Senior Detection & Response Automation Engineer

Expel · Remote

Company

Expel

Location

Remote

Type

Full Time

Job Description

Imagine yourself as a SOC analyst and a new alert shoots to the top of the queue. You open the alert and all of the relevant facts are laid out for you. You know the whos the whats and the wheres of what happened and it’s all right there in the alert. You notice the attacker IP immediately you wonder “Where is that IP located?”. Wonder no more because the IP has already been fully enriched with all publicly available information! This looks bad, just as you’re about to shift to the EDR console to see what kind of damage was done, you notice further down that’s already been provided for you. You have full context of everything that happened before, during and after this event and it’s confirming your suspicions. You raise the alarm and notify the customer that you’re digging into a potential security incident and it only took 20 seconds to make that decision. 

Now imagine the person that created that alert. This person understands security operations and has a keen understanding of what information is needed to make an informed decision about a potential attack. This person knows the sort of enrichment needed to provide the right context about the facts of the alert. This person has studied the metrics from previous investigations and knows where analysts get tripped up or slowed down on decisions during the moments that matter. Once identified, they work tirelessly to streamline that and make sure the decisions can be made quickly. 

This person also enjoys working together on a team to prioritize the problems that matter and work toward a solution. This person also has a high degree of empathy and understands the demands of working in a SOC environment. They understand that scaling operations doesn’t always mean scaling with more people, the real strength comes when you can arm analysts with the tools they need to become super heroes.

Does this person sound like you? At Expel, we’re taking a new approach to managed security. We spend our time trying to discover ways to keep our customers safe and our security analysts happy. We’re trying to meet our customers where they are—understanding a vast number of attacker tactics, security vendor capabilities, and customer requirements. We believe innovating while handling the combinatorial explosion represents a captivating problem. If you agree, we may have the job for you!

What Expel can do for you
  • Place you into the middle of a fast-growing cybersecurity company with the most enthusiastic customers you’ve ever seen—a welcome surprise in the MSSP/MDR market
  • Give you an opportunity to collaboratively drive a significant security capability of the business
  • Enable you to learn from analysts, data scientists, engineers, and responders responsible for various components of Expel’s service and technology
  • Provide access to Expel’s proprietary automation engine allowing you to develop content and expand capabilities
  • Provide an entertaining small and highly transparent startup environment
  • Challenge you to push the boundaries of our security vision
  • Give you access to popular EDR, network, SIEM, and Cloud technologies
What you can do for Expel
  • Ensure our customers get maximum value from their security investments
  • Help ensure our analysts keep learning and doing more sophisticated security work
  • Continuously improve our response capabilities by developing new investigative actions and automated workflows
  • Analyze metrics from SOC operations to find areas of improvement
  • Continuously reevaluate, redefine, extend, and refactor data sources and workflows as needed
  • Instill a culture of experimentation and continuous improvement within the analyst corps
What you should bring with you
  • A desire to build relationships to collaborate with and influence peer teams in the organization.
  • Aptitude for solving ambiguous and complex tasks with support from the team.
  • High degree of curiosity and empathy; continuously striving to acquire new knowledge
  • Intermediate knowledge and experience with security operations
  • 1+ years of experience with security operations, especially in a SOC environment
  • 3+ years of experience writing or maintaining automation tools to facilitate efficient investigations
Work Location

This role will be based out of our offices in Herndon, Virginia. We will consider remote work for this position.

Additional Notes

The base salary range for this role is a base salary between $134,700 USD and $195,300 USD + bonus eligibility and equity.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You’ll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

Our headquarters is in Herndon, Virginia. However, we realize that while there is a benefit to in-person interaction, good people don’t all live in Northern Virginia. Remote work is an option within the continental US.

We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We're only hiring those authorized to work in the United States.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

#LI-Remote

Salary Range
$134,700—$195,300 USD
Apply Now

Date Posted

08/22/2023

Views

32

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.9