Managed SIEM Detection Engineer

Expel

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Deliver end-to-end professional services engagements including detection strategy, MITRE ATT&CK assessment, and SIEM optimization
  • Develop and validate detection content that satisfies security use cases with high fidelity
  • Optimize SIEM performance and cost by tuning detections and improving ingestion efficiency
  • Translate detection logic between SIEM platforms and write custom parsers for log sources
  • Partner with Detection Engineering and the SOC to hand off environments for co-managed operations
  • Track the evolving threat landscape to drive new detection development

Requirements

  • Hands-on SIEM expertise in Splunk, Microsoft Sentinel, or CrowdStrike NG SIEM
  • 3+ years of experience with detection and response tooling (SIEM, SOAR, EDR)
  • 3+ years writing and tuning custom detections from research or investigative work
  • Experience with SIEM migration and translating detection logic between platforms
  • Working knowledge of MITRE ATT&CK framework and attacker tactics
  • Proficiency in Windows, macOS, Linux, networking basics, and cloud IAM models
  • Basic proficiency with Python or Go and experience using Git/GitHub
  • Willingness to travel up to 20%

Preferred Qualifications

  • SIEM or vendor certifications (Splunk Core, Microsoft SC-200, CrowdStrike CCFA/CCFR)
  • Experience with Sigma for platform-agnostic detections
  • Familiarity with detection-as-code practices and CI/CD pipelines
  • Industry security certifications such as GIAC or Security+
  • Bachelor's degree in Computer Science or Information Security

About the Company

Expel is a security provider that helps organizations manage their security through co-managed SIEM models and professional services.

Skills & tools

SIEMPythonSplunk

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01SIEM expertise (Splunk, Sentinel, or CrowdStrike)
  2. 023+ years detection/response experience
  3. 033+ years custom detection tuning experience
  4. 04Knowledge of MITRE ATT&CK
  5. 05Python or Go proficiency
  6. 06Willingness to travel up to 20%
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches