Managed SIEM Detection Engineer
About the role
Expel's professional services practice is just getting started, and we're looking for a detection engineer to deliver hands-on expertise that prepares customers to thrive under our co-managed SIEM model. You’ll turn around SIEMs that are currently a management burden—reducing costs, cutting alert noise, closing detection gaps, and optimizing ingestion—so they become force multipliers again. The role evolves alongside our customers and the market, with opportunities to work on deeper integrations, AI-assisted tooling, and next-level security strategies.
Responsibilities
- Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing.
- Develop and validate detection content that satisfies defined security use cases, ensuring strong coverage and clean fidelity at onboarding and as environments evolve.
- Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency.
- Contribute to Expel's professional services proprietary detection library, continuously improving detection strategy and capability.
- Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where applicable and validating outputs.
- Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and collaborate with SOC analysts to sharpen rule and alert fidelity.
- Track the evolving threat landscape and develop new detections in response.
- Help the function grow by contributing repeatable processes, templates, and tooling to raise the quality and consistency of deliverables.
Requirements
- Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development.
- 3+ years of experience with detection and response tooling, particularly SIEM, SOAR, and EDR.
- 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar).
- SIEM migration experience translating detection logic between platforms and re-pointing log sources.
- Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework.
- Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms.
- Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates.
- Curiosity, strong ownership, and an appetite for growth.
- Willingness to travel up to 20%.
Nice to have
- One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR).
- Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends.
- Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content.
- Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar.
- A bachelor's degree in Computer Science or Information Security.
Benefits
- Unlimited PTO (modeled and encouraged).
- Work location flexibility.
- Up to 24 weeks of parental leave.
- Excellent health benefits.
Pay
The base salary range for this role is $111,900–$162,300 USD, with a primary target range of $120,000–$140,000 based on experience, skills, and market data. The role also includes bonus eligibility and equity.
Schedule
This role is remote within the United States.