North AmericaFull TimeEngineering
Remotely
siemsplunkedrsigmamitre att&cksoar
Also available on
Job Description
📋 Description
- Join Expel's growing professional services function as a hands-on SIEM detection expert.
- Deliver detection content, tune rules, and optimize SIEMs across customer environments.
- Work across SIEM platforms (Splunk, Microsoft Sentinel, CrowdStrike NG SIEM) and AI-assisted
- Collaborate with Sales, Detection Engineering, SOC, and Customer Success to drive outcomes
- Grow the function and your career through ownership of meaningful outcomes.
🎯 Requirements
- Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM
- 3+ years in detection and response tooling (SIEM, SOAR, EDR).
- 3+ years writing, deploying, and tuning custom detections using Windows Event Logs, auditd
- Experience migrating detection logic between platforms and re-pointing log sources.
- Working knowledge of ATT&CK techniques and attacker tactics.
- Basic proficiency with Python or Go; comfortable with Git/GitHub for content versioning.
🎁 Benefits
- Remote-friendly within the United States with competitive compensation, bonus eligibility, and
- Unlimited PTO, flexible work location, parental leave, and comprehensive health benefits.
- Equal opportunity employer; accommodation available for disabilities.