Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Detection & Response Engineer

$142.9k - $207.2k
Full-time

Expel

You're the detection engineer people turn to when they ask "what does Microsoft actually see here?" Not the marketing-slide answer, the real map. Which product emits which telemetry, any anticipated ingestion lags, what table or API it lands in, which license tier gates it, how long it survives before it ages out, and where the documentation quietly disagrees with reality. When a new technique drops, your first instinct is to ask which Microsoft signal would catch it, and whether customers have it switched on.

You also know Microsoft never sits still. Hunting tables appear, columns get renamed, Graph versions retire, capability shuffles between SKUs, previews go GA, features quietly vanish, and native alert logic shifts underneath you. You've got a repeatable way of staying ahead of that churn instead of finding out when a detection stops firing. You're comfortable behind a command line and in front of a customer, including scenarios where the conversation isn’t pleasant. If that's you, we'd love to talk! We have an amazing team and believe you'll love getting to know us.

At Expel, we help businesses bridge the cybersecurity talent gap by providing transparent Managed Detection and Response. To do this we build technology to make sure our security analysts are solving important problems, and automation is helping them make better decisions at every step. We delight in using technology to make security accessible for our customers.

What Expel can do for you

  • Make you one of our recognized authorities on Microsoft detection and response — for our SOC, our engineers, our go-to-market teams, and our customers
  • Give you real ownership of Expel's detection coverage across the whole Microsoft security estate
  • Put Microsoft telemetry from across our customer base in front of you — a breadth of real-world environments no single enterprise gets to see
  • Let you write and tune detections in our own rule engine and watch them run against live signal
  • Treat AI tooling (Claude Code and friends) as a first-class part of how you work, not a side experiment
  • Enable you to learn from analysts, data scientists, engineers, and responders responsible for various components of Expel's product and services
  • Provide access to popular EDR, network, SIEM, identity, and cloud technologies well beyond the Microsoft stack
  • Challenge you to push the boundaries of our security vision

What you can do for Expel

  • Own our detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 — from raw signal through to shipped, tuned detections
  • Build and maintain a living map of Microsoft security signal: what exists, known ingestion lag, where it lands, what gates it, how long it's kept, and how far you can trust it
  • Track how that signal changes and turn every material change into a concrete action — catching drift before it costs us efficacy
  • Tell us where Microsoft's native detections are strong enough to lean on, where they're noisy or shallow, and where Expel needs its own layer
  • Make SOC analysts faster by automating Microsoft-specific investigative workflows against the Graph, Defender, Sentinel, and Entra APIs
  • Partner with Engineering on our Microsoft integrations — ingestion, API limits and throttling, and schema mapping
  • Answer the hard questions from the SOC, CS, and Sales — and mentor the people asking them
  • Help customers understand what they're actually covered for, what they're missing, and what turning it on would buy them

What you should bring with you

  • Deep, current, hands-on knowledge of the Microsoft security stack — Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID, Sentinel, Microsoft Graph, and the Azure and Microsoft 365 control and data planes
  • Fluency in KQL: you can write, read, optimize, and debug non-trivial hunting queries across both Defender Advanced Hunting and Sentinel, and you know how and why the two schemas differ
  • Working knowledge of the Graph and Graph Security APIs, the Defender and Sentinel APIs, and their authentication, permission, versioning, and throttling models
  • A strong grasp of the Entra ID (and legacy Active Directory) identity attack surface — authentication flows, conditional access, OAuth application consent, token theft and replay, hybrid identity and sync, privileged role abuse — and the telemetry each produces
  • Solid understanding of Windows internals and command line tooling, with enough macOS and Linux to keep up with Defender's cross-platform coverage
  • Experience writing, deploying, and tuning custom detections against Microsoft data sets, plus enough non-Microsoft exposure (AWS, GCP, other EDR and SIEM) to keep perspective
  • Proficiency with Python and Sigma, and real fluency using Anthropic tools such as Claude Code to work across systems and data (locally, via MCP, and so on)
  • 5+ years in information technology or security operations, with substantial time spent defending or operating Microsoft environments
  • Excellent tact and diplomacy skills — you can explain Microsoft's limits to an audience that doesn't want to hear about them
  • SC-200, AZ-500, or SC-300 are a plus; demonstrated depth matters considerably more

Work Location

Our headquarters is in Herndon, Virginia. However, we realize that while there is a benefit to in-person interaction, good people don’t all live in Northern Virginia. Remote work is an option for this role.

