Expel
Expel
Expel is a cybersecurity and SaaS company focused on Managed Detection and Response (MDR). Its services support phishing investigations, threat hunting, vulnerability prioritization, and continuous protection for organizations of different sizes. The Expel Workbench™ Security Operations Platform connects with existing technology to help security teams investigate threats, reduce alert noise, and respond more efficiently. Expel combines this platform with an expert security team to strengthen customers’ security operations while allowing them to stay focused on their broader business.

Senior Detection and Response Engineer - Virginia Remote

Expel is hiring a Senior Detection and Response Engineer to lead Microsoft security detection coverage. The role maps telemetry, automates investigations, and strengthens customer protection through managed detection and response.

Description

  • Lead detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365, from raw signals through deployed and tuned detections.
  • Maintain a current map of Microsoft security signals, including ingestion delays, destinations, licensing requirements, retention, and reliability.
  • Monitor signal changes and convert significant updates into actions that prevent detection drift.
  • Evaluate Microsoft native detections and determine where Expel requires an additional detection layer.
  • Automate Microsoft-focused investigation workflows using Graph, Defender, Sentinel, and Entra APIs.
  • Work with Engineering on Microsoft integrations, data ingestion, API constraints, throttling, and schema mapping.
  • Support SOC, Customer Success, and Sales teams with technical guidance while mentoring colleagues.
  • Help customers understand their coverage, detection gaps, and the value of enabling further capabilities.

Requirements

  • Advanced, current hands-on expertise with Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 control and data planes.
  • Strong KQL capability, including writing, interpreting, optimizing, and debugging complex hunting queries in Defender Advanced Hunting and Sentinel.
  • Practical experience with Graph, Graph Security, Defender, and Sentinel APIs, including authentication, permissions, versioning, and throttling.
  • Strong knowledge of Entra ID and legacy Active Directory identity attack surfaces and associated telemetry.
  • Solid understanding of Windows internals and command-line tools, plus sufficient macOS and Linux knowledge for cross-platform coverage.
  • Experience creating, deploying, and tuning custom detections for Microsoft datasets.
  • Experience with AWS, GCP, and other EDR and SIEM platforms.
  • Proficiency in Python and Sigma.
  • Experience using Anthropic tools such as Claude Code locally and through MCP.
  • At least five years in information technology or security operations, including substantial experience defending or operating Microsoft environments.
  • Excellent tact and diplomacy.
  • SC-200, AZ-500, or SC-300 certification is desirable.
  • Authorization to work in the United States is required.
  • Expel does not currently sponsor immigration visas.

Benefits

  • Eligibility for a bonus.
  • Equity participation.
  • Unlimited paid time off.
  • Flexibility in work location.
  • Up to 24 weeks of parental leave.
  • Comprehensive health benefits.
  • Reasonable accommodation for disabilities.

Related Jobs

Basis Technologies

Office and Administrative Coordinator — Basis Technologies, Chicago (Hybrid)

Basis Technologies

Manage daily operations at Basis Technologies’ Chicago headquarters while supporting executives with scheduling, travel, and administrative projects. Coordinate facilities, vendors, events, and workplace logistics in a hybrid role.

Open