SIEM Detection Engineer

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Managed SIEM Detection Engineer delivering detection strategy, migration, and optimization services. Helping Expel customers strengthen co-managed security monitoring across SIEM platforms.

Responsibilities:

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
  • Develop and validate detection content for defined security use cases during onboarding and as environments evolve
  • Optimize SIEM performance and cost by tuning detections, reducing alert noise, and improving ingestion efficiency
  • Contribute to Expel’s proprietary professional services detection library
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources
  • Partner with Detection Engineering and the SOC to hand off environments for co-managed operations
  • Work with SOC analysts to improve rule and alert fidelity and actionability
  • Track the evolving threat landscape and turn it into new detection development
  • Contribute repeatable processes, templates, and tooling to improve delivery quality and consistency

Requirements:

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
  • 3+ years writing, deploying, and tuning custom detections using common datasets such as Windows Event Logs, auditd, and CloudTrail
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources
  • Working knowledge of attacker tactics, techniques, and the MITRE ATT&CK framework
  • Fundamentals across Windows, macOS, and Linux
  • Networking basics, including TCP/IP and OSI
  • Working knowledge of cloud IAM models and platforms
  • Basic proficiency with Python, Go, or similar
  • Comfort using Git/GitHub for version control of detection content, scripts, and templates
  • Curiosity, strong ownership, and appetite for growth
  • Willingness to travel up to 20%
  • Must be authorized to work in the United States
  • Immigration visa sponsorship is not currently available
  • Preferred/bonus: SIEM or vendor certifications; Sigma; detection-as-code and CI/CD; industry security certifications; bachelor’s degree in Computer Science or Information Security

Benefits:

  • Bonus eligibility
  • Equity
  • Unlimited PTO
  • Work location flexibility
  • Up to 24 weeks of parental leave
  • Really excellent health benefits
  • Professional development runway
  • Exposure to complex, high-stakes detection and SIEM problems
  • Career growth through ownership of meaningful outcomes
  • Ground-floor opportunity in a new professional services function