Full-Time

Customer Success Manager

Scale

Expel

Expel

201-500 employees

Software-driven MDR services with threat analysis

Compensation Overview

$93.9k - $136.2k/yr

+ Bonus Eligibility + Equity

H1B Sponsorship Available

Remote in USA

Remote

Must be authorized to work in the United States.

Category
Customer Experience & Support (1)

Get referred to Expel

See people who can refer or advise you

Requirements
  • 2+ years of customer success, account management, or customer-facing experience
  • At least 2 years in the security industry (operations, products, consulting, governance, risk, and compliance, or incident response)
  • Familiarity with CS platforms, ticketing systems, and automation tools, with opinions about what works
  • Solid security domain fluency: MDR, EDR, SIEM, NDR, cloud security, and how a real security program fits together
Responsibilities
  • Help design, execute and continuously improve playbook-driven customer interactions across the scale segment: new customer/onboarding, health checks, renewals, proactive outreach
  • Own specific motions or programs within the model, from design through execution and measurement
  • Exercise judgment on edge cases, distinguishing between situations that fit the playbook, situations that need a creative solution, and situations that require escalation
  • Design and lead one-to-many customer engagements: webinars, digital campaigns, scaled communications
  • Identify patterns in customer interactions and translate them into process improvements that make the scale function stronger
  • Maintain technical credibility in every interaction, speaking knowledgeably about Expel's service, security operations, and common integration patterns
  • Provide coaching and guidance to associate-level team members on process execution and customer handling
  • Contribute to the design of the scale operating model itself: systems requirements, automation workflows, measurement frameworks
Desired Qualifications
  • Experience in a scale, scaled, or digital CS model is strongly preferred
  • Experience designing or significantly improving customer-facing processes or playbooks

Expel provides Managed Detection and Response (MDR) services that help organizations protect their digital assets. It combines technology and human expertise to monitor, detect, and respond to threats across cloud, SaaS, and on‑premises systems. The platform collects logs and alerts from a company’s existing tech stack and processes them with automated tools and security analysts to identify malicious activity and take action. It also offers clear, actionable recommendations to improve security and maximize ROI, along with workflows that support and augment a company’s security team. Unlike some providers that rely on limited tools or slow handoffs, Expel emphasizes quick integration with new technologies and a transparent, software‑driven approach that continuously improves security posture. The company’s goal is to raise a customer’s security maturity while delivering measurable security outcomes and better ROI by preventing incidents and guiding future security spending.

Company Size

201-500

Company Stage

Series E

Total Funding

$288.8M

Headquarters

Herndon, Virginia

Founded

2016

Get referred to Expel

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • 24x7x365 coverage and 14-minute MTTR strengthen buyer confidence in rapid response.
  • Google SecOps and Microsoft coverage expand distribution inside dominant cloud ecosystems.
  • Automated remediation across phishing, identity, and endpoints creates clear efficiency gains.

What critics are saying

  • Microsoft-native SecOps bundles directly substitute for Expel's outsourced MDR offering.
  • Agentic automation failures become highly visible and damage trust during major incidents.
  • Easy integrations lower switching costs and invite cheaper MDR competitors.

What makes Expel unique

  • Expel combines MDR software, analysts, and Workbench transparency in one service.
  • Ruxie AI now automates enrichment, triage, investigation, response, and reporting.
  • Expel supports 160+ integrations across cloud, identity, SaaS, endpoints, and networks.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Unlimited vacation

401k plan

Healthcare plan with dental and vision

Flexible work hours

Opportunity to work from home

One paid conference per year

Parental leave

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

0%
PR Newswire
Mar 23rd, 2026
Expel launches Managed SIEM to tackle detection engineering burden for Sentinel and Splunk users

Expel has launched Expel Managed SIEM, a co-managed service that integrates the company's detection engineering expertise into customers' existing Microsoft Sentinel and Splunk Enterprise Security environments. The service is now generally available as an add-on to Expel MDR. The offering handles detection strategy, writes custom detection logic, optimises data ingestion costs, and feeds SIEM alerts into Expel's MDR response workflows. Unlike traditional providers that profit from increased data volume, Expel helps customers control ingestion costs whilst maintaining security coverage. The service includes two tiers: Detection Engineering provides ongoing detection support and rule optimisation, whilst Performance Engineering offers deeper operational support including SIEM health monitoring and automation development. Customers retain full ownership of all detection rules created by Expel, with complete visibility into every tuning decision.

PR Newswire
Apr 28th, 2025
Expel Brings Security Heroes Together At Rsac™ Conference 2025

Leading MDR provider to celebrate security defenders with cutting-edge service innovations and exclusive VIP experiencesHERNDON, Va., April 28, 2025 /PRNewswire/ -- Expel , the leading managed detection and response (MDR) provider, today announced its return to the showfloor at RSAC™ Conference 2025. Find Expel in the South Hall of the Moscone Center (booth #0535) for product demos and activations celebrating the true heroes protecting our digital world: cybersecurity defenders."Security teams are often the unsung heroes of their organizations—protecting their businesses, people, and critical systems from threats every day," said Dave Merkel, co-founder and CEO, Expel. "But even the strongest defenders can't go it alone. Expel combines the best people, tech, and expertise to elevate our customers' efforts—creating a force multiplier against today's biggest threats for the best security outcomes."Security teams are fighting an uphill battle—balancing threats that are growing in volume, sophistication, and speed, especially enabled by generative AI, against tighter budgets and heightened scrutiny on their security programs. Expel combats these issues head-on by extending and enhancing security operations helping customers stay ahead of adversaries with industry-leading coverage across their attack surfaces, while maximizing the ROI on their existing security investments.Visit the booth to learn how Expel's human-centric, AI-driven MDR approach delivers the most comprehensive security coverage with unmatched results. Highlights include:A 17-minute mean-time-to-remediate on critical incidents, minimizing disruption so your business keeps running smoothly.on critical incidents, minimizing disruption so your business keeps running smoothly

