Cybersecurity Threat Detection – Automation Manager
Job Description:
- Lead, manage, mentor, and develop a team of detection engineering and automation professionals
- Define and execute threat detection and automation strategy aligned with business risk, operational needs, threat landscape, compliance requirements, and organizational priorities
- Establish intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement processes
- Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms
- Own high-impact detections for complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats
- Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk
- Conduct detection gap analysis and threat modeling
- Build detection validation practices, test cases, regression checks, tuning evidence, performance monitoring, and analyst feedback loops
- Lead SIEM and SOAR detection and response workflows
- Build SIEM content including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment
- Develop SOAR playbooks for enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support
- Drive integrations across SIEM, SOAR, EDR, email security, identity, threat intelligence, ITSM, cloud, network, PAM, DLP/CASB, and OT monitoring platforms
- Build and mature the detection and automation lifecycle from intake through retirement
- Manage the detection and automation roadmap and program metrics
- Maintain audit-ready documentation and evidence
- Communicate strategy, risk coverage, maturity, roadmap, and outcomes to technical and non-technical stakeholders, including executive leadership
Requirements:
- 10+ years of cybersecurity experience working in SOC and creating SIEM correlations/detections and automating incident information enrichment tasks
- Experience building mature detection lifecycle practices
- Experience building SOAR playbooks and automation workflows
- Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns
- Experience operationalizing threat intelligence
- Experience designing detections for identity-based attacks
- Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases
- Experience working in large, complex enterprise or manufacturing environments
- Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams
- Ability to distinguish between detection, telemetry, control, ownership, and response process gaps
- Excellent analytical and problem-solving skills
- Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries
- Writing and tuning SIEM detections
- Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches
- SOAR playbook design and automation guardrails
- Detection validation, regression testing, tuning, and release readiness
- MITRE ATT&CK mapping and coverage measurement
- Threat-informed detection engineering
- Identity attack detection, including Entra ID, MFA abuse, token theft, OAuth abuse, suspicious consent grants, and privileged role changes
- Endpoint detection and response workflows
- Phishing, malware, suspicious email, and account compromise use cases
- Cloud security detections and CNAPP telemetry
- Network, DNS, proxy, firewall, VPN, and GlobalProtect telemetry
- OT/ICS monitoring considerations in manufacturing environments
- Privileged access monitoring and CyberArk-style PAM telemetry
- Threat intelligence enrichment and operationalization
- Case management, ITSM integration, and analyst workflow improvement
- Detection-as-code, Git, CI/CD, reusable templates, and content lifecycle management
Benefits:
- Equal employment opportunity policy
- Off-site remote work arrangement