Cybersecurity Threat Detection – Automation Manager

🕒 August 19

🏈 Alabama, Alaska, +44 more states – Remote

infoinfo

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 11%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cummins Inc.

Cummins Inc.

10,000+ employees

Founded 1919

🏗️ Construction

💼 Consulting

🏥 Healthcare

💰 $75M Grant on 2024-07

Construction • Consulting • Healthcare

Cummins Inc. is a global power technology leader that designs, manufactures, and distributes a variety of engines and power systems solutions. They offer products that range from diesel and natural gas engines to hybrid and electric power systems, as well as components like turbochargers, fuel systems, and emissions solutions. With a strong emphasis on innovation, Cummins aims to reduce emissions and improve fuel efficiency. The company is dedicated to helping industries navigate the transition to cleaner energy through integrated power solutions suitable for diverse applications such as on-highway, marine, mining, and construction. Additionally, Cummins provides services including remote monitoring, diagnostics, and aftermarket support, reinforcing its commitment to sustainability and customer service excellence.

📋 Description

• Manage, mentor, and develop a team of detection engineering and automation professionals • Define and execute threat detection and automation strategy aligned with business risk, threats, compliance, and organizational priorities • Establish intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement processes • Personally own, review, and contribute to key detections, automation workflows, technical initiatives, and program improvements • Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms • Translate adversary behavior and threat intelligence into actionable analytics using MITRE ATT&CK and kill-chain models • Conduct detection gap analysis and threat modeling • Build detection validation, testing, regression, monitoring, and analyst feedback practices • Lead SIEM and SOAR detection and response workflows • Develop SOAR playbooks for enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support • Identify SOC activities suitable for automation and measure automation effectiveness • Drive integrations across SIEM, SOAR, EDR, email security, identity, threat intelligence, ITSM, cloud, network, PAM, DLP/CASB, and OT platforms • Build and mature the detection and automation lifecycle from intake through retirement • Manage the detection and automation roadmap and program metrics • Resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and ownership issues • Maintain audit-ready documentation and communicate strategy, risk coverage, roadmap, and outcomes to technical, non-technical, and executive stakeholders • Partner with SOC Monitoring, Incident Response, Threat Intelligence, SIEM Engineering, Cloud, Identity, Network, OT, IT Infrastructure, Vulnerability Management, GRC, and business stakeholders

🎯 Requirements

• 10+ years of cybersecurity experience working in SOC and in creating SIEM correlations/detections and automating incident information enrichment tasks • Experience building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases • Experience building SOAR playbooks and automation workflows • Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns • Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks • Experience designing detections for identity-based attacks, including token theft, MFA bypass, device code phishing, OAuth abuse, suspicious consent grants, impossible travel, privileged role changes, and anomalous sign-ins • Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases • Experience working in large, complex enterprise or manufacturing environments • Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams • Proficiency in Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches • Knowledge of SOAR playbook design, automation guardrails, MITRE ATT&CK, EDR workflows, cloud security, CNAPP telemetry, network/DNS/proxy/firewall/VPN/GlobalProtect telemetry, OT/ICS monitoring, PAM telemetry, ITSM integration, Git, and CI/CD • Demonstrated ability to lead, coach, and advise team members • Master’s degree is listed as preferred, not required

Apply Now

Similar Jobs

🕒 August 19

Dark Wolf Solutions

51 - 200

💼 Consulting

📦 Logistics

🏥 Healthcare

Cybersecurity engineer leading RMF authorization, risk assessments, and compliance for Dark Wolf Solutions’ defense systems. Strengthening cyber defenses through incident response, reporting, and process automation.

🕒 August 19

True Zero Technologies, LLC

11 - 50

💼 Consulting

🏥 Healthcare

📦 Logistics

Cybersecurity Engineer implementing and validating Zero Trust capabilities for enterprise and federal systems. Supporting security controls, testing, documentation, and operational risk reduction.

🕒 August 19

Humana

10,000+ employees

🏥 Healthcare

🛡️ Insurance

⚕️ Healthcare Insurance

Senior Cybersecurity Engineer engineering cloud data-protection solutions for Humana, a U.S. healthcare and insurance company. Building Azure/GCP deployments, security controls, and CI/CD pipelines.

🕒 August 19

Ryder System, Inc.

10,000+ employees

🚘 Automotive

💼 Consulting

🏥 Healthcare

Senior Director leading Ryder’s enterprise AI security strategy, governance, and architecture. Securing generative AI, LLMs, and AI/ML adoption across Ryder’s transportation and supply chain operations.

🕒 August 19

AECOM

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Transit safety specialist leading FTA/APTA risk and security projects for AECOM, a global infrastructure consulting firm. Developing safety analyses, certifications, PTASPs, and client training.