
SIEM Detection Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Execute comprehensive professional services projects, encompassing detection strategy, MITRE ATT&CK assessments, SIEM optimization and integrations, SOAR playbook creation, and custom log parsing.
• Create and validate detection content tailored for specific security use cases during onboarding and as environments advance.
• Enhance SIEM performance and cost efficiency by fine-tuning detections, minimizing alert noise, and optimizing ingestion processes.
• Contribute to Expel’s exclusive professional services detection library.
• Convert detection logic between SIEM platforms and develop custom parsers for both standard and non-standard log sources.
• Collaborate with Detection Engineering and the SOC to transition environments for co-managed operations.
• Partner with SOC analysts to enhance rule and alert accuracy and actionability.
• Monitor the evolving threat landscape and leverage it for new detection development initiatives.
• Contribute to the creation of repeatable processes, templates, and tools to enhance delivery quality and consistency.
• Extensive hands-on SIEM expertise with Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule crafting.
• Over 3 years of experience with detection and response tools, particularly SIEM, SOAR, and EDR.
• More than 3 years of experience in writing, deploying, and fine-tuning custom detections utilizing common datasets such as Windows Event Logs, auditd, and CloudTrail.
• Experience with SIEM migrations, translating detection logic between platforms, and re-pointing log sources.
• Familiarity with attacker tactics, techniques, and the MITRE ATT&CK framework.
• Basic understanding of Windows, macOS, and Linux systems.
• Knowledge of networking fundamentals, including TCP/IP and OSI models.
• Working knowledge of cloud IAM models and platforms.
• Basic proficiency in Python, Go, or similar programming languages.
• Comfortable using Git/GitHub for version control of detection content, scripts, and templates.
• Demonstrates curiosity, a strong sense of ownership, and a desire for growth.
• Willingness to travel up to 20% of the time.
• Must be authorized to work in the United States.
• Immigration visa sponsorship is not available at this time.
• Preferred/bonus qualifications: SIEM or vendor certifications; Sigma; detection-as-code and CI/CD knowledge; industry security certifications; bachelor's degree in Computer Science or Information Security.
• Eligibility for bonuses.
• Equity options.
• Unlimited Paid Time Off (PTO).
• Flexible work location.
• Up to 24 weeks of parental leave.
• Excellent health benefits.
• Opportunities for professional development.
• Exposure to complex, high-stakes detection and SIEM challenges.
• Career advancement through ownership of significant outcomes.
• A ground-floor opportunity in a new professional services function.
Catena
Timmons Group
Utilita Energy
Get handpicked remote jobs straight to your inbox weekly.