--- title: 'Managed SIEM Detection Engineer at Expel' canonical: 'https://feeny.ai/job/managed-siem-detection-engineer-expel-remote-yqgq7z6byexj' type: 'job' last_seen: '2026-09-09' --- # Managed SIEM Detection Engineer at Expel - **Company:** Expel - **Location:** Remote - **Compensation:** $112k–$162k - **Work type:** remote - **Posted:** 2026-08-15 - **Last confirmed live:** 2026-09-09 - **Apply:** https://expel.com/about/career-listing/8718734002?gh_jid=8718734002 ## Job description Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself. Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden. And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next. What Expel can do for you - Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers - Provide real runway for professional development as the function grows - Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments - Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling - Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success - Accelerate your career by letting you own meaningful outcomes end to end ## What you can do for Expel - Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing - Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity - Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency - Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability - Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs - Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts - Track the evolving threat landscape and turn it into new detection development - Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver ## What you should bring to Expel - Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development - 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR - 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar) - SIEM migration experience translating detection logic between platforms and re-pointing log sources - Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework - Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms - Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates - Curiosity, strong ownership, and the appetite for growth - A willingness to travel up to 20% Bonus points for - One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR) - Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends - Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content - Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar - A bachelor's degree in Computer Science or Information Security Additional notes This role is remote within the United States. The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data. We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits. We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas. We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability. We'll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind. #LI-Remote Salary Range $111,900—$162,300 USD ## About Expel ## Company Overview - **One-liner**: Expel provides managed detection and response (MDR) security services, combining practitioner-led human analysts with AI augmentation to deliver rapid, transparent threat remediation. - **Entity Type**: Private (late-stage, unicorn status reached in November 2021) - **Headquarters**: Not explicitly stated in provided sources (publicly known as Herndon, Virginia, USA) - **Founded**: 2016 - **Founders**: Dave Merkel ## Core Business - **Primary industry/industries**: Cybersecurity, Managed Detection and Response (MDR) - **Target customers**: B2B – enterprise and SMB organizations seeking outsourced security operations - **Mission or purpose statement**: “To evolve security operations through practitioner-led, AI-augmented solutions that adapt to our customers, integrate easily, and prove value with measurable outcomes” ## Products & Services - **Expel Managed Detection and Response (MDR)**: 24×7 monitoring and response using clients’ existing security tools, with direct access to human analysts via Slack or Teams. Achieves a 14-minute mean time to remediate. - **Ruxie AI**: Agentic AI models that work across the full threat lifecycle, accelerating analyst decision-making without replacing human judgment. - **Expel Workbench™**: A transparency portal providing real-time visibility into every alert, investigation, and action taken by the SOC. - **Managed Phishing Service**: Dedicated phishing detection and response (launched October 2020). - **Partner Program**: Relaunched in September 2023 with a new partner portal and program structure. ## Market Standing - **Valuation/Market Cap**: $1B+ unicorn valuation (as of November 2021). - **Key Metric**: Annual revenue not publicly disclosed; total funding amount not specified in provided sources. - **Notable Investors/Partners**: Not specified in the provided search results. - **Growth Signals**: - Named a Leader in Forrester Wave™: MDR Services, Q1 2025 (5/5 in 15 of 21 criteria). - Five consecutive years on Deloitte’s Technology Fast 500 Rankings. - Expanded into EMEA (October 2022). - 90% reduction in investigation volume and 50% improvement in recovery time for a customer. - Recognized on multiple Great Place to Work® lists in 2023. ## Competitive Advantages - **AI‑intentional MDR**: Ruxie AI augments human analysts across the entire threat lifecycle, delivering speed (14-minute MTTR) without sacrificing accuracy. - **Full transparency**: Expel Workbench gives customers real-time visibility into every alert and action – “go ahead; check our work.” - **Practitioner‑led approach**: Founded by industry veterans who were “fed up with MDR” noise and hidden metrics. - **Vendor‑agnostic integration**: Works with the security tools customers already own, minimizing disruption. - **Measurable outcomes**: Publishes verified results (e.g., 64% MTTR improvement for one customer). ## Strategic Focus - **Agentic MDR**: Deepening AI capabilities to automate where it counts while keeping humans in the loop. - **Global expansion**: Growing presence in EMEA and building out partner channels. - **Continuous improvement**: Culture of “everything must get a little bit better the next time” and “measure what matters.” ## Why Work Here - **Culture**: Values include “intentionally transparent,” “get it done. do it together,” “treat people like people,” and “improve continuously.” Employee Resource Groups (BOLD for Black Expletives, WE for women, Treehouse for LGBTQ+, and Connection for mental well-being). - **Work flexibility**: “Flexible work hours and locations” – start early, stay late, step away; remote-friendly environment. - **Benefits**: 24 weeks parental leave, unlimited vacation (with encouragement to actually take it), 401(k) 100% match up to 3%, 100% medical deductible coverage, one paid conference per year, and group life/income protection (UK/Ireland roles). - **Recognition**: 99% of employees say management is honest and ethical, 99% felt welcome on joining, and 98% are proud to tell others they work there. Great Place to Work® certifications include Fortune Best Workplaces for Women (#12, 2023), Best Workplaces in Technology (#8, 2023), and Best Medium Workplaces (#15, 2023). ## Sources 1. [expel.com](https://expel.com/about/) – Company overview, mission, history, leadership 2. [expel.com](https://expel.com/) – Product details, MDR capabilities, Forrester recognition 3. [expel.com](https://expel.com/about/careers/) – Career page, values, benefits, interview process 4. [expel.com](https://expel.com/about/eid/) – Equity, inclusion & diversity, ERGs 5. [expel.com](https://expel.com/blog/what-makes-expel-a-great-place-to-work/) – Great Place to Work awards and employee survey results ## Other roles at Expel - [Senior Deal Desk Manager](https://feeny.ai/job/senior-deal-desk-manager-expel-remote-vpb50adzhv8v) - [Senior Security Solutions Engineer](https://feeny.ai/job/senior-security-solutions-engineer-expel-remote-17jtkkbarmzx) - [Systems Engineer](https://feeny.ai/job/systems-engineer-expel-herndon-nmjpwq9pdfyr) — Herndon, VA - [Product Manager, Detection Pipeline](https://feeny.ai/job/product-manager-detection-pipeline-expel-remote-qcwggmg9t1f5) - [Enterprise Account Executive - New England](https://feeny.ai/job/enterprise-account-executive-new-england-expel-remote-q00wppt2ecee) - [Customer Success Manager, Scale](https://feeny.ai/job/customer-success-manager-scale-expel-remote-9c30gzv5hyr0) - [Join Our Community of Prospective Expletives](https://feeny.ai/job/join-our-community-of-prospective-expletives-expel-herndon-zdhac1r4qrcr) — Herndon, VA