Expel
Managed SIEM Detection Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 5 weeks ago · Added 5 days ago
Been open since 5 weeks ago, still being checked, but it has been live a while.
Salary
$112k per year
Location
United States only
Timezone
Not stated
Contract
Full-time
Experience
Mid
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the listing expects you to be based in United States.
What the employer says
- Source listing states candidate location: "Remote"
- Listing states: "This role is remote within the United States."
What Nomaders makes of it
- Confirm with the employer before assuming you can work from another country
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself.
Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.
And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.
What Expel can do for you
Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
Provide real runway for professional development as the function grows
Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
Accelerate your career by letting you own meaningful outcomes end to end
What you can do for Expel
Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability
Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
Track the evolving threat landscape and turn it into new detection development
Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver
What you should bring to Expel
Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
SIEM migration experience translating detection logic between platforms and re-pointing log sources
Requirements
- ·Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
- ·3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
- ·3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
- ·SIEM migration experience translating detection logic between platforms and re-pointing log sources
- ·Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Expel, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$112k per year · You'll be taken to the employer's careers page.