
Work Here?
Expel provides Managed Detection and Response (MDR) services that help organizations protect their digital assets. It combines technology and human expertise to monitor, detect, and respond to threats across cloud, SaaS, and on‑premises systems. The platform collects logs and alerts from a company’s existing tech stack and processes them with automated tools and security analysts to identify malicious activity and take action. It also offers clear, actionable recommendations to improve security and maximize ROI, along with workflows that support and augment a company’s security team. Unlike some providers that rely on limited tools or slow handoffs, Expel emphasizes quick integration with new technologies and a transparent, software‑driven approach that continuously improves security posture. The company’s goal is to raise a customer’s security maturity while delivering measurable security outcomes and better ROI by preventing incidents and guiding future security spending.
Industries
Data & Analytics
Consulting
Enterprise Software
Cybersecurity
Company Size
201-500
Company Stage
Series E
Total Funding
$288.8M
Headquarters
Herndon, Virginia
Founded
2016
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$288.8M
Below
Industry Average
Funded Over
6 Rounds
Industry standards
Unlimited vacation
401k plan
Healthcare plan with dental and vision
Flexible work hours
Opportunity to work from home
One paid conference per year
Parental leave
Expel has launched the first managed detection and response (MDR) service covering the complete AI attack surface. The coverage addresses three areas: attacks launched using AI, employee misuse of AI, and vulnerabilities within AI systems themselves. The service includes an Anthropic Claude integration that analyses prompt content to detect intent, not just activity logs. Expel's detection library maps to 13 of 16 MITRE ATLAS tactics and is available to customers. Human operators run the detection and triage processes, using AI to accelerate rather than replace their work. The company also offers AI-focused threat hunting for customers. James Shank, Director of Threat Operations at Expel, will present the Expel AI Risk Framework at Black Hat USA 2026 on 5 August.
Expel has extended Ruxie, its AI SOC manager, with new agentic capabilities to provide AI coverage across every stage of the threat lifecycle. The capabilities are now in production in customers' MDR deployments. The enhancements address AI-powered attacks that compress the time from initial access to impact. Ruxie's new capabilities include automated enrichment pulling data from over 160 security tools, contextual analysis, threat detection across multiple attack surfaces, automated detection engineering, alert triage and classification, investigation workflows, targeted response actions, and automated reporting. The system operates alongside human analysts to improve speed and accuracy. According to Expel's Chief Strategy Officer Justin Bajko, the agentic workflows are designed to match the pace of machine-speed attackers at every stage, eliminating gaps for exploitation.
Expel, a security provider, has published a practitioner framework for implementing AI in security operations, supported by a decade of production AI experience. The "Trust vs. Impact" framework maps security workflows based on potential impact and system confidence, helping practitioners determine where AI should operate autonomously versus where humans should lead. The company released an interactive tool allowing security teams to plot their own workflows on the framework. Expel's AI engine, Ruxie, now includes capabilities such as agentic detection rule generation, AI-powered identity alert triage with 99.7% confidence, and AI-generated summarisation. The identity classification feature alone reduces alert volume by approximately 10%. The framework, interactive tool, and Ruxie capabilities are available now through Expel Workbench for managed detection and response customers.
Expel has launched Expel Managed SIEM, a co-managed service that integrates the company's detection engineering expertise into customers' existing Microsoft Sentinel and Splunk Enterprise Security environments. The service is now generally available as an add-on to Expel MDR. The offering handles detection strategy, writes custom detection logic, optimises data ingestion costs, and feeds SIEM alerts into Expel's MDR response workflows. Unlike traditional providers that profit from increased data volume, Expel helps customers control ingestion costs whilst maintaining security coverage. The service includes two tiers: Detection Engineering provides ongoing detection support and rule optimisation, whilst Performance Engineering offers deeper operational support including SIEM health monitoring and automation development. Customers retain full ownership of all detection rules created by Expel, with complete visibility into every tuning decision.
Leading MDR provider to celebrate security defenders with cutting-edge service innovations and exclusive VIP experiencesHERNDON, Va., April 28, 2025 /PRNewswire/ -- Expel , the leading managed detection and response (MDR) provider, today announced its return to the showfloor at RSAC™ Conference 2025. Find Expel in the South Hall of the Moscone Center (booth #0535) for product demos and activations celebrating the true heroes protecting our digital world: cybersecurity defenders."Security teams are often the unsung heroes of their organizations—protecting their businesses, people, and critical systems from threats every day," said Dave Merkel, co-founder and CEO, Expel. "But even the strongest defenders can't go it alone. Expel combines the best people, tech, and expertise to elevate our customers' efforts—creating a force multiplier against today's biggest threats for the best security outcomes."Security teams are fighting an uphill battle—balancing threats that are growing in volume, sophistication, and speed, especially enabled by generative AI, against tighter budgets and heightened scrutiny on their security programs. Expel combats these issues head-on by extending and enhancing security operations helping customers stay ahead of adversaries with industry-leading coverage across their attack surfaces, while maximizing the ROI on their existing security investments.Visit the booth to learn how Expel's human-centric, AI-driven MDR approach delivers the most comprehensive security coverage with unmatched results. Highlights include:A 17-minute mean-time-to-remediate on critical incidents, minimizing disruption so your business keeps running smoothly.on critical incidents, minimizing disruption so your business keeps running smoothly
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Consulting
Enterprise Software
Cybersecurity
Company Size
201-500
Company Stage
Series E
Total Funding
$288.8M
Headquarters
Herndon, Virginia
Founded
2016
Find jobs on Simplify and start your career today