SIEM Detection Engineer

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $111.9k - $162.3k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👷🏻‍♀️ Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Expel

Expel

201 - 500 employees

Founded 2016

🔒 Cybersecurity

☁️ SaaS

Cybersecurity • SaaS • Technology

Expel is a leading cybersecurity company specializing in Managed Detection and Response (MDR) services. They offer a range of solutions, including phishing investigation, threat hunting, and vulnerability prioritization, tailored for organizations of all sizes with 24x7 protection. Expel's Security Operations Platform, Expel Workbench™, integrates with existing tech to enhance security operations. Their expert team and advanced technology help reduce alert noise, respond swiftly to incidents, and improve overall security posture, enabling organizations to focus on core business activities without worrying about cybersecurity threats.

📋 Description

• Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing • Develop and validate detection content for defined security use cases during onboarding and as environments evolve • Optimize SIEM performance and cost by tuning detections, reducing alert noise, and improving ingestion efficiency • Contribute to Expel’s proprietary professional services detection library • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources • Partner with Detection Engineering and the SOC to hand off environments for co-managed operations • Work with SOC analysts to improve rule and alert fidelity and actionability • Track the evolving threat landscape and turn it into new detection development • Contribute repeatable processes, templates, and tooling to improve delivery quality and consistency

🎯 Requirements

• Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR • 3+ years writing, deploying, and tuning custom detections using common datasets such as Windows Event Logs, auditd, and CloudTrail • SIEM migration experience translating detection logic between platforms and re-pointing log sources • Working knowledge of attacker tactics, techniques, and the MITRE ATT&CK framework • Fundamentals across Windows, macOS, and Linux • Networking basics, including TCP/IP and OSI • Working knowledge of cloud IAM models and platforms • Basic proficiency with Python, Go, or similar • Comfort using Git/GitHub for version control of detection content, scripts, and templates • Curiosity, strong ownership, and appetite for growth • Willingness to travel up to 20% • Must be authorized to work in the United States • Immigration visa sponsorship is not currently available • Preferred/bonus: SIEM or vendor certifications; Sigma; detection-as-code and CI/CD; industry security certifications; bachelor’s degree in Computer Science or Information Security

🏖️ Benefits

• Bonus eligibility • Equity • Unlimited PTO • Work location flexibility • Up to 24 weeks of parental leave • Really excellent health benefits • Professional development runway • Exposure to complex, high-stakes detection and SIEM problems • Career growth through ownership of meaningful outcomes • Ground-floor opportunity in a new professional services function

Apply Now

Similar Jobs

🔥 39 minutes ago

ASR Group

5001 - 10000

🍽️ Food & Beverage

🏭 Manufacturing

🌾 Agriculture

Lead complex capital programs for ASR Group, the world’s largest cane-sugar refiner and marketer. Oversee engineering, budgets, commissioning, compliance, and cross-functional project delivery across refinery operations.

🔥 51 minutes ago

Sargent & Lundy

1001 - 5000

🏗️ Construction

🎖️ Defense

⚡ Energy

Lead structural engineering for Sargent & Lundy’s nuclear facilities and plant modernization projects. Guiding teams through safety-related analysis, design calculations, specifications, and client coordination.

🔥 1 hour ago

Sargent & Lundy

1001 - 5000

🏗️ Construction

🎖️ Defense

⚡ Energy

Senior structural engineer analyzing safety-related nuclear structures for Sargent & Lundy. Leading design calculations, blast and seismic analysis, and engineering automation for clean-energy projects.

🔥 2 hours ago

General Dynamics Ordnance and Tactical Systems

1001 - 5000

🚀 Aerospace

🎖️ Defense

🏭 Manufacturing

Project Engineer II leading solid rocket motor design, manufacturing, and delivery projects. Coordinating integrated teams, schedules, budgets, resources, and technical customer requirements for aerospace and defense products.

🔥 4 hours ago

NetCov

201 - 500

🔒 Cybersecurity

🤝 B2B

💼 Consulting

Service Desk Engineer delivering managed IT and cybersecurity services for NetCov clients. Managing infrastructure, resolving complex issues, and guiding managed services teams.

🇺🇸 United States – Remote

💵 $61.9k - $82.5k / year

💰 Private equity on 2022-11

⏰ Full Time

🟡 Mid-level

🟠 Senior

👷🏻‍♀️ Engineer