SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 142,900 - 207,200 / annual
Expel is a Managed Detection and Response (MDR) company that helps businesses bridge the cybersecurity talent gap through transparent security operations and intelligent automation. This role focuses on deep expertise in the Microsoft security ecosystem.
You will own Expel's detection coverage across the entire Microsoft security estate, including Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365. Your responsibilities include:
- Building and maintaining a comprehensive map of Microsoft security signals: what exists, ingestion lags, where data lands, licensing gates, retention periods, and reliability
- Tracking changes to Microsoft's security platform and converting material changes into concrete actions to prevent detection drift
- Evaluating where Microsoft's native detections are strong enough to rely on versus where Expel needs custom detection layers
- Writing, deploying, and tuning custom detections in Expel's rule engine against live signal
- Automating Microsoft-specific investigative workflows using Graph, Defender, Sentinel, and Entra APIs to accelerate SOC analyst productivity
- Partnering with Engineering on Microsoft integrations, including ingestion optimization, API limits, throttling, and schema mapping
- Mentoring SOC analysts, customer success, and sales teams on Microsoft detection capabilities and coverage gaps
- Helping customers understand their actual coverage, gaps, and the value of enabling additional capabilities
You'll have access to Microsoft telemetry from across Expel's customer base—a breadth of real-world environments no single enterprise sees—and will use AI tools (Claude Code and similar) as a first-class part of your workflow. You'll work alongside analysts, data scientists, engineers, and responders, and gain exposure to EDR, network, SIEM, identity, and cloud technologies beyond Microsoft.
REQUIREMENTS:
- Deep, current, hands-on knowledge of the Microsoft security stack: Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 control and data planes
- Fluency in KQL: ability to write, read, optimize, and debug non-trivial hunting queries in both Defender Advanced Hunting and Sentinel; understanding of schema differences between the two
- Working knowledge of Graph and Graph Security APIs, Defender and Sentinel APIs, including authentication, permissions, versioning, and throttling models
- Strong grasp of Entra ID and legacy Active Directory identity attack surface: authentication flows, conditional access, OAuth application consent, token theft and replay, hybrid identity and sync, privileged role abuse, and associated telemetry
- Solid understanding of Windows internals and command-line tooling; sufficient macOS and Linux knowledge to follow Defender's cross-platform coverage
- Experience writing, deploying, and tuning custom detections against Microsoft datasets; exposure to AWS, GCP, and other EDR/SIEM platforms for perspective
- Proficiency with Python and Sigma; real fluency using Anthropic tools such as Claude Code to work across systems and data
- 5+ years in information technology or security operations, with substantial time defending or operating Microsoft environments
- Excellent tact and diplomacy skills—ability to explain Microsoft's limitations to audiences reluctant to hear them
- SC-200, AZ-500, or SC-300 certifications are a plus; demonstrated depth matters more than credentials