Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Threat Detection & Automation Manager

Cummins Inc.

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.

This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.

The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.

The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

The Impact You Will Make

In this role, you will help modernize and mature the organization’s threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.

You will directly influence:

  • Detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments
  • Alert fidelity and false-positive reduction
  • Investigation speed and analyst consistency
  • SOAR automation maturity and response scalability
  • Detection lifecycle governance, testing, validation, and documentation
  • SecOps modernization across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms
  • Reduced manual triage and improved operational repeatability
  • Stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams

Key Responsibilities

Leadership and Team Management

  • Manage, mentor, and develop a team of detection engineering and automation professionals.
  • Build a culture of engineering rigor, operational discipline, innovation, accountability, quality, and continuous improvement.
  • Operate as a hands-on manager by personally owning, reviewing, and contributing to key detections, automation workflows, technical initiatives, and program improvements.
  • Define and execute the threat detection and automation strategy aligned to business risk, operational needs, threat landscape, compliance requirements, and organizational priorities.
  • Establish the team’s operating rhythm, including intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement.
  • Coach team members on detection logic, investigation quality, automation design, threat modeling, analyst usability, operational impact, and stakeholder communication.
  • Partner closely with SOC Monitoring, Incident Response, Threat Intelligence, SIEM Engineering, Cloud, Identity, Network, OT, IT Infrastructure, Vulnerability Management, GRC, and business stakeholders.

Threat Detection Engineering

  • Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms.
  • Personally own a portfolio of high-impact detections focused on complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats.
  • Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, kill-chain models, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk.
  • Conduct detection gap analysis and threat modeling to prioritize improvements based on exposure, telemetry readiness, attacker behavior, business impact, and operational value.
  • Build and maintain detection validation practices, including test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback loops.
  • Ensure detections are operationally useful by including clear context, enrichment, severity guidance, response steps, escalation paths, and containment recommendations.
  • Measure and expand detection coverage across ATT&CK tactics and techniques, critical assets, identities, cloud platforms, OT environments, and enterprise telemetry sources.
  • Stay current with emerging threats, adversary tradecraft, tools, vulnerabilities, and detection methods.

SIEM, SOAR, and Security Automation

  • Lead the design, development, and continuous improvement of SIEM and SOAR-driven detection and response workflows.
  • Build and optimize SIEM content, including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment.
  • Develop and mature SOAR playbooks that automate enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support.
  • Identify repetitive, high-volume, or high-value SOC activities that can be safely and effectively automated.
  • Define automation standards covering human-in-the-loop approvals, reversible actions, audit trails, exception handling, failure modes, escalation criteria, and rollback considerations.
  • Partner with SOC and Incident Response teams to ensure automation improves investigation speed, consistency, quality, and response outcomes without creating unnecessary operational risk.
  • Measure automation effectiveness using metrics such as analyst time saved, touch reduction, playbook success rate, case consistency, response acceleration, and manual effort reduction.
  • Drive integrations across SIEM, SOAR, EDR, email security, identity platforms, threat intelligence, ITSM, cloud security, network security, PAM, DLP/CASB, and OT monitoring platforms.

Detection Lifecycle, Governance, and Program Management

  • Build and mature the detection and automation lifecycle from intake through retirement.
  • Own standards for request intake, prioritization, design, build, peer review, testing, deployment, tuning, production monitoring, and continuous improvement.
  • Create and maintain use case standards, templates, documentation requirements, acceptance criteria, release gates, change history, and ownership models.
  • Manage the detection and automation roadmap based on threat intelligence, incident trends, MITRE coverage gaps, telemetry gaps, crown jewel risks, regulatory requirements, and business priorities.
  • Develop and maintain program metrics that demonstrate detection coverage, alert fidelity, false-positive trends, automation value, telemetry readiness, backlog health, delivery throughput, and investigation quality.
  • Partner with stakeholders to identify and resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and unclear ownership across the detection and response ecosystem.
  • Ensure detection and automation practices support internal policies, audit expectations, and applicable regulatory requirements.
  • Maintain audit-ready documentation and evidence, including rationale, test results, tuning notes, change history, ownership, approvals, validation results, and monitoring insights.
  • Communicate detection strategy, risk coverage, maturity, roadmap, and outcomes clearly to both technical and non-technical stakeholders, including executive leadership.

Preferred Qualifications

  • Master’s degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related discipline.
  • 10+ years of cybersecurity experience working in SOC and in creating SEIM correlations/detections and automating incident information enrichment tasks
  • Experience in building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases.
  • Experience building SOAR playbooks and automation workflows for phishing, malware, suspicious sign-ins, account compromise, endpoint containment, cloud alerts, privileged access activity, and threat intelligence enrichment.
  • Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns.
  • Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks.
  • Experience designing detections for identity-based attacks such as token theft, MFA bypass, device code phishing, OAuth abuse, suspicious consent grants, impossible travel, privileged role changes, and anomalous sign-ins.
  • Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases.
  • Experience working in large, complex enterprise or manufacturing environments with distributed stakeholders, shared ownership models, and operational constraints.
  • Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams.
  • Ability to distinguish between detection gaps, telemetry gaps, control gaps, ownership gaps, and response process gaps.
  • Excellent analytical and problem-solving skills, with the ability to balance precision, scale, operational usability, and business risk.
  • Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries.
  • Passion for automation, continuous improvement, high-quality engineering practices, and building durable security systems that scale.

