8+ years in security engineering, security operations, or detection engineering, with 3+ years managing engineers.
Hands-on experience with Google SecOps and Microsoft Sentinel, or deep expertise in one with credibility in the other.
Proficient in integration engineering, including data-source onboarding and API development.
Proven ability to build repeatable delivery processes at scale, including playbooks and capacity planning.
Strong customer-facing communication skills for managing delivery relationships.
Responsibilities
Own time-to-protection across supported platforms, ensuring rapid deployment.
Lead multi-SIEM engineering, managing pipelines, parsers, and configurations.
Oversee integrations, including data-source onboarding and normalization.
Manage context engineering for optimal platform performance per customer.
Ensure ongoing platform health and optimization across the business.
Develop a repeatable delivery model with playbooks and quality gates.
Lead and scale the engineering team, managing capacity and delivery quality.
Benefits
Work with cutting-edge AI-driven cybersecurity technologies.
Collaborate with a talented and innovative team.
Competitive salary and benefits package.
Culture of growth and development in AI and cybersecurity.
Opportunity to define enterprise security delivery at scale.
Full Job Description
About the Role
TENEX.AI is the AI-native, human-led MDR provider. This Director owns the foundational delivery of our MDR service: how we build, deploy, manage, and integrate the platforms our service runs on: Google SecOps, Microsoft Sentinel, and the Tenex Platform. The mandate is time-to-protection and repeatable, high-quality multi-SIEM delivery at scale, standing platforms up cleanly, wiring in the customer's data and tooling, operationalizing detection content and context, and keeping it all running well across the portfolio.
This is an engineering leadership role, not an advisory or product-building one. The team implements and manages the platforms and works closely with the teams that deliver advisory engagements and develop agentic use cases; deploying and integrating what they produce and relaying field context back to them.
What You'll Do
Own time-to-protection across our supported platforms - the speed and repeatability of standing up Google SecOps, Microsoft Sentinel, and the Tenex Platform in customer environments for example.
Lead multi-SIEM engineering - build, deploy, and manage pipelines, parsers, detections, playbooks and other configuration across Google SecOps, Microsoft Sentinel, and the Tenex Platform.
Own integrations - data-source onboarding, connector/API work, and normalization that wire the customer's environment and security tooling into the SIEMs and the Tenex Platform; build integration patterns that get reused, not rebuilt.
Own context engineering - the data mappings, entity resolution, tuning, and environment knowledge that make the platforms actually perform per customer.
Own ongoing platform management - health, optimization, and lifecycle of deployed platforms across the book of business.
Build the repeatable delivery machine - playbooks, intake, quality gates, and a capacity model that let the team scale against pipeline instead of heroics.
Lead and scale the team - hire, coach, and develop the engineers responsible for platform implementation, content, and integration; manage capacity against the customer pipeline; own delivery quality, SLOs, and OKRs.
Run the cross-team interfaces - partner with customer success, product management, threat intelligence, and cyber defense across the delivery lifecycle, and maintain clean support/relay channels with the advisory and agentic engineering functions.
What You Bring
Must-have
8+ years in security engineering, security operations, or detection engineering, with 3+ years managing engineers (ideally managing leads/managers).
Hands-on depth across both major SIEMs: Google SecOps (Chronicle - ingestion, parsers/CBN, YARA-L, entity graph) and Microsoft Sentinel (KQL, analytics rules, data connectors, Log Analytics) - or deep in one and strongly credible in the other, with clear ability to lead both.
Integration engineering - data-source onboarding, connector/API development, and normalization across platforms.
Demonstrated track record building repeatable delivery at scale - playbooks, quality gates, capacity planning - not just running individual projects.
Strong customer-facing communication; can own a delivery relationship with a customer security team.
Comfort with multi-tenant delivery and content-as-code / CI/CD workflows.
Experience operating alongside agentic and advisory functions without absorbing their scope.
What Success Looks Like
90-day: Multi-SIEM delivery playbooks and quality gates in place. Time-to-protection baseline measured across SecOps and Sentinel deployments. Team capacity model built against pipeline. Support/relay interfaces with the advisory and agentic engineering functions defined and agreed.
6-month: Measurable reduction in time-to-protection across both SIEMs. Integration patterns reused rather than rebuilt. Ongoing platform management running to a defined health/optimization cadence. Team staffed to plan.
12-month: A repeatable, metric-driven multi-platform delivery machine that scales sub-linearly to customer growth. Managed platforms healthy across the book. The "we support, they own" interfaces to the advisory and agentic engineering functions running smoothly, with no scope drift in either direction.
Education & Certifications
Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field (or equivalent practical experience)
Relevant certifications such as CISSP, CISM, GIAC certifications, Google Cloud Professional, Microsoft SC-200/AZ-500, or AWS Certified Solutions Architect are a plus
Why Join Us?
Opportunity to work with cutting-edge AI-driven cybersecurity technologies and next-generation security platforms
Collaborate with a talented and innovative team focused on continuously improving security operations
Competitive salary and benefits package
A culture of growth and development, with opportunities to expand your expertise in AI, cybersecurity, and engineering
Be part of building something new - TENEX's Forward Deployed Engineering organization is a greenfield opportunity to define how enterprise security is delivered at scale