远程工作雷达

托管SIEM检测工程师

Managed SIEM Detection Engineer

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Expel
薪资$111,900 - $162,300/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间29 天前
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

你是否是位检测工程师,希望将深厚的专业技能带入一个新成立且正在发展的职能,并用它为客户提供卓越的安全服务?Expel的专业服务业务才刚刚起步,我们正在寻找一位技术专家,负责为客户交付使其在我们的联合管理SIEM模式下能够蓬勃发展的工作。你将为一支正在逐步找到节奏的团队带来实战技能,帮助其成长,并拥有真正的职业发展机会。

以下是你的工作内容。客户带着本应发现威胁但实际却消耗团队资源的SIEM系统来到我们这里:数据摄入成本逐年上升,工程师被警报噪音和断裂的流程压得喘不过气,检测盲点导致真实的安全缺口。你是那位能扭转局面的工程师:编写并优化满足真实安全使用场景的检测内容,填补覆盖空白,将检测逻辑从旧平台迁移出去,并帮助优化客户的数据摄入和费用,使他们的SIEM再次成为增效工具,而不是管理负担。

由于该职能会随着客户和市场的发展而不断演进,这项工作也不会停滞不前。可以期待它向更深入的集成、自动化和AI辅助工具以及客户所需的下一步安全策略发展。

### Expel能为你做什么

- 让你参与一个新专业服务职能的早期建设,你的专业知识直接影响我们为客户交付的质量
- 在该职能成长过程中提供真实的个人发展机会
- 让你处理跨多种客户环境的复杂、高风险的检测和SIEM问题
- 允许你在包括Splunk、Microsoft Sentinel、CrowdStrike NG SIEM在内的主流SIEM平台上工作,以及新兴的AI辅助工具
- 让你与公司内部多个部门建立可见性和合作关系,包括销售、检测工程、SOC和客户成功团队
- 通过让你全程负责有意义的结果来加速你的职业发展

### 你能为Expel做什么

- 完成端到端的专业服务项目,包括检测策略、MITRE ATT&CK评估、SIEM优化和集成、SOAR剧本开发以及自定义日志解析
- 开发并验证满足明确安全使用场景的检测内容,在客户上线时以及环境演变过程中,确保良好的覆盖范围和清晰的准确性
- 通过优化检测内容以提高准确性和降低资源消耗,提升SIEM性能和成本效益

查看英文原文

Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself.

Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.

And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.

### What Expel can do for you

- Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
- Provide real runway for professional development as the function grows
- Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
- Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
- Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
- Accelerate your career by letting you own meaningful outcomes end to end

### What you can do for Expel

- Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
- Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
- Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
- Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability
- Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
- Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
- Track the evolving threat landscape and turn it into new detection development
- Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver

### What you should bring to Expel

- Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
- 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
- 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
- SIEM migration experience translating detection logic between platforms and re-pointing log sources
- Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
- Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
- Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
- Curiosity, strong ownership, and the appetite for growth
- A willingness to travel up to 20%

### Bonus points for

- One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
- Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
- Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
- Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
- A bachelor's degree in Computer Science or Information Security

### **Additional notes**

This role is remote within the United States.

The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We'll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range

$111,900—$162,300 USD

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级交易桌经理

ExpelUnited States$110,600 - $160,400/年permanent12 天前
市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级安全解决方案工程师

ExpelUnited States$122,400 - $177,500/年permanent19 天前
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

检测流水线产品经理

ExpelUnited States$114,300 - $165,700/年permanent2026-08-13
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

客户成功经理,扩展

ExpelUnited States$93,900 - $136,200/年permanent2026-07-14
市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位