
Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model.
Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for.
What you can do for Expel
- Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing.
- Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve.
- Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency.
- Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability.
- Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources.
- Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations.
- Track the evolving threat landscape and turn it into new detection development.
What you should bring to Expel
- Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development.
- 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR.
- 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail).
- SIEM migration experience translating detection logic between platforms and re-pointing log sources.
- Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework.
- Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms.
- Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control.
- A willingness to travel up to 20%.
Bonus points for
- One or more SIEM or vendor certifications (e.g., Splunk, Microsoft SC-200, CrowdStrike).
- Experience authoring platform-agnostic detections with Sigma.
- Familiarity with detection-as-code practices and CI/CD for detection content.
- Industry security certifications such as GIAC, Security+, or similar.
- A bachelor's degree in Computer Science or Information Security.
Timezone overlap
UTC-8–-4
Benefits
Bonus, Equity, Health, Unlimited PTO, Parental leave, PTO, Learning
Open to
US
Sign in to track applications and earn points.