Additional Notes

The base salary range for this role is between $142,900 USD and $207,200 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $160,000 and $192,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You’ll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We’re only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We’ll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range

$142,900—$207,200 USD

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Detection & Response Engineer in Remote vacancy
  • $119.32k - $202.85k

    Description ICF is actively recruiting for an experienced Senior Threat Detection & Response Engineer to support the research and development of new cyber analytic capabilities that will help the US protect and defend its networks and critical information systems. The successful... 
    Senior
    Full time
    Contract work
    Work at office
    Remote work

    ICF

    Arlington, VA
    1 day ago
  • ICF is seeking an experienced Senior Threat Detection & Response Engineer to support R&D of cyber analytic capabilities for federal networks. The role is primarily telework-based with occasional client or ICF facility meetings in the DC metro area. Responsibilities include... 
    Senior
    Remote job

    ICF

    Arlington, VA
    1 day ago
  • $174.5k - $240k

     ...Responsibilities Define the technical direction, roadmap, tooling needs, and operating standards for detection and response at Faire. Build enterprise detection engineering end to end, including telemetry pipelines, detection content, alert routing, and enrichment... 
    Senior
    Full time
    Work at office
    Remote work
    Monday to Friday
    Flexible hours
    3 days per week

    Faire

    San Francisco, CA
    29 days ago
  • $174.5k - $240k

     ...to join us as we power the shop local movement. If you believe in community, come join ours.About this roleAs our first Detection & Response engineer, you'll build that capability from the ground up focused on our enterprise environment. Looking for and monitoring threats... 
    Senior
    Work experience placement
    Work at office
    Local area
    Remote work
    Monday to Friday
    Flexible hours
    3 days per week

    Faire

    San Francisco, CA
    4 days ago
  • $89.01k - $142.19k

     ...consider yourself a innovator in threat detection? About the role: You will be entrusted as the senior most technical member of incident response team for our global information...  ...exploitation techniques, malware reverse engineering, threat analysis, and security threat... 
    Senior
    Full time
    Local area
    Work from home

    Elsevier

    New Jersey
    2 days ago
  • $120k - $160k

     ...Posted: 2026-09-01 Category: Engineering and Sciences Subcategory:...  ...ground systems for Nuclear Detection System (NDS) capabilities....  ...need for a hybrid Senior Nuclear Detection System Engineer...  ...architecture. Responsibilities: Provide Systems... 
    Senior
    Full time
    For contractors
    Immediate start
    Remote work
    Shift work

    SAIC

    El Segundo, CA
    15 hours ago
  • $240k - $290k

     ...hiring remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv. Runway is hiring a Detection & Response Engineer to own how we find and stop attacks against our infrastructure, our research environment and our products. Securing a... 
    Full time
    Remote work

    Runway

    Remote
    3 days ago
  • $125.8k - $209.7k

     ...automation and orchestration. Join our dynamic team as a Senior SOAR Engineer, where you'll play a key role in designing,...  ...You will work closely with security operations, incident response, threat detection, and engineering teams to automate repetitive tasks, orchestrate... 
    Senior
    Immediate start

    EY

    Boca Raton, FL
    4 days ago
  •  ...to where we work. Overview Instacarts Detection Engineering team sits at the core of our Security...  ...collection and signal design to automated response, across a complex, cloud-native...  ...endpoint, cloud, container, and SaaS. As a Senior Detection Engineer II, you'll be a... 
    Senior
    Full time
    Work at office
    Work from home
    Flexible hours
    Shift work

