regarding our screening process or data privacy, please review our Background Check Policy at this link. We are committed to transparency and encourage you to familiarize yourself with these guidelines before finalizing your application. choose one
  • Linkedin Profile (www.linkedin.com/in/YOURINFO):
  • If you do not currently reside in the San Jose/San Francisco Bay Area, Kansas City Metro Area, or the Greater Tampa/Sarasota Metro Area, please select what city you would be interested in a Company assisted relocation package? choose any
  • What is your current job title?
  • Years of Experience: 
  • Security Tool Experience:  written answer
  • Upload your cover letter upload · optional
  • Desired Compensation Range:
  • How did you find out about this position? choose one
  • If you were referred by a Current Employee, please list their name. If this is not applicable, please list N/A. 

See also