freehire launches on Product Hunt on 26 August.

Follow →

Purple Team - Lead Cloud Security Engineer

Open 20d

Summary

Lead a purple team to test and improve cloud security defenses by emulating real attacks, writing detections, and analyzing telemetry for a fast-growing AI-native MDR provider.

Company Overview:

TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape.

We’re a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you’ll play a meaningful role in defining and building our culture. Get in on the ground floor. We’re a small but well-funded team that just raised a substantial round – joining now comes with limited risk and unlimited upside.

Culture is one of the most important things at —explore our culture deck at to witness how we embody it, prioritizing the irreplaceable collaboration and community of in-person work.

About the Opportunity:

TENEX runs an Adversary Research Team that studies how real attackers operate and turns that into stronger detection and response for our customers. As Lead Security Engineer on the purple team, you sit with that team and close the loop between offense and defense. You will emulate current adversary techniques against our detection stack, measure how well we catch and respond to them, and feed the gaps back into detection engineering and the SOC. This is a hands-on role for someone equally comfortable on the red side, building and running emulations, and on the blue side, reading telemetry and writing detections.

What You’ll Do:

  • Identify and address gaps. Find where coverage falls short, research and design detection use-cases to close it, and validate through testing where that is merited.

  • Detection engineering research. Where public detection research is thin or nonexistent, develop detection strategies from scratch for high-blast-radius technologies, crown-jewel systems, and areas of high risk or exposure.

  • Adversary research. Track the actors, malware, and tooling active against our customers’ verticals, and dissect their tradecraft down to the behaviors that matter for detection and emulation.

  • Adversary emulation. Design and recreate real attacks to test and validate detections and controls. Use the outcomes to improve detections and tooling in customer environments.

  • Track and report results. Develop reporting that gives leadership and customers a straight answer on where our defenses stand.

What You Bring:

  • 7+ years in offensive security, detection engineering, or a blend of the two, with hands-on purple team or adversary emulation experience.

  • Strong red-side skills: adversary tradecraft, command and control, evasion, and building emulation plans that reflect how real intrusions unfold.

  • Strong blue-side skills: writing and tuning detections and analyzing endpoint, network, and cloud telemetry in a SIEM or EDR.

  • Ability to measure detection effectiveness and communicate results clearly to engineers, analysts, and leadership.

Bonus Points:

  • Experience with emulation and purple team tooling (Caldera, Atomic Red Team, Prelude, Scythe, or similar).

  • Experience in an MDR/MSSP or high-growth startup environment.

  • Detection content development or threat-hunting background.

Education & Certifications:

  • Bachelor’s degree in Computer Science, Cybersecurity, or Engineering, or a related field (or equivalent experience).

  • Relevant certifications such as OSCP, OSEP, CRTO, GIAC (GPEN, GCFA, or GCDA), or CISSP are a plus.

Why Join Us?

  • Own the purple team at an MDR company, working directly with adversary research, detection engineering, and the SOC to prove and improve how well we detect real attacks.

  • Collaborate with a talented and innovative team focused on continuously improving security operations.

  • Competitive salary and benefits package.

  • A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.

What this application asks

ashby

Legal Name, Email, Location, Upload your resume

  • Phone
  • Are you legally authorized to work in the United States? yes / no
  • Will you now or in the future require sponsorship? yes / no
  • If you have any questions regarding our screening process or data privacy, please review our Background Check Policy at this link. We are committed to transparency and encourage you to familiarize yourself with these guidelines before finalizing your application. choose one
  • Linkedin Profile (www.linkedin.com/in/YOURINFO):
  • If you do not currently reside in the San Jose/San Francisco Bay Area, Kansas City Metro Area, or the Greater Tampa/Sarasota Metro Area, please select what city you would be interested in a Company assisted relocation package? choose any
  • What is your current job title?
  • Years of Experience: 
  • Security Tool Experience:  written answer
  • Upload your cover letter upload · optional
  • Desired Compensation Range:
  • How did you find out about this position? choose one
  • If you were referred by a Current Employee, please list their name. If this is not applicable, please list N/A. 

See also