Managed SIEM Detection Engineer
$111.9k - $162.3kExpel
Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself.
Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.
And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.
What Expel can do for you
- Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
- Provide real runway for professional development as the function grows
- Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
- Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
- Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
- Accelerate your career by letting you own meaningful outcomes end to end
What you can do for Expel
- Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
- Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
- Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
- Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability
- Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
- Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
- Track the evolving threat landscape and turn it into new detection development
- Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver
What you should bring to Expel
- Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
- 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
- 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
- SIEM migration experience translating detection logic between platforms and re-pointing log sources
- Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
- Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
- Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
- Curiosity, strong ownership, and the appetite for growth
- A willingness to travel up to 20%
Bonus points for
- One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
- Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
- Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
- Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
- A bachelor's degree in Computer Science or Information Security
Additional notes
This role is remote within the United States.
The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.
We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.
We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.
We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
We'll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.
#LI-Remote
Salary Range
$111,900—$162,300 USD
$150k - $200k
...a high-growth CrowdStrike Next Gen SIEM and MDR Enablement practice, and we... ...help shape and scale delivery across detection, automation, and managed response services. As a Senior... ...you will oversee a team of detection engineers and client delivery professionals deploying...SuggestedTemporary workRemote work$101.9k - $132.8k
...are looking for a savvy, high-performing Threat Detection Engineer who will be responsible for the day-to-day management of company-wide information security toolsets and... ...criteria ~Perform intrusion analysis using SIEM technology, reports, data visualization, log analysis...SuggestedFull timeRemote workFlexible hours- GTSC seeks Cybersecurity Engineer – Zero Trust / RMF / SIEM \\\ for mid -August 2026 start. Commitment to... ..., continuous monitoring, threat detection, secure configuration, hardening, NIST... .... \\ Support vulnerability management + IR. \\ Own monitoring and compliance...SuggestedFull timeTemporary workLocal areaRemote workFlexible hours
$155k
...most complete suite of fully managed services that focus on secure... ...looking for a Cybersecurity Engineer to join our Corporate IT Team... ...enterprise security tools including SIEM, EDR, vulnerability scanners,... ...monitoring and incident detection Develop custom Splunk...SuggestedFull time- ...platform - and a full portfolio of managed security, advisory, assessment,... ...Position Overview: The Cybersecurity Engineer is a hands-on practitioner who... ...SOC Analysts to develop and refine SIEM correlation rules and custom detection methods. Leverage platforms and...SuggestedRemote jobFull timeTemporary workLocal areaImmediate startHome office
$101k - $194k
...motivated and experienced Security Engineer with expertise in security detections, EDR systems and data engineering... ...Response (EDR) ecosystem and our SIEM visibility. You will be expected to... ...complex attack patterns.EDR Strategy & Management: Serve as the global SME for our...Full timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week$118.8k - $205.6k
...for all.About the team and the role:The Detection & Response team helps protect eBay’s global... ...closely with the SOC, Global Technology engineering, People Team, Legal, and other security... ...by building, tuning, and maintaining SIEM detections and alert logic that increase...Immediate startRemote workVisa sponsorship$99k - $225k
F5 EngineerThe Opportunity: Manage, administer, support, and enhance... ..., firewalls, and intrusion detection systems and intrusion... ...years of experience in Network Engineering, or HS diploma or GED and 10+... ...including device hardening, IDS/IPS, SIEM, firewalls and internet...Full timeContract workPart timeWork at officeLocal areaRemote work$155k - $175k
...makes everything possible. The Senior SIEM Engineer will be responsible for engineering, sustaining... ...that enable enterprise-wide threat detection, investigations, and security... ...Security team, reporting to the Senior Manager, Cyber Threat Engineering as a fully remote...Full timeRemote workWork from homeFlexible hours- ...opportunity for a Cybersecurity Engineer in Dallas, TX.The Cybersecurity Engineer implements and manages security technologies and... ...like system hardening, threat detection, vulnerability management, and... ...enterprise security tools (e.g., SIEM, endpoint protection, vulnerability...Full timeLocal area
- ...dynamic security architects and engineers tasked with securing the firm... ...Defensive Architecture Managing DirectorWhat you will be responsible... ...configurations for threat detection and response, in cloud and on... ...tools.Experience with SIEM, Network Security Monitoring...Full timeTemporary workLocal areaRemote workFlexible hours
- ...recognized and largest pure-play managed security services provider,... ...Chicago Office.The Sr. Sales Engineer is responsible for... ...Incident Response and/or Threat Detection. The sales engineer will provide... ...including but not limited to EDR, SIEM, WAF, Firewall, IDS/IPS,...Work at officeImmediate startRemote workFlexible hours
$124k - $229.4k
Job Title:Expert Detection and Response Engineer (Remote)Requisition ID:R027801Job Description:Role OverviewActivision... ...tune threat detections within the SIEM based on real‑world attacker behavior... ...pipelines integrated with case management platforms) to accelerate...Full timeTemporary workPart timeLocal areaRemote workWorldwideRelocation package$110k - $160k
...Senior Identity Engineer Later is the world's most intelligent... ...right creators, execute fully managed campaigns, and drive meaningful... ...manual effort and improving detection and prevention Engineering... ...GCP Security Command Center), SIEM/SOAR tools, and...Permanent employmentLocal areaRemote work$140k - $150k
...behalf of a partner company, who manages all applications and next... ...looking for a Cybersecurity Engineer based in United States.... ...technologies including EDR/XDR, SIEM, SOAR, CSPM, identity security... ...automation solutions that improve detection, remediation, reporting,...Remote work- ...enterprise security operations by implementing and managing controls across endpoint, network, identity,... ...The position plays a hands-on role in threat detection, incident response, vulnerability management, and SIEM engineering, while partnering with IT and application...Remote workVisa sponsorshipWork visa
- ...Working remotely, the full-time salaried Cybersecurity Engineer II will manage SIEM and EDR solutions, ensuring the security and integrity of... ...Information and Event Management (SIEM) systems Manage Endpoint Detection and Response (EDR) tools to enhance threat detection and...Full timeRemote work
- ...Endpoint Engineer Franklin, Tennessee, United States 5iron is a... ...company, providing best-in-class managed cybersecurity operations in... ...platforms for security risks to detect and act as escalation point... ...below: Threat Hunting. SIEM and Log Management experience...Full timeWork experience placementImmediate startRemote workWork from home
$99k - $225k
...Job Number: R0245232 F5 Engineer The Opportunity: Manage, administer, support, and enhance cloud environments... ...security, firewalls, and intrusion detection systems and intrusion prevention... ...device hardening, IDS/IPS, SIEM, firewalls and internet protocol security...Full timeContract workPart timeWork at officeLocal areaRemote work- ...SIEM Engineer Opportunity Be Challenged and Make a Difference In a world of technology... ...experienced SIEM (Security Information and Event Management) Engineer to provide support to a... ...cyber operations, advanced threat detection, incident response, and compliance initiatives...Temporary workImmediate startRemote work
$99k - $225k
...Cloud Operations Engineer Manage, administer, support, and enhance cloud environments, ensuring... ...security, firewalls, and intrusion detection systems and intrusion prevention systems... ..., including device hardening, IDS/IPS, SIEM, firewalls and internet protocol security...Full timeContract workPart timeWork at officeLocal areaRemote work$120.4k - $200.2k
...Diego, CaliforniaSales - Sales Engineering /Permanent /HybridAbout UsSophos... ..., 24/7 threat monitoring, detection, and response.Sophos offers industry-leading managed detection and response (MDR) alongside... ...response (ITDR), and next-gen SIEM. Together with expert advisory...Permanent employmentContract workLocal areaRemote work$80k - $110k
...Mechanicus LLC is a managed service provider with a security-forward... ...investigations, malicious login attempts, SIEM triage, and MDR collaboration. We need a senior engineer who can own that work end-to-... ...proactive work — hardening, detection engineering, post-incident...Permanent employmentFull timeWork at officeRemote workHome officeMonday to Friday- ...business and our commitment to managing our company in socially... ...ways. Job Purpose The Sales Engineer partners with the sales team... ...identity management, threat detection, or related security solutions... ...endpoint protection, EDR/XDR, SIEM, IAM, network security, cloud...Remote workWorldwide
- ...native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a... ...are seeking a dynamic Sales Customer Engineer (CE) to join our team, reporting to the... ...with security operations platforms (e.g., SIEM, SOAR, Threat Intelligence, UEBA)....Remote work
$95.9k - $160.3k
...products. Sophos is now the largest pure-play Managed Detection and Response (MDR) provider, supporting... ...and response (ITDR), next-gen SIEM capabilities, managed risk, and a comprehensive... ...in Oxford, U.K. Role Summary The Sales Engineer supports the sales organization in all...Local areaRemote workWorldwide$100k - $125k
...for a Senior Cybersecurity Engineer to join their dynamic team.... ...encryption, and vulnerability management. The Senior Cybersecurity Engineer... ...with them, not at them. Detection/response engineering support... ...tooling integration experience (SIEM, EDR, vulnerability scanning,...Permanent employmentFull timeWork at officeLocal areaRemote workFlexible hours- ...Senior Security Operations Engineer Cohere is the leading security... ...reusable code libraries Manage IAM / RBAC for cloud infrastructure... ...services and tools (eg: SIEM, SOAR, domain monitoring,... ...DevSecOps, Cloud Security, Threat Detection & Response or software...Full timeWork at officeLocal areaRemote workHome officeFlexible hours
- ...Security Operations Engineer Yellow Card is the largest licensed... ...infrastructure businesses need to manage Stablecoins, payments, and... ...down manual effort through detection-as-code and SOAR automation.... ...coverage Design and maintain SIEM detection rules covering...Local areaRemote work
- ...Security Operations Engineer Capco is a fully independent, global management and technology consultancy. For 25 years we have combined innovative thinking... ...will play a key part in building and optimizing SIEM detection capabilities, supporting threat verification,...Contract workRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Managed SIEM Detection Engineer. Be the first to apply!
- weight management Remote
- lecturer management Remote
- change management coordinator Remote
- absence management specialist Remote
- learning management system specialist Remote
- product management intern Remote
- director client management Remote
- change management project manager Remote
- organizational change management lead Remote
- internship event management company Remote




