Remote SIEM Detection Engineer: Build Detection Excellence

Mosaec

Northern (KY)

Hybrid

USD 112,000 - 162,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Unlimited PTO
Work location flexibility
Parental leave (up to 24 weeks)

Job summary

Expel is seeking a detection engineer to build and tune detection content across SIEM platforms for a co-managed model. You’ll own end-to-end engagements, from onboarding to optimization, driving real coverage and reducing alert noise within diverse customer environments.

You’ll work with Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, leveraging MITRE ATT&CK and AI-assisted tooling. A strong desire to grow into leadership and a willingness to travel up to 20% are valued.

Qualifications

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development.
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR.
  • 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources

Responsibilities

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing.
  • Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity.
  • Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency.
  • Contribute to Expel’s professional services proprietary detection library, continuously improving our detection strategy and capability.
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs.
  • Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts.

Skills

SIEM expertise
Detections writing
Threat detection
Python
Go
Git/GitHub
MITRE ATT&CK
Windows
macOS
Linux
Networking basics
Cloud IAM
Travel willing

Education

Bachelor's degree in Computer Science

Tools

Splunk
Microsoft Sentinel
CrowdStrike NG SIEM
SOAR
EDR
Sigma

Job description

Expel is seeking a detection engineer to build and tune detection content across SIEM platforms for a co-managed model. You’ll own end-to-end engagements, from onboarding to optimization, driving real coverage and reducing alert noise within diverse customer environments.

You’ll work with Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, leveraging MITRE ATT&CK and AI-assisted tooling. A strong desire to grow into leadership and a willingness to travel up to 20% are valued.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Co-Managed SIEM Detection Engineer – Growth & Impact
Co-Managed SIEM Detection Engineer – Growth & Impact

Expel • United States

Remote
USD 110,000 - 170,000
Remote SIEM Engineer: Detection & Content Architect
Remote SIEM Engineer: Detection & Content Architect

Relha LLC • Washington, Northern (KY)

Hybrid
USD 89,000 - 163,000
Remote SIEM Engineer: Detection & Analytics Lead
Remote SIEM Engineer: Detection & Analytics Lead

PowerToFly • Washington

On-site
USD 89,000 - 163,000
Expel: Managed SIEM Detection Engineer
Expel: Managed SIEM Detection Engineer

Mosaec • Northern (KY)

Hybrid
USD 112,000 - 162,000
Unlimited PTO
Work location flexibility
Parental leave (up to 24 weeks)
Remote Detection Engineer: Build & Automate Detections
Remote Detection Engineer: Build & Automate Detections

Binary-Defense • Houston (TX)

Remote
USD 110,000 - 170,000
Medical, dental, and vision coverage
401k match
Remote-friendly work environment
+1
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Senior AI-Driven Detection Engineer for SIEM
Senior AI-Driven Detection Engineer for SIEM

Relha LLC • Cincinnati (OH)

On-site
USD 120,000 - 150,000
Remote Splunk Detection Engineer - Advanced SIEM
Remote Splunk Detection Engineer - Advanced SIEM

DivIHN Integration Inc • United States

Remote
USD 100,000 - 130,000
Frontline SIEM/SOAR Data Engineer Shape Next-Gen Detection
Frontline SIEM/SOAR Data Engineer Shape Next-Gen Detection

TENEX.AI • Sarasota (FL)

On-site
USD 90,000 - 120,000
Competitive salary and benefits package
Growth and development opportunities
Work with cutting-edge AI technologies
Staff Detection Engineer: SIEM, Cloud & Threat Hunting
Staff Detection Engineer: SIEM, Cloud & Threat Hunting

LinkedIn • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Health and wellness programs
Annual performance bonus
Stock options
+1