Decrypt
Mar 18th, 2025
Microsoft Flags Trojan Malware Targeting Metamask, Phantom And Coinbase Wallets

Microsoft security researchers have identified a new malware threat targeting popular crypto wallet extensions including MetaMask and Phantom.The StilachiRAT remote access trojan was first discovered in November 2024 and has since been deeply analyzed to reveal the depth of this threat. Specifically, it can target crypto wallets.MetaMask, Coinbase, Phantom, Keplr and more could be at risk as the RAT is able to scan for cryptocurrency wallet extensions in the Google Chrome browser. It can then extract and decrypt saved credentials to access usernames and passwords.The information gathering RAT can continuously monitor clipboard content, as it actively hunts for sensitive information like cryptocurrency keys and passwords.The researchers shared examples of the regular expressions the RAT uses to scan clipboard contents for credentials, noting that they're seeking information related to the Tron network—which is particularly popular in China.Microsoft says that StilachiRAT targets specific wallets including: Bitget Wallet, Trust Wallet, TronLink, MetaMask, TokenPocket, BNB Chain Wallet, OKX Wallet, Sui Wallet, Braavos - Starknet Wallet, Coinbase Wallet, Leap Cosmos Wallet, Manta Wallet, Kepler, Phantom, Compass Wallet for Sei, Math Wallet, Fractal Wallet, Station Wallet, ConfluxPortal, and Plug.Aaron Walton, Threat Intel Analyst at Expel, told Decrypt: "Infostealing malware, leverages social engineering to trick users into downloading and executing malicious code. These lures range from everything from a download, to a job offer, or even a fake-captcha that interrupts a user while web browsing."There is big money to be made and the tactics criminals are using can bypass basic security and even business level defenses."StilachiRAT appears to be using anti-forensic behaviors, including clearing event logs and evading detection.The Microsoft Incident Response team says: "Based on Microsoft’s current visibility, the malware does not exhibit widespread distribution at this time. However, due to its stealth capabilities and the rapid changes within the malware ecosystem, we are sharing these findings as part of our ongoing efforts to monitor, analyze, and report on the evolving threat landscape."Edited by Stacy Elliott.Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more

PR Newswire
Mar 13th, 2025
Expel Introduces Industry-First Mdr Coverage For Oracle Cloud Infrastructure

MDR pioneer extends lead in cloud security with expanded cloud control plane coverage, continues its commitment to multi-cloud organizationsHERNDON, Va., March 12, 2025 /PRNewswire/ -- Expel , the leading managed detection and response (MDR) provider, today announced expanded cloud control plane MDR coverage to include Oracle Cloud Infrastructure (OCI). Expel is the first MDR services provider to cover OCI environments, and with this announcement extends its established leadership position in managed cloud detection and response.In addition to OCI, Expel offers leading MDR services for Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. Coupled with support for Kubernetes and multiple cloud security tools like Wiz, Lacework, and Orca, the Expel MDR ™ is uniquely suited to provide comprehensive protection for multi-cloud environments. Approximately 80% of organizations operate in multi-cloud or hybrid cloud environments, and many lack the internal expertise needed to effectively manage the security of their cloud configurations. This can lead to unmanageable alerts, misaligned security controls, and security gaps."Multi-cloud and hybrid cloud environments are practically ubiquitous, but many enterprises struggle to effectively manage security across these platforms," said Yonni Shelmerdine, Chief Product Officer at Expel. "We've added MDR support for OCI to ease that burden—addressing a critical cloud security need for many enterprises and lightening the load for increasingly over-taxed security teams."Furthering its commitment to cloud security, Expel has joined the Cloud Security Alliance (CSA), the world's leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment

Silicon Canals
Feb 27th, 2025
"Expel Is An Excellent Choice For Tech-Forward Enterprise Customers Looking For A Premium Provider To Manage The Entirety Of The Detection And Response Lifecycle," Says Independent Research Firm

Expel named a Leader in managed detection and response (MDR) services industry research report, and is cited for its strengths in detection and analyst experienceHERNDON, Va.–(BUSINESS WIRE)–Expel, the leading MDR provider, was named a Leader in The Forrester Wave™: Managed Detection and Response Services, Q1 2025. Expel received a five-out-of-five score (“superior relative to others in this evaluation”) in 15 out of 21 criteria, including the extended detection, cloud, and identity detection surface criteria, as well as analyst experience, integrations, and metrics, among others. The report states, “Expel’s strategy continues to successfully strike a balance between human delivery and software-enabled platforms that few in the cybersecurity market can replicate.”Expel is one of only three vendors recognized as a Leader in The Forrester Wave: Managed Detection and Response Services, Q1 2025.“Expel has always understood what security practitioners need because we’ve been in their shoes. In fact, we never left. We’re constantly working alongside our customers, innovating and iterating in lock-step with their security needs,” said Dave Merkel, co-founder and CEO of Expel. “For us, Forrester’s analysis reaffirms our commitment to being the trusted security partner our customers rely on (and deserve), so that our 1000th customer experiences the same positive security outcomes as our first.”The report states, “Rapid onboarding, unmatched transparency for its customers, and plans to expand its access to customer data wherever it’s stored confirm the provider is still plugged into what MDR customers need.”Expel MDR delivers trusted outcomes for customers at all phases of their security journeys