
Senior Detection & Response Engineer
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in Virginia.
• Take charge of detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365, managing everything from raw signals to deployed and optimized detections.
• Create and sustain a dynamic map of Microsoft security signals, detailing aspects such as ingestion delays, destinations, licensing requirements, retention, and reliability.
• Monitor signal modifications and convert significant changes into actionable steps to avert detection drift.
• Evaluate Microsoft's built-in detections and determine where Expel needs to implement its own detection framework.
• Streamline Microsoft-specific investigative workflows utilizing Graph, Defender, Sentinel, and Entra APIs.
• Collaborate with Engineering on Microsoft integrations, signal ingestion, API limitations, throttling, and schema mapping.
• Address technical inquiries from SOC, Customer Success, and Sales teams while mentoring team members.
• Assist customers in comprehending their coverage, identifying gaps, and recognizing the benefits of activating additional capabilities.
• Extensive, current, hands-on expertise in Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 control and data planes.
• Proficient in KQL, including the ability to write, read, optimize, and debug complex hunting queries across Defender Advanced Hunting and Sentinel.
• Familiarity with Graph, Graph Security, Defender, and Sentinel APIs, covering authentication, permissions, versioning, and throttling models.
• Strong comprehension of Entra ID and legacy Active Directory identity attack surfaces along with the associated telemetry.
• Solid grasp of Windows internals and command line tools, complemented by sufficient macOS and Linux knowledge for cross-platform support.
• Experience in crafting, deploying, and fine-tuning custom detections against Microsoft datasets.
• Exposure to AWS, GCP, and other EDR and SIEM platforms.
• Proficient in Python and Sigma.
• Fluent in using Anthropic tools such as Claude Code, both locally and via MCP.
• Over 5 years of experience in information technology or security operations, with significant involvement in defending or managing Microsoft environments.
• Exceptional tact and diplomacy skills.
• SC-200, AZ-500, or SC-300 certification is advantageous.
• Must have authorization to work in the United States.
• Expel does not currently provide immigration visa sponsorship.
• Bonus eligibility.
• Equity options.
• Unlimited paid time off (PTO).
• Flexible work location.
• Up to 24 weeks of parental leave.
• Comprehensive health benefits.
• Reasonable accommodations for disabilities.
Mercor
RTX
Qualus
General Dynamics Information Technology
Get handpicked remote jobs straight to your inbox weekly.