
You're the detection engineer people turn to when they ask "what does Microsoft actually see here?" Not the marketing-slide answer, the real map. Which product emits which telemetry, any anticipated ingestion lags, what table or API it lands in, which license tier gates it, how long it survives before it ages out, and where the documentation quietly disagrees with reality. When a new technique drops, your first instinct is to ask which Microsoft signal would catch it, and whether customers have it switched on.
You also know Microsoft never sits still. Hunting tables appear, columns get renamed, Graph versions retire, capability shuffles between SKUs, previews go GA, features quietly vanish, and native alert logic shifts underneath you. You've got a repeatable way of staying ahead of that churn instead of finding out when a detection stops firing. You're comfortable behind a command line and in front of a customer, including scenarios where the conversation isn’t pleasant.
At Expel, we help businesses bridge the cybersecurity talent gap by providing transparent Managed Detection and Response. To do this we build technology to make sure our security analysts are solving important problems, and automation is helping them make better decisions at every step.
What Expel Can Do for You
- Make you one of our recognized authorities on Microsoft detection and response — for our SOC, our engineers, our go-to-market teams, and our customers
- Give you real ownership of Expel's detection coverage across the whole Microsoft security estate
- Put Microsoft telemetry from across our customer base in front of you — a breadth of real-world environments no single enterprise gets to see
- Let you write and tune detections in our own rule engine and watch them run against live signal
- Treat AI tooling (Claude Code and friends) as a first-class part of how you work, not a side experiment
- Enable you to learn from analysts, data scientists, engineers, and responders responsible for various components of Expel's product and services
- Provide access to popular EDR, network, SIEM, identity, and cloud technologies well beyond the Microsoft stack
- Challenge you to push the boundaries of our security vision
What You Can Do for Expel
- Own our detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 — from raw signal through to shipped, tuned detections
- Build and maintain a living map of Microsoft security signal: what exists, known ingestion lag, where it lands, what gates it, how long it's kept, and how far you can trust it
- Track how that signal changes and turn every material change into a concrete action — catching drift before it costs us efficacy
- Tell us where Microsoft's native detections are strong enough to lean on, where they're noisy or shallow, and where Expel needs its own layer
- Make SOC analysts faster by automating Microsoft-specific investigative workflows against the Graph, Defender, Sentinel, and Entra APIs
- Partner with Engineering on our Microsoft integrations — ingestion, API limits and throttling, and schema mapping
- Answer the hard questions from the SOC, CS, and Sales — and mentor the people asking them
- Help customers understand what they're actually covered for, what they're missing, and what turning it on would buy them
What You Should Bring With You
- Deep, current, hands-on knowledge of the Microsoft security stack — Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID, Sentinel, Microsoft Graph, and the Azure and Microsoft 365 control and data planes
- Fluency in KQL: you can write, read, optimize, and debug non-trivial hunting queries across both Defender Advanced Hunting and Sentinel, and you know how and why the two schemas differ
- Working knowledge of the Graph and Graph Security APIs, the Defender and Sentinel APIs, and their authentication, permission, versioning, and throttling models
- A strong grasp of the Entra ID (and legacy Active Directory) identity attack surface — authentication flows, conditional access, OAuth application consent, token theft and replay, hybrid identity and sync, privileged role abuse — and the telemetry each produces
- Solid understanding of Windows internals and command line tooling, with enough macOS and Linux to keep up with Defender's cross-platform coverage
- Experience writing, deploying, and tuning custom detections against Microsoft data sets, plus enough non-Microsoft exposure (AWS, GCP, other EDR and SIEM) to keep perspective
- Proficiency with Python and Sigma, and real fluency using Anthropic tools such as Claude Code to work across systems and data (locally, via MCP, etc.)
- 5+ years in information technology or security operations, with substantial time spent defending or operating Microsoft environments
- Excellent tact and diplomacy skills — you can explain Microsoft's limits to an audience that doesn't want to hear about them
- SC-200, AZ-500, or SC-300 certifications are a plus; demonstrated depth matters considerably more
Location & Eligibility
- Our headquarters is in Herndon, Virginia; remote work is fully supported for this role.
- Candidates must be authorized to work in the United States. Expel does not currently sponsor immigration visas.
Timezone overlap
UTC-8–-4
Benefits
Equity, Bonus, Unlimited PTO, Parental leave, Health, Vision, PTO
Open to
US
Sign in to track applications and earn points.