
Managed SIEM Detection Engineer
Expel
Completely RemoteFull TimeInformation Technology
Posted Today
Job description
Responsibilities
- Deliver end-to-end professional services engagements including detection strategy, MITRE ATT&CK assessment, and SIEM optimization
- Develop and validate detection content that satisfies security use cases with high fidelity
- Optimize SIEM performance and cost by tuning detections and improving ingestion efficiency
- Translate detection logic between SIEM platforms and write custom parsers for log sources
- Partner with Detection Engineering and the SOC to hand off environments for co-managed operations
- Track the evolving threat landscape to drive new detection development
Requirements
- Hands-on SIEM expertise in Splunk, Microsoft Sentinel, or CrowdStrike NG SIEM
- 3+ years of experience with detection and response tooling (SIEM, SOAR, EDR)
- 3+ years writing and tuning custom detections from research or investigative work
- Experience with SIEM migration and translating detection logic between platforms
- Working knowledge of MITRE ATT&CK framework and attacker tactics
- Proficiency in Windows, macOS, Linux, networking basics, and cloud IAM models
- Basic proficiency with Python or Go and experience using Git/GitHub
- Willingness to travel up to 20%
Preferred Qualifications
- SIEM or vendor certifications (Splunk Core, Microsoft SC-200, CrowdStrike CCFA/CCFR)
- Experience with Sigma for platform-agnostic detections
- Familiarity with detection-as-code practices and CI/CD pipelines
- Industry security certifications such as GIAC or Security+
- Bachelor's degree in Computer Science or Information Security
About the Company
Expel is a security provider that helps organizations manage their security through co-managed SIEM models and professional services.
Skills & tools
SIEMPythonSplunk
What the team is looking for
Use this list as a quick fit check before you apply.
- 01SIEM expertise (Splunk, Sentinel, or CrowdStrike)
- 023+ years detection/response experience
- 033+ years custom detection tuning experience
- 04Knowledge of MITRE ATT&CK
- 05Python or Go proficiency
- 06Willingness to travel up to 20%
AdWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matches
Expel
Job details
- Work model
- Completely Remote
- Commitment
- Full Time
- Category
- Information Technology
- Posted
- Today
AdWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matches