Managed SIEM Detection Engineer
E
ExpelCybersecurity
This role is remote within the United States.Full-TimeMiddle
Salary$111,900 USD to $162,300 USD + bonus eligibility and equity
Apply NowOpens the employer's application page
Job Details
- Experience
- 3+ years
- Required Skills
- PythonGitGo
Requirements
- 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR.
- 3+ years writing, deploying, and tuning custom detections against datasets like Windows Event Logs, auditd, and CloudTrail.
- Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM.
- Experience with SIEM migration and translating detection logic between platforms.
- Working knowledge of attacker tactics, techniques, and the MITRE ATT&CK framework.
- Solid fundamentals in Windows, macOS, and Linux systems.
- Understanding of networking basics including TCP/IP and OSI model.
- Working knowledge of cloud IAM models and platforms.
- Basic proficiency with Python, Go, or similar languages.
- Comfort using Git/GitHub for version control of detection content and scripts.
- Willingness to travel up to 20%.
Responsibilities
- Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization, and SOAR playbook development.
- Develop and validate detection content that satisfies defined security use cases with strong coverage and clean fidelity.
- Optimize SIEM performance and cost by tuning detections, reducing alert noise, and improving ingestion efficiency.
- Translate detection logic between SIEM platforms and write custom parsers for log sources.
- Partner with Detection Engineering and SOC teams to prepare environments for ongoing co-managed operations.
- Track the evolving threat landscape to inform new detection development.
- Contribute to internal professional services processes, templates, and proprietary detection libraries.
View Full Description & ApplyYou'll be redirected to the employer's site