Cybersecurity Threat Detection – Automation Manager

🕒 September 16

🏈 Alabama, Alaska, +44 more states – Remote

infoinfo

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 11%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cummins Inc.

Cummins Inc.

10,000+ employees

Founded 1919

🏗️ Construction

💼 Consulting

🏥 Healthcare

💰 $75M Grant on 2024-07

Construction • Consulting • Healthcare

Cummins Inc. is a global power technology leader that designs, manufactures, and distributes a variety of engines and power systems solutions. They offer products that range from diesel and natural gas engines to hybrid and electric power systems, as well as components like turbochargers, fuel systems, and emissions solutions. With a strong emphasis on innovation, Cummins aims to reduce emissions and improve fuel efficiency. The company is dedicated to helping industries navigate the transition to cleaner energy through integrated power solutions suitable for diverse applications such as on-highway, marine, mining, and construction. Additionally, Cummins provides services including remote monitoring, diagnostics, and aftermarket support, reinforcing its commitment to sustainability and customer service excellence.

📋 Description

• Manage, mentor, and develop a team of detection engineering and automation professionals • Define and execute the threat detection and automation strategy • Establish intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement processes • Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms • Own high-impact detections for complex use cases, critical risks, advanced adversary behaviors, and enterprise threats • Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk • Conduct detection gap analysis and threat modeling • Build detection validation practices, including test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback loops • Lead SIEM and SOAR detection and response workflows • Build and optimize SIEM content, correlation rules, dashboards, risk-based alerts, data models, investigation views, and alert enrichment • Develop SOAR playbooks for enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support • Drive integrations across SIEM, SOAR, EDR, email security, identity, threat intelligence, ITSM, cloud, network, PAM, DLP/CASB, and OT monitoring platforms • Manage the detection and automation roadmap and lifecycle from intake through retirement • Develop program metrics covering detection coverage, alert fidelity, false positives, automation value, telemetry readiness, backlog health, throughput, and investigation quality • Maintain audit-ready documentation and communicate strategy, risk coverage, roadmap, and outcomes to technical, non-technical, and executive stakeholders

🎯 Requirements

• 10+ years of cybersecurity experience working in SOC and in creating SIEM correlations/detections and automating incident information enrichment tasks • Master’s degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related discipline (preferred) • Experience building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases • Experience building SOAR playbooks and automation workflows • Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns • Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks • Experience designing detections for identity-based attacks, endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases • Experience working in large, complex enterprise or manufacturing environments • Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams • Excellent analytical and problem-solving skills • Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries • Proficiency in Splunk SPL, risk-based alerting, notable events, dashboards, correlation searches, SOAR, MITRE ATT&CK, EDR, CNAPP, network telemetry, OT/ICS monitoring, PAM, ITSM, Git, and CI/CD

Apply Now

Similar Jobs

🕒 September 16

TBI

5001 - 10000

🏗️ Construction

🏠 Real Estate

Personnel Security Specialist supporting GovStrive’s federal agency clients with background investigations, vetting, onboarding, and personnel security compliance. Managing eAPP cases, fingerprints, and sensitive records remotely.

🕒 September 16

W.C. Bradley Co.

501 - 1000

🍽️ Food & Beverage

🏨 Hospitality

🛒 Retail

EHSS leader standardizing safety, environmental compliance, and operational risk across W.C. Bradley’s U.S. pellet mills and distribution centers. Leading site managers, audits, training, investigations, and corrective actions.

🕒 September 16

Multi Media, LLC

51 - 200

💼 Consulting

📣 Marketing

📱 Media

Staff Security Engineer building threat intelligence, detection, and response capabilities for a global live-streaming platform. Applying cloud security, offensive security, and AI-driven tools to protect users and systems.

🕒 September 15

Alteryx

1001 - 5000

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

Senior legal counsel advising Alteryx, a data-analytics and automation company, on privacy, security, and AI matters. Leading complex customer and vendor negotiations and developing legal standards.

🕒 September 15

Guidewire Software

1001 - 5000

🛡️ Insurance

Senior Security Engineer securing Guidewire’s AWS-first cloud platform for P&C insurers. Building infrastructure, CI/CD, and AI security controls across teams.