Skip to content
Expel logo

Managed SIEM Detection Engineer

ExpelManaged Detection company
United States$111,900 - $162,300 USDSenior
CapitalG logo
CapitalG
Paladin Capital Group
Scale Venture Partners logo
Scale Venture Partners
March Capital
Index Ventures logo
Index Ventures
Battery Ventures logo
Battery Ventures
Software EngineeringNew

About the role

TL;DR

Develop and optimize SIEM detection content for customers, ensuring security excellence.

  • Expel is seeking a skilled Detection Engineer to join its new and growing professional services practice.
  • This role will be instrumental in delivering security excellence to customers by authoring and tuning detection content, optimizing SIEM performance, and closing security coverage gaps.
  • Key Responsibilities Author and tune detection content for real security use cases.
  • Migrate detection logic off legacy platforms and optimize SIEM ingestion.
  • Develop and validate detection content with strong coverage and clean fidelity.
  • Translate detection logic between SIEM platforms and write custom parsers.
  • Requirements Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM. 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR. 3+ years writing, deploying, and tuning custom detections.
  • Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework.
  • Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub.
View original posting →

Required skills

PythonGoGitLinux

Nice-to-have skills

AWSGoogle CloudAzure

Domain expertise

cybersecurity

Benefits & perks

bonus eligibility, equity, unlimited PTO, work location flexibility, parental leave, health benefits

Tech stack

PythonGoGitLinuxAWSGoogle CloudAzure

Similar jobs

O

Senior Dev Ops Engineer

E

Systems Engineer

O

Senior Cloud Ops Engineer