Senior Detection & Response Engineer
Posted 13hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Detection & Response Engineer owning Microsoft security detections at Expel, which provides transparent managed detection and response. Mapping telemetry, automating investigations, and improving customer coverage.
Responsibilities:
- Own detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365, from raw signal through shipped and tuned detections
- Build and maintain a living map of Microsoft security signals, including ingestion lag, destinations, licensing gates, retention, and reliability
- Track signal changes and turn material changes into concrete actions to prevent detection drift
- Assess Microsoft's native detections and identify where Expel needs its own detection layer
- Automate Microsoft-specific investigative workflows against Graph, Defender, Sentinel, and Entra APIs
- Partner with Engineering on Microsoft integrations, ingestion, API limits, throttling, and schema mapping
- Answer technical questions from SOC, Customer Success, and Sales teams and mentor colleagues
- Help customers understand their coverage, gaps, and the value of enabling additional capabilities
Requirements:
- Deep, current, hands-on knowledge of Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 control and data planes
- Fluency in KQL, including writing, reading, optimizing, and debugging non-trivial hunting queries across Defender Advanced Hunting and Sentinel
- Working knowledge of Graph, Graph Security, Defender, and Sentinel APIs, including authentication, permissions, versioning, and throttling models
- Strong understanding of Entra ID and legacy Active Directory identity attack surfaces and related telemetry
- Solid understanding of Windows internals and command line tooling, with enough macOS and Linux knowledge for cross-platform coverage
- Experience writing, deploying, and tuning custom detections against Microsoft datasets
- Exposure to AWS, GCP, and other EDR and SIEM platforms
- Proficiency with Python and Sigma
- Fluency using Anthropic tools such as Claude Code, locally and via MCP
- 5+ years in information technology or security operations, with substantial experience defending or operating Microsoft environments
- Excellent tact and diplomacy skills
- SC-200, AZ-500, or SC-300 certification is a plus
- Must be authorized to work in the United States
- Expel does not currently sponsor immigration visas
Benefits:
- Bonus eligibility
- Equity
- Unlimited PTO
- Work location flexibility
- Up to 24 weeks of parental leave
- Excellent health benefits
- Reasonable accommodation for disabilities
















