Managed SIEM Detection Engineer
ExpelManaged Detection company
United States$111,900 - $162,300 USDSenior
CapitalG
Scale Venture Partners
Index Ventures
Battery Ventures
Paladin Capital Group
March Capital
Software EngineeringNew
About the role
TL;DR
Develop and optimize SIEM detection content for customers, ensuring security excellence.
- •Expel is seeking a skilled Detection Engineer to join its new and growing professional services practice.
- •This role will be instrumental in delivering security excellence to customers by authoring and tuning detection content, optimizing SIEM performance, and closing security coverage gaps.
- •Key Responsibilities Author and tune detection content for real security use cases.
- •Migrate detection logic off legacy platforms and optimize SIEM ingestion.
- •Develop and validate detection content with strong coverage and clean fidelity.
- •Translate detection logic between SIEM platforms and write custom parsers.
- •Requirements Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM. 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR. 3+ years writing, deploying, and tuning custom detections.
- •Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework.
- •Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub.
Required skills
PythonGoGitLinux
Nice-to-have skills
AWSGoogle CloudAzure
Domain expertise
cybersecurity
Benefits & perks
bonus eligibility, equity, unlimited PTO, work location flexibility, parental leave, health benefits
Tech stack
PythonGoGitLinuxAWSGoogle CloudAzure