TandemTrace
We’re hiring · Security research

Senior Cybersecurity
Researcher.

We’re looking for a cybersecurity expert who can think like an attacker, investigate like a defender, and challenge our product without compromise. You will simulate realistic attacks, follow the resulting evidence across the stack, and stress-test whether TandemTrace reaches the right conclusion.

Level
Senior
Experience
10+ years
Focus
Product validation
Practice
Red / blue / purple
// 01 · The mission

Try to break the product before the market does.

TandemTrace is building the autonomous layer for the modern SOC. Our agents investigate alerts, correlate evidence across the security stack, hunt for threats, and help teams understand what happened and what to do next.

Your job is to challenge that system. You will create realistic attack scenarios, generate imperfect and conflicting telemetry, investigate the evidence as a defender, and determine where the product succeeds, hesitates, or reaches the wrong conclusion.

This is an internal adversarial role. You will combine red-team creativity, blue-team discipline, and product judgment to expose blind spots before customers depend on the answer.

// 02 · What you’ll challenge

Attack it. Investigate it. Prove what failed.

  • Design end-to-end attack simulations that exercise realistic intrusion paths across identity, endpoint, cloud, network, email, and data.
  • Execute red-team and purple-team scenarios safely in controlled environments using current adversary techniques and meaningful variations.
  • Investigate every scenario from the blue-team side to establish ground truth, expected evidence, correct scope, root cause, impact, and response.
  • Stress-test TandemTrace against noisy, missing, delayed, misleading, or contradictory telemetry and deliberate attacker evasion.
  • Challenge conclusions and reasoning by finding unsupported claims, missed pivots, weak evidence, false positives, and incomplete attack paths.
  • Turn every gap into a reproducible asset such as an evaluation case, attack fixture, product requirement, detection opportunity, or regression test.
// 03 · Your operating environment

Challenge the full security stack.

You should be equally comfortable generating attacker activity, validating security telemetry, and investigating the resulting incident across multiple tools.

Adversary emulationAttack plans, TTP execution, variation, evasion, and controlled labs.
SIEMSearch, correlation, detection logic, timelines, and historical telemetry.
EDR / XDREndpoint activity, process trees, response actions, and cross-domain evidence.
Cloud / CNAPPWorkloads, identities, posture, control plane activity, and runtime risk.
DFIRForensic evidence, scoping, root cause, containment, and incident reconstruction.
Identity / networkPrivilege, lateral movement, authentication, traffic, and attacker infrastructure.
// 04 · What you bring

Offensive creativity. Defensive rigor.

  • 10+ years of hands-on security operations experience, including significant responsibility for complex investigations and incident response.
  • Practical red-team, blue-team, or purple-team experience designing attack scenarios, validating controls, and explaining exactly what defenders should have observed.
  • Strong threat-hunting experience with a record of forming hypotheses, finding evidence, and communicating actionable conclusions.
  • Fluency across modern security stacks, including SIEM, EDR/XDR, CNAPP, DFIR, identity, cloud, network, and threat-intelligence systems.
  • Deep understanding of attacker behavior across the intrusion lifecycle and practical familiarity with MITRE ATT&CK and adversary-emulation methods.
  • A product-testing mindset that turns ambiguous failures into minimal, repeatable cases engineering teams can act on.
  • Clear analytical writing that makes ground truth, evidence, uncertainty, expected behavior, and actual behavior easy to inspect.
// 05 · Why this role

Be the expert who says, “prove it.”

Autonomous security products should not be judged by polished demos or plausible explanations. They should be challenged with realistic attacker behavior, incomplete evidence, operational edge cases, and repeatable tests.

You will work directly with an experienced cybersecurity founder and a compact product team. Your judgment will influence product behavior, attack coverage, investigation quality, evaluation standards, and the evidence we require before calling a capability ready.

// Interested?

Show us how you challenge security systems.

Send your LinkedIn profile or CV and a short note about an attack simulation, purple-team exercise, product stress test, or difficult investigation that reflects how you work.

Apply by email ↗