Remotery

SIEM Detection Engineer

atExpelRemoteUS flagUnited StatesFull-timeEngineerMid-levelSenior$111.9k – $162.3k/year

Posted 2 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Execute comprehensive professional services projects, encompassing detection strategy, MITRE ATT&CK assessments, SIEM optimization and integrations, SOAR playbook creation, and custom log parsing.

• Create and validate detection content tailored for specific security use cases during onboarding and as environments advance.

• Enhance SIEM performance and cost efficiency by fine-tuning detections, minimizing alert noise, and optimizing ingestion processes.

• Contribute to Expel’s exclusive professional services detection library.

• Convert detection logic between SIEM platforms and develop custom parsers for both standard and non-standard log sources.

• Collaborate with Detection Engineering and the SOC to transition environments for co-managed operations.

• Partner with SOC analysts to enhance rule and alert accuracy and actionability.

• Monitor the evolving threat landscape and leverage it for new detection development initiatives.

• Contribute to the creation of repeatable processes, templates, and tools to enhance delivery quality and consistency.


⛳️ Requirements

• Extensive hands-on SIEM expertise with Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule crafting.

• Over 3 years of experience with detection and response tools, particularly SIEM, SOAR, and EDR.

• More than 3 years of experience in writing, deploying, and fine-tuning custom detections utilizing common datasets such as Windows Event Logs, auditd, and CloudTrail.

• Experience with SIEM migrations, translating detection logic between platforms, and re-pointing log sources.

• Familiarity with attacker tactics, techniques, and the MITRE ATT&CK framework.

• Basic understanding of Windows, macOS, and Linux systems.

• Knowledge of networking fundamentals, including TCP/IP and OSI models.

• Working knowledge of cloud IAM models and platforms.

• Basic proficiency in Python, Go, or similar programming languages.

• Comfortable using Git/GitHub for version control of detection content, scripts, and templates.

• Demonstrates curiosity, a strong sense of ownership, and a desire for growth.

• Willingness to travel up to 20% of the time.

• Must be authorized to work in the United States.

• Immigration visa sponsorship is not available at this time.

• Preferred/bonus qualifications: SIEM or vendor certifications; Sigma; detection-as-code and CI/CD knowledge; industry security certifications; bachelor's degree in Computer Science or Information Security.


🏝️ Benefits

• Eligibility for bonuses.

• Equity options.

• Unlimited Paid Time Off (PTO).

• Flexible work location.

• Up to 24 weeks of parental leave.

• Excellent health benefits.

• Opportunities for professional development.

• Exposure to complex, high-stakes detection and SIEM challenges.

• Career advancement through ownership of significant outcomes.

• A ground-floor opportunity in a new professional services function.

People also viewed

Catena13 hours ago

Forward Deployed Engineer

MX flagMexico, +4 more statesFull-timeEngineer
ApplyView job
Petco14 hours ago

Identity Engineer

MX flagMexico OnlyFull-timeEngineer
ApplyView job
Timmons Group14 hours ago

Civil Project Engineer II/III – Renewable Energy Structural Design

US flagVirginia OnlyFull-timeEngineer$82k – $90k/year
ApplyView job
Utilita Energy15 hours ago

Dual Fuel Smart Meter Engineer

GB flagUnited Kingdom OnlyFull-timeEngineer£39k/year
ApplyView job
NVIDIA15 hours ago

Deep Learning Compiler Engineer

US flagCalifornia, +3 more statesFull-timeEngineer$152k – $241.5k/year
ApplyView job
GE Vernova16 hours ago

Lead Commissioning Engineer

GB flagUnited Kingdom OnlyFull-timeEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers