SlipstreamJobsFresh Startup & VC-Backed Jobs

Managed SIEM Detection Engineer

Expel - Remote - Remote - posted 2026-08-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Expel is seeking a Managed SIEM Detection Engineer to join its growing professional services practice. You'll be a hands-on technical expert delivering security excellence to customers through co-managed SIEM services. In this role, you'll author and tune detection content that addresses real security use cases, close coverage gaps, migrate detection logic from legacy platforms, and optimize SIEM ingestion costs and performance. You'll work across leading platforms including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling. Key responsibilities include: - Delivering end-to-end professional services engagements: detection strategy, MITRE ATT&CK assessments, SIEM optimization, SOAR playbook development, and custom log parsing - Developing and validating detection content with strong coverage and clean fidelity - Optimizing SIEM performance by tuning detections, reducing alert noise, and improving ingestion efficiency - Contributing to Expel's proprietary detection library - Translating detection logic between SIEM platforms and writing custom parsers - Partnering with Detection Engineering and SOC teams to hand off production-ready environments - Tracking the threat landscape and developing new detections - Building repeatable processes, templates, and tooling to scale the function You'll have a ground-floor opportunity in a new function with real runway for growth, working on complex, high-stakes problems across diverse customer environments. The role offers visibility across Sales, Detection Engineering, the SOC, and Customer Success, with the chance to own meaningful outcomes end-to-end.

Similar roles