Managed SIEM Detection Engineer
Expel · Remote
About this role
**Managed SIEM Detection Engineer (Expel)** Are you a detection engineer who wants to bring deep expertise into a new and growing function—and use it to deliver security excellence to customers? Expel’s professional services practice is just getting started, and we’re looking for a technical expert to help customers thrive under our co-managed SIEM model. --- ## The work Customers come to us with SIEMs that *should* be surfacing threats but are instead consuming their teams—through rising ingestion costs, alert noise, broken pipelines, and detection blind spots. You’ll: - Author and tune detection content for real security use cases - Close coverage gaps and migrate detection logic off legacy platforms - Optimize what customers ingest and pay for so their SIEM becomes a force multiplier (not a burden) - Help the function evolve with deeper integrations and automated/AI-assisted tooling --- ## What Expel can do for you - Ground-floor seat in a new professional services function where your expertise shapes customer outcomes - Real runway for professional development as the function grows - Complex, high-stakes detection and SIEM problems across a wide range of customer environments - Work across leading SIEM platforms, including **Splunk**, **Microsoft Sentinel**, and **CrowdStrike NG SIEM** (plus emerging AI-assisted tooling) - Visibility and partnership across Sales, Detection Engineering, the SOC, and Customer Success - Own meaningful outcomes end to end --- ## What you can do for Expel - Deliver end-to-end professional services engagements: detection strategy, **MITRE ATT&CK** assessment, SIEM optimization/integrations, **SOAR** playbook development, and custom log parsing - Develop and validate detection content at onboarding and as environments evolve (strong coverage + clean fidelity) - Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency - Contribute to Expel’s proprietary detection library to continuously improve detection strategy and capability - Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources (using AI-assisted tools where helpful) and validate outputs - Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations; sharpen rule/alert fidelity and actionability - Track the evolving threat landscape and turn it into new detection development - Help the function grow with repeatable processes, templates, and tooling --- ## What you should bring to Expel - Hands-on SIEM expertise across **Splunk**, **Microsoft Sentinel**, and/or **CrowdStrike NG SIEM** (architecture, data ingestion, detection rule development) - **3+ years** with detection and response tooling—especially **SIEM, SOAR, and EDR** - **3+ years** writing, deploying, and tuning custom detections from research/investigative work against common datasets (e.g., Windows Event Logs, auditd, CloudTrail) - SIEM migration experience translating detection logic between platforms and re-pointing log sources - Working knowledge of attacker tactics/techniques and the **MITRE ATT&CK** framework - Solid fundamentals across **Windows, macOS, and Linux**, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models/platforms - Basic proficiency with **Python, Go, or similar**; comfort using **Git/GitHub** for version control of detection content/scripts/templates - Curios
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.