CronJobs

security jobs

Managed SIEM Detection Engineer

Expel · Remote

remoteunknown$111,900–$111,900Posted Aug 17, 2026SplunkMicrosoft SentinelCrowdStrike NG SIEMSOARMITRE ATT&CKPythonGoGit

Apply on the employer site

About this role

**Managed SIEM Detection Engineer (Expel)** Are you a detection engineer who wants to bring deep expertise into a new and growing function—and use it to deliver security excellence to customers? Expel’s professional services practice is just getting started, and we’re looking for a technical expert to help customers thrive under our co-managed SIEM model. --- ## The work Customers come to us with SIEMs that *should* be surfacing threats but are instead consuming their teams—through rising ingestion costs, alert noise, broken pipelines, and detection blind spots. You’ll: - Author and tune detection content for real security use cases - Close coverage gaps and migrate detection logic off legacy platforms - Optimize what customers ingest and pay for so their SIEM becomes a force multiplier (not a burden) - Help the function evolve with deeper integrations and automated/AI-assisted tooling --- ## What Expel can do for you - Ground-floor seat in a new professional services function where your expertise shapes customer outcomes - Real runway for professional development as the function grows - Complex, high-stakes detection and SIEM problems across a wide range of customer environments - Work across leading SIEM platforms, including **Splunk**, **Microsoft Sentinel**, and **CrowdStrike NG SIEM** (plus emerging AI-assisted tooling) - Visibility and partnership across Sales, Detection Engineering, the SOC, and Customer Success - Own meaningful outcomes end to end --- ## What you can do for Expel - Deliver end-to-end professional services engagements: detection strategy, **MITRE ATT&CK** assessment, SIEM optimization/integrations, **SOAR** playbook development, and custom log parsing - Develop and validate detection content at onboarding and as environments evolve (strong coverage + clean fidelity) - Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency - Contribute to Expel’s proprietary detection library to continuously improve detection strategy and capability - Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources (using AI-assisted tools where helpful) and validate outputs - Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations; sharpen rule/alert fidelity and actionability - Track the evolving threat landscape and turn it into new detection development - Help the function grow with repeatable processes, templates, and tooling --- ## What you should bring to Expel - Hands-on SIEM expertise across **Splunk**, **Microsoft Sentinel**, and/or **CrowdStrike NG SIEM** (architecture, data ingestion, detection rule development) - **3+ years** with detection and response tooling—especially **SIEM, SOAR, and EDR** - **3+ years** writing, deploying, and tuning custom detections from research/investigative work against common datasets (e.g., Windows Event Logs, auditd, CloudTrail) - SIEM migration experience translating detection logic between platforms and re-pointing log sources - Working knowledge of attacker tactics/techniques and the **MITRE ATT&CK** framework - Solid fundamentals across **Windows, macOS, and Linux**, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models/platforms - Basic proficiency with **Python, Go, or similar**; comfort using **Git/GitHub** for version control of detection content/scripts/templates - Curios

Listing freshness

CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord