Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Managed SIEM Detection Engineer

$111.9k - $162.3k
Full-time

Expel

Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself.

Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.

And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.

What Expel can do for you

  • Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
  • Provide real runway for professional development as the function grows
  • Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
  • Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
  • Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
  • Accelerate your career by letting you own meaningful outcomes end to end

What you can do for Expel

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
  • Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
  • Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
  • Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
  • Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
  • Track the evolving threat landscape and turn it into new detection development
  • Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver

What you should bring to Expel

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
  • 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources
  • Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
  • Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
  • Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
  • Curiosity, strong ownership, and the appetite for growth
  • A willingness to travel up to 20%

Bonus points for

  • One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
  • Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
  • Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
  • Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
  • A bachelor's degree in Computer Science or Information Security

Additional notes

This role is remote within the United States.

The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We'll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range

$111,900—$162,300 USD

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Managed SIEM Detection Engineer in Remote vacancy
  • $150k - $200k

     ...a high-growth CrowdStrike Next Gen SIEM and MDR Enablement practice, and we...  ...help shape and scale delivery across detection, automation, and managed response services. As a Senior...  ...you will oversee a team of detection engineers and client delivery professionals deploying... 
    Suggested
    Temporary work
    Remote work
    United States
    more than 2 months ago
  • $101.9k - $132.8k

     ...are looking for a savvy, high-performing Threat Detection Engineer who will be responsible for the day-to-day management of company-wide information security toolsets and...  ...criteria ~Perform intrusion analysis using SIEM technology, reports, data visualization, log analysis... 
    Suggested
    Full time
    Remote work
    Flexible hours

    Blackbaud

    Remote
    1 day ago
  • GTSC seeks  Cybersecurity Engineer – Zero Trust / RMF / SIEM \\\ for mid -August 2026 start. Commitment to...  ..., continuous monitoring, threat detection, secure configuration, hardening, NIST...  .... \\ Support vulnerability management + IR. \\ Own monitoring and compliance... 
    Suggested
    Full time
    Temporary work
    Local area
    Remote work
    Flexible hours

    Gtsc-Talent Solutions

    Washington DC
    1 day ago
  • $155k

     ...most complete suite of fully managed services that focus on secure...  ...looking for a Cybersecurity Engineer to join our Corporate IT Team...  ...enterprise security tools including SIEM, EDR, vulnerability scanners,...  ...monitoring and incident detection Develop custom Splunk... 
    Suggested
    Full time

    Met Tel

    Remote
    1 day ago
  •  ...platform - and a full portfolio of managed security, advisory, assessment,...  ...Position Overview: The Cybersecurity Engineer is a hands-on practitioner who...  ...SOC Analysts to develop and refine SIEM correlation rules and custom detection methods. Leverage platforms and... 
    Suggested
    Remote job
    Full time
    Temporary work
    Local area
    Immediate start
    Home office

    Apollo Information Systems

    United States
    1 day ago
  • $101k - $194k

     ...motivated and experienced Security Engineer with expertise in security detections, EDR systems and data engineering...  ...Response (EDR) ecosystem and our SIEM visibility. You will be expected to...  ...complex attack patterns.EDR Strategy & Management: Serve as the global SME for our... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Work from home
    Shift work
    3 days per week

    Verizon

    Cary, NC
    8 hours ago
  • $118.8k - $205.6k

     ...for all.About the team and the role:The Detection & Response team helps protect eBay’s global...  ...closely with the SOC, Global Technology engineering, People Team, Legal, and other security...  ...by building, tuning, and maintaining SIEM detections and alert logic that increase... 
    Immediate start
    Remote work
    Visa sponsorship

    eBay

    Austin, TX
    3 days ago
  • $99k - $225k

    F5 EngineerThe Opportunity: Manage, administer, support, and enhance...  ..., firewalls, and intrusion detection systems and intrusion...  ...years of experience in Network Engineering, or HS diploma or GED and 10+...  ...including device hardening, IDS/IPS, SIEM, firewalls and internet... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  • $155k - $175k

     ...makes everything possible. The Senior SIEM Engineer will be responsible for engineering, sustaining...  ...that enable enterprise-wide threat detection, investigations, and security...  ...Security team, reporting to the Senior Manager, Cyber Threat Engineering as a fully remote... 
    Full time
    Remote work
    Work from home
    Flexible hours

    Danaher Corporation

    New York, NY
    8 hours ago
  •  ...opportunity for a Cybersecurity Engineer in Dallas, TX.The Cybersecurity Engineer implements and manages security technologies and...  ...like system hardening, threat detection, vulnerability management, and...  ...enterprise security tools (e.g., SIEM, endpoint protection, vulnerability... 
    Full time
    Local area

    American Heart Association

    Dallas, TX
    3 days ago
  •  ...dynamic security architects and engineers tasked with securing the firm...  ...Defensive Architecture Managing DirectorWhat you will be responsible...  ...configurations for threat detection and response, in cloud and on...  ...tools.Experience with SIEM, Network Security Monitoring... 
    Full time
    Temporary work
    Local area
    Remote work
    Flexible hours

    State Street Bank

    Princeton, NJ
    3 days ago
  •  ...recognized and largest pure-play managed security services provider,...  ...Chicago Office.The Sr. Sales Engineer is responsible for...  ...Incident Response and/or Threat Detection. The sales engineer will provide...  ...including but not limited to EDR, SIEM, WAF, Firewall, IDS/IPS,... 
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Trustwave

    Chicago, IL
    8 hours ago
  • $124k - $229.4k

    Job Title:Expert Detection and Response Engineer (Remote)Requisition ID:R027801Job Description:Role OverviewActivision...  ...tune threat detections within the SIEM based on real‑world attacker behavior...  ...pipelines integrated with case management platforms) to accelerate... 
    Full time
    Temporary work
    Part time
    Local area
    Remote work
    Worldwide
    Relocation package

    Activision

    Irvine, CA
    2 days ago
  • $110k - $160k

     ...Senior Identity Engineer Later is the world's most intelligent...  ...right creators, execute fully managed campaigns, and drive meaningful...  ...manual effort and improving detection and prevention Engineering...  ...GCP Security Command Center), SIEM/SOAR tools, and... 
    Permanent employment
    Local area
    Remote work

    Later

    United States
    2 days ago
  • $140k - $150k

     ...behalf of a partner company, who manages all applications and next...  ...looking for a Cybersecurity Engineer based in United States....  ...technologies including EDR/XDR, SIEM, SOAR, CSPM, identity security...  ...automation solutions that improve detection, remediation, reporting,... 
    Remote work

    Jobgether

    United States
    1 hour ago
  •  ...enterprise security operations by implementing and managing controls across endpoint, network, identity,...  ...The position plays a hands-on role in threat detection, incident response, vulnerability management, and SIEM engineering, while partnering with IT and application... 
    Remote work
    Visa sponsorship
    Work visa

    Golden Nugget Hotels & Casinos

    Houston, TX
    2 days ago
  •  ...Working remotely, the full-time salaried Cybersecurity Engineer II will manage SIEM and EDR solutions, ensuring the security and integrity of...  ...Information and Event Management (SIEM) systems Manage Endpoint Detection and Response (EDR) tools to enhance threat detection and... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    1 day ago
  •  ...Endpoint Engineer Franklin, Tennessee, United States 5iron is a...  ...company, providing best-in-class managed cybersecurity operations in...  ...platforms for security risks to detect and act as escalation point...  ...below: Threat Hunting. SIEM and Log Management experience... 
    Full time
    Work experience placement
    Immediate start
    Remote work
    Work from home

    Five Iron LLC

    Franklin, TN
    8 hours ago
  • $99k - $225k

     ...Job Number: R0245232 F5 Engineer The Opportunity: Manage, administer, support, and enhance cloud environments...  ...security, firewalls, and intrusion detection systems and intrusion prevention...  ...device hardening, IDS/IPS, SIEM, firewalls and internet protocol security... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    8 hours ago
  •  ...SIEM Engineer Opportunity Be Challenged and Make a Difference In a world of technology...  ...experienced SIEM (Security Information and Event Management) Engineer to provide support to a...  ...cyber operations, advanced threat detection, incident response, and compliance initiatives... 
    Temporary work
    Immediate start
    Remote work

    AnaVation LLC

    Washington DC
    3 days ago
  • $99k - $225k

     ...Cloud Operations Engineer Manage, administer, support, and enhance cloud environments, ensuring...  ...security, firewalls, and intrusion detection systems and intrusion prevention systems...  ..., including device hardening, IDS/IPS, SIEM, firewalls and internet protocol security... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    ClearanceJobs

    United States
    3 days ago
  • $120.4k - $200.2k

     ...Diego, CaliforniaSales - Sales Engineering /Permanent /HybridAbout UsSophos...  ..., 24/7 threat monitoring, detection, and response.Sophos offers industry-leading managed detection and response (MDR) alongside...  ...response (ITDR), and next-gen SIEM. Together with expert advisory... 
    Permanent employment
    Contract work
    Local area
    Remote work

    Sophos

    San Diego, CA
    8 hours ago
  • $80k - $110k

     ...Mechanicus LLC  is a managed service provider with a security-forward...  ...investigations, malicious login attempts, SIEM triage, and MDR collaboration. We need a senior engineer who can own that work end-to-...  ...proactive work — hardening, detection engineering, post-incident... 
    Permanent employment
    Full time
    Work at office
    Remote work
    Home office
    Monday to Friday

    MSP Hire, Inc.

    Belle Vernon, PA
    4 days ago
  •  ...business and our commitment to managing our company in socially...  ...ways. Job Purpose The Sales Engineer partners with the sales team...  ...identity management, threat detection, or related security solutions...  ...endpoint protection, EDR/XDR, SIEM, IAM, network security, cloud... 
    Remote work
    Worldwide

    ESET North America

    San Diego, CA
    4 days ago
  •  ...native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a...  ...are seeking a dynamic Sales Customer Engineer (CE) to join our team, reporting to the...  ...with security operations platforms (e.g., SIEM, SOAR, Threat Intelligence, UEBA).... 
    Remote work

    TENEX.AI

    San Jose, CA
    4 days ago
  • $95.9k - $160.3k

     ...products. Sophos is now the largest pure-play Managed Detection and Response (MDR) provider, supporting...  ...and response (ITDR), next-gen SIEM capabilities, managed risk, and a comprehensive...  ...in Oxford, U.K. Role Summary The Sales Engineer supports the sales organization in all... 
    Local area
    Remote work
    Worldwide

    Sophos

    Annapolis, MD
    1 day ago
  • $100k - $125k

     ...for a  Senior Cybersecurity Engineer to join their dynamic team....  ...encryption, and vulnerability management. The Senior Cybersecurity Engineer...  ...with them, not at them. Detection/response engineering support...  ...tooling integration experience (SIEM, EDR, vulnerability scanning,... 
    Permanent employment
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Aprio

    Remote
    1 day ago
  •  ...Senior Security Operations Engineer Cohere is the leading security...  ...reusable code libraries Manage IAM / RBAC for cloud infrastructure...  ...services and tools (eg: SIEM, SOAR, domain monitoring,...  ...DevSecOps, Cloud Security, Threat Detection & Response or software... 
    Full time
    Work at office
    Local area
    Remote work
    Home office
    Flexible hours

    Cohere

    United States
    1 day ago
  •  ...Security Operations Engineer Yellow Card is the largest licensed...  ...infrastructure businesses need to manage Stablecoins, payments, and...  ...down manual effort through detection-as-code and SOAR automation....  ...coverage Design and maintain SIEM detection rules covering... 
    Local area
    Remote work

    Yellow Card Financial

    United States
    1 day ago
  •  ...Security Operations Engineer Capco is a fully independent, global management and technology consultancy. For 25 years we have combined innovative thinking...  ...will play a key part in building and optimizing SIEM detection capabilities, supporting threat verification,... 
    Contract work
    Remote work
    Flexible hours

    Capco

    United States
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Managed SIEM Detection Engineer. Be the first to apply!