
Managed SIEM Detection Engineer
Expel
WorldwideFully remoteFull TimeInformation Technology
No salary statedPosted 29 days ago4w ago
Why we think you can apply
- Hiring model
- Open worldwide · the employer states no country restriction
- Work from
- Anywhere, the UAE included
Posted 29 days ago
About the role
Responsibilities
- Deliver end-to-end professional services engagements including detection strategy, MITRE ATT&CK assessment, and SIEM optimization
- Develop and validate detection content that satisfies security use cases with high fidelity
- Optimize SIEM performance and cost by tuning detections and improving ingestion efficiency
- Translate detection logic between SIEM platforms and write custom parsers for log sources
- Partner with Detection Engineering and the SOC to hand off environments for co-managed operations
- Track the evolving threat landscape to drive new detection development
Requirements
- Hands-on SIEM expertise in Splunk, Microsoft Sentinel, or CrowdStrike NG SIEM
- 3+ years of experience with detection and response tooling (SIEM, SOAR, EDR)
- 3+ years writing and tuning custom detections from research or investigative work
- Experience with SIEM migration and translating detection logic between platforms
- Working knowledge of MITRE ATT&CK framework and attacker tactics
- Proficiency in Windows, macOS, Linux, networking basics, and cloud IAM models
- Basic proficiency with Python or Go and experience using Git/GitHub
- Willingness to travel up to 20%
Preferred Qualifications
- SIEM or vendor certifications (Splunk Core, Microsoft SC-200, CrowdStrike CCFA/CCFR)
- Experience with Sigma for platform-agnostic detections
- Familiarity with detection-as-code practices and CI/CD pipelines
- Industry security certifications such as GIAC or Security+
- Bachelor's degree in Computer Science or Information Security
About the Company
Expel is a security provider that helps organizations manage their security through co-managed SIEM models and professional services.
What we look for
- SIEM expertise (Splunk, Sentinel, or CrowdStrike)
- 3+ years detection/response experience
- 3+ years custom detection tuning experience
- Knowledge of MITRE ATT&CK
- Python or Go proficiency
- Willingness to travel up to 20%
SIEMPythonSplunk
SponsorWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matchesSimilar jobsbased on title, category and scope

Expel
SponsorWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matchesManaged SIEM Detection EngineerExpel · 3 free applies a month