864,009open jobs
54,355companies
145,726added this week
Browse all
Salary
$143k – $207k per year
Location
Remote (United States)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Sep 28, 2026. First seen by Alion on Sep 26, 2026.

Overview
Company
Impact
Profile match
Expel is a leading cybersecurity company specializing in Managed Detection and Response (MDR) services. They offer a range of solutions, including phishing investigation, threat hunting, and vulnerability prioritization, tailored for organizations of all sizes with 24x7 protection. Expel's Security Operations Platform, Expel Workbench™, integrates with existing tech to enhance security operations.

You're the detection engineer people turn to when they ask "what does Microsoft actually see here?" Not the marketing-slide answer, the real map. Which product emits which telemetry, any anticipated ingestion lags, what table or API it lands in, which license tier gates it, how long it survives before it ages out, and where the documentation quietly disagrees with reality. When a new technique drops, your first instinct is to ask which Microsoft signal would catch it, and whether customers have it switched on.

You also know Microsoft never sits still. Hunting tables appear, columns get renamed, Graph versions retire, capability shuffles between SKUs, previews go GA, features quietly vanish, and native alert logic shifts underneath you. You've got a repeatable way of staying ahead of that churn instead of finding out when a detection stops firing. You're comfortable behind a command line and in front of a customer, including scenarios where the conversation isn’t pleasant. If that's you, we'd love to talk! We have an amazing team and believe you'll love getting to know us.

At Expel, we help businesses bridge the cybersecurity talent gap by providing transparent Managed Detection and Response. To do this we build technology to make sure our security analysts are solving important problems, and automation is helping them make better decisions at every step. We delight in using technology to make security accessible for our customers.

What Expel can do for you

  • Make you one of our recognized authorities on Microsoft detection and response - for our SOC, our engineers, our go-to-market teams, and our customers
  • Give you real ownership of Expel's detection coverage across the whole Microsoft security estate
  • Put Microsoft telemetry from across our customer base in front of you - a breadth of real-world environments no single enterprise gets to see
  • Let you write and tune detections in our own rule engine and watch them run against live signal
  • Treat AI tooling (Claude Code and friends) as a first-class part of how you work, not a side experiment
  • Enable you to learn from analysts, data scientists, engineers, and responders responsible for various components of Expel's product and services
  • Provide access to popular EDR, network, SIEM, identity, and cloud technologies well beyond the Microsoft stack
  • Challenge you to push the boundaries of our security vision

What you can do for Expel

  • Own our detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 - from raw signal through to shipped, tuned detections
  • Build and maintain a living map of Microsoft security signal: what exists, known ingestion lag, where it lands, what gates it, how long it's kept, and how far you can trust it
  • Track how that signal changes and turn every material change into a concrete action - catching drift before it costs us efficacy
  • Tell us where Microsoft's native detections are strong enough to lean on, where they're noisy or shallow, and where Expel needs its own layer
  • Make SOC analysts faster by automating Microsoft-specific investigative workflows against the Graph, Defender, Sentinel, and Entra APIs
  • Partner with Engineering on our Microsoft integrations - ingestion, API limits and throttling, and schema mapping
  • Answer the hard questions from the SOC, CS, and Sales - and mentor the people asking them
  • Help customers understand what they're actually covered for, what they're missing, and what turning it on would buy them

What you should bring with you

  • Deep, current, hands-on knowledge of the Microsoft security stack - Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID, Sentinel, Microsoft Graph, and the Azure and Microsoft 365 control and data planes
  • Fluency in KQL: you can write, read, optimize, and debug non-trivial hunting queries across both Defender Advanced Hunting and Sentinel, and you know how and why the two schemas differ
  • Working knowledge of the Graph and Graph Security APIs, the Defender and Sentinel APIs, and their authentication, permission, versioning, and throttling models
  • A strong grasp of the Entra ID (and legacy Active Directory) identity attack surface - authentication flows, conditional access, OAuth application consent, token theft and replay, hybrid identity and sync, privileged role abuse - and the telemetry each produces
  • Solid understanding of Windows internals and command line tooling, with enough macOS and Linux to keep up with Defender's cross-platform coverage
  • Experience writing, deploying, and tuning custom detections against Microsoft data sets, plus enough non-Microsoft exposure (AWS, GCP, other EDR and SIEM) to keep perspective
  • Proficiency with Python and Sigma, and real fluency using Anthropic tools such as Claude Code to work across systems and data (locally, via MCP, and so on)
  • 5+ years in information technology or security operations, with substantial time spent defending or operating Microsoft environments
  • Excellent tact and diplomacy skills - you can explain Microsoft's limits to an audience that doesn't want to hear about them
  • SC-200, AZ-500, or SC-300 are a plus; demonstrated depth matters considerably more

Work Location

Our headquarters is in Herndon, Virginia. However, we realize that while there is a benefit to in-person interaction, good people don’t all live in Northern Virginia. Remote work is an option for this role.

