Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
TENEX.AI

Forward Deployed Security Automation Engineer

TENEX.AI

. Deploy, configure, and maintain SIEM, SOAR, and EDR environments across vendors including CrowdStrike, SentinelOne, Microsoft Defender, Splunk, Microsoft Sentinel, and Google SecOps .

Posted 10/6/2026full-timeUnited StatesMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in deploying and maintaining SIEM, SOAR, and EDR environments, with a strong focus on Python service development and automated detection workflows. Proven ability to manage platform reliability and integrate complex vendor APIs while ensuring security and compliance.

Highest-signal resume keywords
SIEM/SOAR/EDR Platform ManagementPython Service DevelopmentAutomated Detection and Response WorkflowsPlatform Reliability OwnershipVendor API Integration

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
PythonGoSIEMSOAREDRAPI IntegrationAutomated WorkflowsDetection-as-CodeProduction OwnershipPerformance Tuning
Tools & Technologies
CrowdStrikeSentinelOneMicrosoft DefenderSplunkMicrosoft SentinelGoogle SecOpsKubernetes
Certifications & Qualifications
AWS Professional EngineerGCP Professional EngineerSecurity-Related Credentials
Industry Keywords
MDRMSSPDetection and ResponseSecurity ToolingMulti-Tenant EDR

Tech Stack

Tools & technologies
AWSGoogle Cloud PlatformKubernetesPythonSplunkGo

About the role

Key responsibilities & impact
  • Deploy, configure, and maintain SIEM, SOAR, and EDR environments across vendors including CrowdStrike, SentinelOne, Microsoft Defender, Splunk, Microsoft Sentinel, and Google SecOps
  • Manage EDR prevention policies, host groups, custom IOAs, exclusions, SIEM detection content, and SOAR connectors
  • Troubleshoot and resolve EDR agent issues, including performance impacts, kernel or driver conflicts, upgrade rollouts, and false-positive tuning
  • Develop, test, and deploy production Python services, APIs, workers, queues, tests, CI, and containers
  • Build automated containment and remediation workflows such as host isolation, process termination, file quarantine, account disabling, and ticket creation
  • Architect safety guardrails including approval thresholds, critical-host allow lists, isolation-action rate limits, audit trails, and safe release or rollback paths
  • Own platform reliability and latency outcomes, including time from alert to containment
  • Participate in the on-call rotation for security tooling
  • Create and maintain observable internal tooling with logging, metrics, and alerting

Requirements

What you’ll need
  • Deep, hands-on experience operating multiple SIEM/SOAR/EDR platforms
  • Proven software engineering experience building and maintaining production Python services and APIs
  • Experience integrating with complex vendor APIs and managing authentication, rate limits, and retries
  • Demonstrated experience building automated detection and response workflows with carefully designed safety guardrails
  • Track record of taking end-to-end production ownership of a platform
  • Bachelor's or Master's degree in Computer Science, Engineering, or a related field
  • Relevant certifications are a plus, including AWS/GCP Professional Engineer, Kubernetes, or security-related credentials
  • Experience managing multi-tenant EDR structures is a nice-to-have
  • Proficiency in Go and/or Python is a nice-to-have
  • Detection-as-code experience is a nice-to-have
  • Background working at MDR/MSSP providers, SOAR vendors, EDR vendor engineering teams, or detection and response teams of security-mature technology companies is a nice-to-have
  • Ability to work onsite four days per week, Monday through Thursday
  • Ability to work in the United States; the application asks whether the candidate is legally authorized to work in the United States and whether sponsorship will be required

Benefits

Comp & perks
  • Competitive salary and benefits package
  • Culture of growth and development
  • Opportunities to expand knowledge in AI, cybersecurity, and emerging technologies
  • Opportunity to work with cutting-edge AI-driven cybersecurity technologies and Google SecOps solutions
  • Collaborate with a talented and innovative team focused on continuously improving security operations