    Instacart

    Remote
    a month ago
  • $101k - $194k

     ...looking for a highly motivated and experienced Security Engineer with expertise in security detections, EDR systems and data engineering to join the Network...  ..., you will be an owner of our Endpoint Detection and Response (EDR) ecosystem and our SIEM visibility. You will be... 
    Senior
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Work from home
    Shift work
    3 days per week

    Verizon

    Cary, NC
    15 hours ago
  • $266.2k - $425.9k

     ...HubSpot is looking for a talented Principal Software Engineer to shape and deliver advanced detection engineering, threat intelligence, and incident response solutions supporting our growing platform. In this pivotal org-impacting role, you will use your extensive hands... 
    Full time
    Live out
    Work at office
    Remote work

    Hubspot

    Park County, MT
    more than 2 months ago
  •  ...deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading...  ...com. Role Summary We are looking for a senior product manager to accelerate...  ...product leader who can work deeply with engineering and research teams while also building... 
    Senior
    Full time

    Sophos

    Remote
    16 days ago
  • We’re looking for a Senior Threat Detection & Intelligence Engineer to help us understand how adversaries operate, detect meaningful threats early, and lead...  ...you.About the TeamThe Cloud Security & Detection & Response (CSDR) team protects Miro by staying ahead of credible... 
    Senior
    Work from home

    Miro

    Austin, TX
    4 days ago
  • $110k - $165.3k

     ...throughout their career as business needs and development opportunities arise. The Senior Detection Engineer plays a vital role in InfoSec's Cyber Defense Technology team, responsible for building, tuning, and scaling detection capabilities across enterprise SIEM platforms... 
    Senior
    Full time
    Work at office
    Relocation

    Procter & Gamble

    Cincinnati, OH
    15 hours ago
  • $160.3k - $240.5k

     ...ôle pratique, pour agir à titre de responsable technique de l’équipe pendant les heures...  ...SecOps team is seeking a senior, hands-on security engineer to serve as the team’s technical lead...  ...Incident Response capabilities across detection, monitoring, investigation, and response... 
    Senior
    Full time
    Work at office
    Remote work
    Worldwide

    Unity Technologies

    Texas
    4 days ago
  •  ...Job Summary: Senior Dynatrace Engineer (Georgia Dept. of Transportation) [About the Role] Step...  ..., with strong renewal prospects. [Responsibilities] - Architect, configure, and...  ...-end visibility and proactive issue detection. - Develop and maintain dashboards... 
    Senior
    Contract work
    Local area
    Remote work
    Flexible hours

    Indotronix International Corporation

    Atlanta, GA
    4 days ago
  •  ...quality ceiling of our training data. Core Responsibilities Human Pose Estimation Design and...  ...on perception models including object detection, instance segmentation, and 6DoF pose...  ...and sensor dropouts Collaborate with ML engineers and data infrastructure teams to ensure... 
    Senior

    xdof, Inc.

    San Mateo, CA
    3 days ago
  •  ...Senior NLP Engineer Theta Lake is the only communication compliance vendor directly financially...  ...archiving, proactive compliance risk detection, and surveillance needs. As Senior...  ...us at ****@*****.*** Responsibilities: Own NLP problems end to end. Take... 
    Senior
    Remote work
    Work from home
    Visa sponsorship

    Theta Lake

    United States
    1 day ago
  • $106.46k - $175k

     ...What to expect.  Lead the engineering, configuration, deployment, and operational maintenance of the organization’s cybersecurity...  ...solutions. Design and maintain security automations, detections, and response playbooks to improve efficiency, consistency, and response... 
    Senior
    Full time