Additional Notes

The base salary range for this role is between $142,900 USD and $207,200 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $160,000 and $192,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You’ll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We’re only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We’ll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

Salary Range

$142,900—$207,200 USD

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
864,009 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
$122k – $241k per year • Remote (United States) • Contractor • 5+ years exp • High School Diploma • Durham
PowerShell
DevOps
Azure
IAM
Cybersecurity
Microsoft Sentinel
Zscaler
Zero Trust
Microsoft Entra ID
Active Directory
Cryptography
Vault
Apply
$100k – $120k per year • Remote (United States) • 5+ years exp • Washington
Python
PowerShell
DevOps
Linux
Windows
TCP/IP
Cybersecurity
Nessus
Apply
≈ $120k – $221k per year (Estimated) • Remote (United States) • 5+ years exp • Bachelor's Degree • Kansas City
DevOps
VPN
Cybersecurity
ISO 27001
Apply
$66k – $101k per year • Remote (United States) • Full-Time
Cybersecurity
SOC 2
Apply
$90k – $130k per year • Remote (United States) • Full-Time • 7+ years exp • Bachelor's Degree • United States
Python
DevOps
Splunk
Terraform
GCP
New Relic
CloudFormation
Datadog
Dynatrace
Azure
CI/CD
AWS
AWS Lambda
IAM
Amazon CloudWatch
Cybersecurity
PCI DSS
SOC 2
HIPAA
Active Directory
DLP
Apply
Hybrid • 15+ years exp • Singapore
Python
JavaScript
DevOps
Terraform
GCP
Azure
AWS
Cloudflare
API Gateway
TCP/IP
DNS
MPLS
Cybersecurity
Zero Trust
DLP
Management
Agile
Apply
≈ $131k – $278k per year (Estimated) • Remote (likely United States) • 7+ years exp
JavaScript
TypeScript
SQL
Databases
PostgreSQL
AI/ML
Copilot
Cursor
Windsurf
Claude Code
LLM
Frontend
Next.js
React.js
DevOps
Terraform
GCP
Vercel
Pulumi
Azure
CI/CD
AWS
Apply
≈ $110k – $240k per year (Estimated) • Remote (likely United States) • 6+ years exp
JavaScript
TypeScript
SQL
Node JS
Databases
PostgreSQL
AI/ML
Copilot
Cursor
Windsurf
Claude Code
RAG
LLM Guardrails
Tool Use
Frontend
Next.js
React.js
DevOps
GCP
Vercel
Azure
CI/CD
AWS
Apply
≈ $128k – $256k per year (Estimated) • Remote (India) • 10+ years exp • Bachelor's Degree
AI/ML
Prompt Engineering
Anomaly Detection
OpenAI
Human-in-the-Loop
LLM Guardrails
Machine Learning
DevOps
Rest API
GCP
Azure
CI/CD
Management
n8n
Apply
≈ $66k – $142k per year (Estimated) • Hybrid • Full-Time • Bachelor's Degree • Bristol
Python
Java
Rust
C++
AI/ML
Machine Learning
DevOps
Splunk
Kali Linux
Red Hat
Ubuntu
Linux
TCP/IP
Cybersecurity
Wireshark
Burp Suite
Metasploit
Nmap
Nessus
IoT
Zigbee
Management
Google Workspace
NeuroTech
Psychopy
Apply
$122k – $178k per year • Remote (United States) • 7+ years exp • Bachelor's Degree
DevOps
AWS
Linux
Windows
Unix
Cybersecurity
SIEM
Apply
$112k – $162k per year • Remote (United States) • Bachelor's Degree
Python
DevOps
Splunk
CI/CD
Git
GitHub
IAM
Linux
Windows
TCP/IP
Cybersecurity
Crowdstrike
Microsoft Sentinel
SIEM
Apply
$85k – $90k per year • Remote (United States) • 1+ year exp
DevOps
GCP
Azure
AWS
Linux
Windows
TCP/IP
Cybersecurity
Okta
SIEM
Apply
≈ $111k – $236k per year (Estimated) • Remote (United States) • 8+ years exp • Bachelor's Degree
Cybersecurity
SIEM
Apply
$94k – $136k per year • Remote (United States) • 2+ years exp
Cybersecurity
SIEM
Apply
See all jobs
This is one of many
864,009 more open roles from verified company boards, updated every day.