Cybersecurity Threat Detection – Automation Manager

🔥 0 minutes ago

🏈 Alabama, Alaska, +44 more states – Remote

infoinfo

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cummins Inc.

Cummins Inc.

10,000+ employees

Founded 1919

🏗️ Construction

💼 Consulting

🏥 Healthcare

💰 $75M Grant on 2024-07

Construction • Consulting • Healthcare

Cummins Inc. is a global power technology leader that designs, manufactures, and distributes a variety of engines and power systems solutions. They offer products that range from diesel and natural gas engines to hybrid and electric power systems, as well as components like turbochargers, fuel systems, and emissions solutions. With a strong emphasis on innovation, Cummins aims to reduce emissions and improve fuel efficiency. The company is dedicated to helping industries navigate the transition to cleaner energy through integrated power solutions suitable for diverse applications such as on-highway, marine, mining, and construction. Additionally, Cummins provides services including remote monitoring, diagnostics, and aftermarket support, reinforcing its commitment to sustainability and customer service excellence.

📋 Description

• Lead, manage, mentor, and develop a team of detection engineering and automation professionals • Define and execute threat detection and automation strategy aligned with business risk, threats, compliance, and organizational priorities • Establish intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement processes • Design, develop, tune, and optimize threat detections across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms • Own high-impact detections for complex use cases, critical risks, advanced adversary behaviors, and enterprise threats • Translate adversary behavior, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk into actionable analytics • Conduct detection gap analysis and threat modeling • Build detection validation practices with test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback • Lead SIEM and SOAR detection and response workflows • Build SIEM content including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment • Develop SOAR playbooks for enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support • Identify and automate repetitive, high-volume, or high-value SOC activities • Drive integrations across SIEM, SOAR, EDR, email security, identity, threat intelligence, ITSM, cloud, network, PAM, DLP/CASB, and OT platforms • Build and mature the detection and automation lifecycle from intake through retirement • Manage the detection and automation roadmap and program metrics • Resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and unclear ownership • Maintain audit-ready documentation and communicate strategy, risk coverage, maturity, roadmap, and outcomes to technical, non-technical, and executive stakeholders

🎯 Requirements

• 10+ years of cybersecurity experience working in SOC and in creating SIEM correlations/detections and automating incident information enrichment tasks • Experience building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases • Experience building SOAR playbooks and automation workflows • Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns • Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks • Experience designing detections for identity-based attacks, endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases • Experience working in large, complex enterprise or manufacturing environments • Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams • Ability to distinguish detection, telemetry, control, ownership, and response process gaps • Excellent analytical and problem-solving skills • Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries • Passion for automation, continuous improvement, high-quality engineering practices, and scalable security systems • Technical competency with Splunk SPL, risk-based alerting, notable events, dashboards, correlation searches, SOAR, MITRE ATT&CK, Entra ID, EDR, CNAPP, DNS, proxy, firewall, VPN, GlobalProtect, OT/ICS, PAM, CyberArk-style telemetry, ITSM, Git, and CI/CD • Master’s degree is listed as preferred, not required

Apply Now

Similar Jobs

🔥 1 hour ago

Corteva Agriscience

10,000+ employees

🍽️ Food & Beverage

💼 Consulting

🏥 Healthcare

Email Security Engineer securing Corteva’s Exchange, email authentication, and messaging infrastructure. Supporting reliable, compliant communications for the global agriscience company.

🔥 1 hour ago

Corteva Agriscience

10,000+ employees

🍽️ Food & Beverage

💼 Consulting

🏥 Healthcare

Email Security Engineer architecting and securing Corteva’s Exchange, Microsoft 365, and enterprise messaging infrastructure. Supporting mail flow, authentication, incident response, and compliance for a global agriscience company.

🔥 1 hour ago

Logically

51 - 200

🤖 Artificial Intelligence

☁️ SaaS

🔐 Security

Senior Security Implementation Engineer leading enterprise cybersecurity deployments for Logically’s customers. Architecting firewalls, SASE/SSE, email, endpoint, SIEM, wireless, and compliance solutions.

🔥 1 hour ago

Baker Tilly US

5001 - 10000

🏗️ Construction

🏥 Healthcare

📦 Logistics

PCI-focused IT risk consultant conducting audits, cybersecurity assessments, and control reviews for Baker Tilly advisory clients. Developing recommendations, reports, and client relationships.

🔥 2 hours ago

FastSpring

51 - 200

💼 Consulting

📦 Logistics

📣 Marketing

Sr. Security Engineer securing FastSpring’s global payments platform and AWS infrastructure. Shaping application security practices for AI-assisted software development.