    Sheppard Pratt Careers

    Remote
    more than 2 months ago
  • $140k - $160k

     ...role: The SeniorCybersecurity Engineer supports a DoW program by...  ...software delivery lifecycle. The Senior Cybersecurity Engineer helps...  ...within the pipeline. Key Responsibilities Work with the Pipeline...  ...container scanning, secrets detection, dependency scanning, and vulnerability... 
    Senior
    Live in
    Remote work

    Raft

    San Antonio, TX
    1 day ago
  • $324k

     ...best of breed AI models. We're responsible for securing every byte that...  ...to the CISO, you'll lead the Detection & Response team that acts as...  ...proactive threat management engine, dedicating the majority of their...  ...sustainable programs where senior engineers thrive solving... 
    Senior
    Work at office
    Local area
    Work from home
    Flexible hours

    Lambda

    Bellevue, WA
    3 days ago
  • $120k - $160k

     ...Posted: 2026-09-18 Category: Engineering and Sciences Subcategory:...  ...frequent direct access to senior Government decision-makers....  ...Operations, maneuver detection, conjunction assessment, and...  ...prepared to excel. The team's responsibilities include: Independent trade... 
    Senior
    Full time
    Remote work
    Shift work

    SAIC

    Chantilly, Loudoun County, VA
    3 days ago
  • $75.2k - $158.1k

     ...Senior Firewall Engineer As a member of the TCS Network Security Services (NSS) team, you will...  ...business/mission goals and objectives. Responsibilities • Assist with design, analysis,...  ...etc.) • Experience with Intrusion Detection Systems/IDS Products (e.g. FireEye,... 
    Senior
    Contract work
    Work experience placement
    Remote work
    Flexible hours

    CACI International

    Saint Louis, MO
    15 hours ago
  •  ...commitment to delivering a trusted member experience. The Senior Security Engineer provides technical leadership and hands-on engineering...  ...—such as privileged access management (PAM), endpoint detection and response (EDR), firewalls, IDS/IPS, CASB, and related security... 
    Senior
    Full time
    Live out
    Remote work

    Allegacy Financial

    Remote
    more than 2 months ago
  •  ...The Senior PBAC Engineer helps architect, deploy and operate a secure application infrastructure...  ...with business needs. The position is responsible for developing security solutions at...  ...LDAP Directory Services, Intrusion Detection, Security Policies / GPOs, Operating... 
    Senior
    Remote work

    EPAM Systems Inc

    San Jose, CA
    2 days ago
  •  ...Posted: 2026-09-25 Category: Engineering and Sciences Subcategory:...  ...SAIC is seeking a Senior Radar Engineer to join the...  ...Huntsville, Alabama. Primary Responsibilities: Perform radar systems analysis...  ...of radar topics such as detection theory, tracking, waveform scheduling... 
    Senior
    Full time
    For contractors
    Remote work
    Shift work

    SAIC

    Huntsville, AL
    1 day ago
  •  ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the United States. This full-time remote role focuses on strengthening detection, incident response, security... 
    Full time
    Remote work

    Jobgether

    Remote
    6 days ago
  • $118.8k - $205.6k

     ...for all.About the team and the role:The Detection & Response team helps protect eBay’s global...  ...closely with the SOC, Global Technology engineering, People Team, Legal, and other security...  ...strengthen resilience across the company.As a senior individual contributor, you will work... 
    Immediate start
    Remote work
    Visa sponsorship

    eBay

    Austin, TX
    1 day ago
  • $100k - $145k

     ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the United States. This full-time remote role focuses on strengthening detection, incident response,... 
    Remote job
    Full time
    Visa sponsorship

    jobgether

    United States
    6 days ago
  •  ...Position Overview The Senior Cybersecurity Engineer leads enterprise security operations, incident response, and technical security engineering across all Spotless Brands...  ...security operations, including threat detection, incident response, and forensic investigations... 
    Senior
    Full time
    Work at office
    Local area

    Spotless Brands

    Remote
    more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Detection & Response Engineer. Be the first to apply!