> Markdown version of [/jobs/ext/739710-senior-proactive-security-engineer](https://www.wearedevelopers.com/jobs/ext/739710-senior-proactive-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Proactive Security Engineer - **Company:** TekStream Solutions - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Ubuntu (Operating System), CentOS, Network Analysis, Cloud Computing, Nvidia CUDA, Computer Engineering, System Configuration, Debian Linux, Linux, Python (Programming Language), Machine Learning, Nmap, Role-Based Access Control, Red Hat Enterprise Linux, Security Information and Event Management, Systems Architecture, TCP/IP, Wireshark, Scripting, Large Language Models, Prompt Engineering, Cyber Threat Analysis, Kubernetes, Deployment Automation, Microsoft Sentinel, Slurm, Virtual Agents, ArcSight Event Correlation, Cyber Warfare, Splunk, Network Server, Docker, Vulnerability Analysis - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5470caf6acc6ab29 ## About the Role Do you have experience in Wireshark?, Do you have a Master's degree in cybersecurity?, * Hands-on experience deploying, configuring, and securing servers and infrastructure (Linux-centric: Ubuntu, CentOS/RHEL, Debian). * Strong coding background - Python and Bash/shell scripting at minimum; ability to automate provisioning and integrate systems via APIs. * Demonstrated ability to take a theoretical concept or research requirement and implement it as working applied technology. * System architecture experience - designing systems that are sustainable, monitored, and resilient rather than one-off setups. * Proactive security experience - honeynets and deception, anomaly detection, vulnerability assessment, or similar offensive-informed defensive work. * Threat intelligence experience - ingesting, enriching, and correlating intel feeds. * Experience with SIEM and log/event correlation (Microsoft Sentinel and/or Splunk preferred; Elastic Security acceptable). * Network analysis fundamentals (Wireshark, Nmap, TCP/IP). * Experience with agentic AI systems, LLM orchestration, prompt engineering, or RAG pipelines. * Familiarity with applying AI to security use cases - anomaly detection, threat classification, alert triage, or intelligence enrichment., * Container and orchestration experience (Docker, Kubernetes/EKS). * ML-based anomaly/threat detection model development. * HPC or GPU-accelerated systems experience (CUDA, SLURM, NVIDIA clusters) used for AI model development. * RBAC and multi-tenant access control design. * Advanced degree (M.S. or Ph.D.) in cybersecurity, computer engineering, or a related field. * Research or publication background in security, side-channel analysis, or systems security. * SOC operations exposureTekStream's Proactive Security practice builds and operates the deception, threat intelligence, and adversary-engagement infrastructure that powers Cosmos - our autonomous cyber defense platform. We design honeynet environments that emulate real customer infrastructure, instrument them to capture adversary behavior, and feed that intelligence back into our MDR operations as governed, auditable signal. We are looking for a Senior Proactive Security Engineer to turn architectural requirements into running, sustainable systems. You will take a deception or detection concept - a sensor design, a threat-intelligence integration, an ML correlation pipeline - and stand it up on real infrastructure so it works on day one and keeps working without breaking. This is a hands-on build-and-maintain role for an engineer who is equally comfortable with system architecture, code, and the security theory behind why it all matters., * Hands-on experience deploying, configuring, and securing servers and infrastructure (Linux-centric: Ubuntu, CentOS/RHEL, Debian). * Strong coding background - Python and Bash/shell scripting at minimum; ability to automate provisioning and integrate systems via APIs. * Demonstrated ability to take a theoretical concept or research requirement and implement it as working applied technology. * System architecture experience - designing systems that are sustainable, monitored, and resilient rather than one-off setups. * Proactive security experience - honeynets and deception, anomaly detection, vulnerability assessment, or similar offensive-informed defensive work. * Threat intelligence experience - ingesting, enriching, and correlating intel feeds. * Experience with SIEM and log/event correlation (Microsoft Sentinel and/or Splunk preferred; Elastic Security acceptable). * Network analysis fundamentals (Wireshark, Nmap, TCP/IP). * Experience with