Senior Detection & Response Engineer

Posted 13hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Detection & Response Engineer owning Microsoft security detections at Expel, which provides transparent managed detection and response. Mapping telemetry, automating investigations, and improving customer coverage.

Responsibilities:

  • Own detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365, from raw signal through shipped and tuned detections
  • Build and maintain a living map of Microsoft security signals, including ingestion lag, destinations, licensing gates, retention, and reliability
  • Track signal changes and turn material changes into concrete actions to prevent detection drift
  • Assess Microsoft's native detections and identify where Expel needs its own detection layer
  • Automate Microsoft-specific investigative workflows against Graph, Defender, Sentinel, and Entra APIs
  • Partner with Engineering on Microsoft integrations, ingestion, API limits, throttling, and schema mapping
  • Answer technical questions from SOC, Customer Success, and Sales teams and mentor colleagues
  • Help customers understand their coverage, gaps, and the value of enabling additional capabilities

Requirements:

  • Deep, current, hands-on knowledge of Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 control and data planes
  • Fluency in KQL, including writing, reading, optimizing, and debugging non-trivial hunting queries across Defender Advanced Hunting and Sentinel
  • Working knowledge of Graph, Graph Security, Defender, and Sentinel APIs, including authentication, permissions, versioning, and throttling models
  • Strong understanding of Entra ID and legacy Active Directory identity attack surfaces and related telemetry
  • Solid understanding of Windows internals and command line tooling, with enough macOS and Linux knowledge for cross-platform coverage
  • Experience writing, deploying, and tuning custom detections against Microsoft datasets
  • Exposure to AWS, GCP, and other EDR and SIEM platforms
  • Proficiency with Python and Sigma
  • Fluency using Anthropic tools such as Claude Code, locally and via MCP
  • 5+ years in information technology or security operations, with substantial experience defending or operating Microsoft environments
  • Excellent tact and diplomacy skills
  • SC-200, AZ-500, or SC-300 certification is a plus
  • Must be authorized to work in the United States
  • Expel does not currently sponsor immigration visas

Benefits:

  • Bonus eligibility
  • Equity
  • Unlimited PTO
  • Work location flexibility
  • Up to 24 weeks of parental leave
  • Excellent health benefits
  • Reasonable accommodation for disabilities