agentic AI systems, LLM orchestration, prompt engineering, or RAG pipelines. * Familiarity with applying AI to security use cases - anomaly detection, threat classification, alert triage, or intelligence enrichment. * Preferred Qualifications * Container and orchestration experience (Docker, Kubernetes/EKS). * ML-based anomaly/threat detection model development. * HPC or GPU-accelerated systems experience (CUDA, SLURM, NVIDIA clusters) used for AI model development. * RBAC and multi-tenant access control design. * Advanced degree (M.S. or Ph.D.) in cybersecurity, computer engineering, or a related field. * Research or publication background in security, side-channel analysis, or systems security. * SOC operations exposure (Tier-1 or above). * Experience working alongside legal/compliance review on offensive-informed defensive capabilities. * Copyright © TekStream Solutions, LLC 2026 (Tier-1 or above). * Experience working alongside legal/compliance review on offensive-informed defensive capabilities. ## Description We are looking for a Senior Proactive Security Engineer to turn architectural requirements into running, sustainable systems. You will take a deception or detection concept - a sensor design, a threat-intelligence integration, an ML correlation pipeline - and stand it up on real infrastructure so it works on day one and keeps working without breaking. This is a hands-on build-and-maintain role for an engineer who is equally comfortable with system architecture, code, and the security theory behind why it all matters. What You'll Do * Build and operate deception infrastructure. Take requirements for honeynet sensors and emulated customer environments and implement them on servers and cloud infrastructure - provisioning, configuration, hardening, and deployment. * Integrate threat intelligence pipelines. Stand up ingestion, enrichment, and correlation across multiple intelligence sources, and route outputs into platform detection and response workflows. * Engineer detection and event-correlation workflows. Combine system telemetry, behavioral monitoring, and ML-based classification into production-grade detection pipelines. * Translate research into applied systems. Turn security theory and research concepts into production-grade implementations, documented so they are reproducible by the next engineer who touches them. * Own reliability and sustainability. Monitoring, access control, patching, and lifecycle management - the systems you build stay stable in production, not just on demo day. * Integrate AI/ML capabilities. Build and operate LLM-powered analysis pipelines, agentic workflows, and AI-driven enrichment, classification, and detection - engineered to run reliably under production constraints. * Collaborate across the platform. Work with the Proactive Security Lead, MDR/SOC teams, and platform architecture to ensure deception and intelligence outputs integrate cleanly into Cosmos operations., * Build and operate deception infrastructure. Take requirements for honeynet sensors and emulated customer environments and implement them on servers and cloud infrastructure - provisioning, configuration, hardening, and deployment. * Integrate threat intelligence pipelines. Stand up ingestion, enrichment, and correlation across multiple intelligence sources, and route outputs into platform detection and response workflows. * Engineer detection and event-correlation workflows. Combine system telemetry, behavioral monitoring, and ML-based classification into production-grade detection pipelines. * Translate research into applied systems. Turn security theory and research concepts into production-grade implementations, documented so they are reproducible by the next engineer who touches them. * Own reliability and sustainability. Monitoring, access control, patching, and lifecycle management - the systems you build stay stable in production, not just on demo day. * Integrate AI/ML capabilities. Build and operate LLM-powered analysis pipelines, agentic workflows, and AI-driven enrichment, classification, and detection - engineered to run reliably under production constraints. * Collaborate across the platform. Work with the Proactive Security Lead, MDR/SOC teams, and platform architecture to ensure deception and intelligence outputs integrate cleanly into Cosmos operations. ## Related Videos - [Running Secure Life Science Research at Scale using Hybrid GPU HPC and Kubernetes 🧬](https://www.wearedevelopers.com/videos/100355-running-secure-life-science-research-at-scale-using-hybrid-gpu-hpc-and-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)