Technical Competency Profile

  • Writing and tuning SIEM detections
  • Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches
  • SOAR playbook design and automation guardrails
  • Detection validation, regression testing, tuning, and release readiness
  • MITRE ATT&CK mapping and coverage measurement
  • Threat-informed detection engineering
  • Identity attack detection, including Entra ID, MFA abuse, token theft, OAuth abuse, suspicious consent grants, and privileged role changes
  • Endpoint detection and response workflows
  • Phishing, malware, suspicious email, and account compromise use cases
  • Cloud security detections and CNAPP telemetry
  • Network, DNS, proxy, firewall, VPN, and GlobalProtect telemetry
  • OT/ICS monitoring considerations in manufacturing environments
  • Privileged access monitoring and CyberArk-style PAM telemetry
  • Threat intelligence enrichment and operationalization
  • Case management, ITSM integration, and analyst workflow improvement
  • Detection-as-code, Git, CI/CD, reusable templates, and content lifecycle management

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.

This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.

The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.

The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

Job Systems/Information Technology

Organization Cummins Inc.

Role Category Off-site Remote

Job Type Exempt - Experienced

ReqID 2434879

Relocation Package No

100% On-Site No

Cummins and E-Verify

At Cummins, we are an equal opportunity and affirmative action employer dedicated to diversity in the workplace. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law. Cummins validates the right to work using E-Verify and will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee’s Form I-9 to confirm work authorization. Visit to know your rights on workplace discrimination.

Vacancy posted 24 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Threat Detection & Automation Manager in Troy, MI vacancy
  •  ...Midmarket Account Executive: Detection & Response Antigen...  ...specializing in comprehensive cybersecurity solutions. By leveraging top...  ...products tailored to specific threats and systems, we help organizations...  .... As a Microsoft Top 150 Managed Partner and exclusive... 
    Suggested
    Work experience placement
    Remote work

    Antigen Security

    Royal Oak, MI
    1 day ago
  • $140k - $175k

     ...build and scale intelligent AI, digital, cybersecurity, cloud and infrastructure solutions....  ...success is enabled by our world-class management consulting, delivery excellence and engineering...  ...Overview World Wide Technology's Automation Practice is seeking an Associate Client... 
    Suggested
    Full time
    Contract work
    Work experience placement
    Remote work
    Flexible hours
    Shift work

    World Wide Technology

    Rochester Hills, MI
    3 days ago
  • $95k - $105k

     ...Installation SupervisorThe Installation Supervisor leads onsite automation installations, coordinates project teams, and helps ensure...  ...issues.Installation leadership: Coordinate engineers, project managers, installers, contractors, customers, and internal teams.Schedule... 
    Suggested
    For contractors
    Remote work

    gpac

    Rochester, MI
    1 day ago
  •  ...Job Description Job Description Title : Senior Project Manager Location : Rochester Hills, MI Hire Type :Direct Compensation...  ...: Senior Project Manager – Medical & Pharmaceutical Automation Sterling Engineering is partnering with a leading custom... 
    Suggested

    Sterling Engineering Inc.

    Rochester Hills, MI
    16 days ago
  • Milton Hershey School, a cost-free pre-K through 12th grade residential school, is seeking a Youth Development Specialist in the Education, Training & E-Learning department. This role supports students’ academic, social, and emotional growth through mentoring, small-group...
    Suggested

    Milton Hershey School

    Troy, MI
    4 days ago
  • $46.92k

     ...development so they can reach their full potential. Responsibilities include: Providing daily supervision and mentorship Managing household routines and student schedules Administering medications and ensuring student wellness Driving students to... 
    Full time
    Work from home
    Relocation
    Relocation package
    Flexible hours
    Weekday work

    Milton Hershey School

    Troy, MI
    15 hours ago
  •  ...quality ratings. Conduct training across the organization and manage special process personnel testing and certifications. Oversee both...  ...with advanced technologies such as ATOS 5 Scan Box and automated quality systems. Strong problem-solving skills with a data-driven... 
    Full time
    Remote work

    StaffBright

    Sterling Heights, MI
    4 days ago
  •  ...Position Business Unit Regional IT Senior Manager, DMS Americas Location Auburn...  ..., assures compliance with IT and cybersecurity standards, and leads the regional IT workforce...  ...data pipelines, and plant level‑level automation. Strengthening IT/OT cybersecurity... 
    Full time
    Local area
    Immediate start
    Visa sponsorship
    Work visa

    BorgWarner Inc.

    Auburn Hills, MI
    4 days ago
  • IT Managed Services Account Manager Location: Hybrid Employment Type: Full-Time Join Our Growing Team! Are you passionate...  ...planning sessions. * Identify opportunities for managed services, cybersecurity, cloud, and professional services growth. * Collaborate with... 
    Full time
    Flexible hours

    Hyperion Managed Services

    Troy, MI
    more than 2 months ago
  •  ...Site Manager – Site Superintendent ACS is looking for a Site Manager – Site Superintendent...  ...of safety violation prevention and detection. Highly effective in communication and documentation...  ..., custom machines, testing solutions, automation, process and discrete production systems... 
    Work experience placement
    For subcontractor
    Work at office

    FAC Services, LLC

    Troy, MI
    4 days ago
  • $80k - $110k

     ...processes including welding, cutting, brazing, machining, process automation, and field repair. The Company leverages proprietary...  ...directing, and execution of local and/or global projects. The Project Manager is also responsible for managing projects and project team... 
    Full time
    Work experience placement
    Local area
    Shift work

    Lincoln Electric

    Macomb, MI
    2 days ago
  •  ...Job Description Job Description Description: Job Title: Project Manager I, Factory Automation (ONISTE M-F) About Us Solving your motion control challenges with ingenuity. Evolution Motion Solutions is a leading engineering partner, systems integrator,... 
    Work at office
    Flexible hours

    Evolution Motion Solutions

    Auburn Hills, MI
    18 days ago
  • $50 per hour

     ..., cutting, brazing, machining, process automation, and field repair. The Company leverages...  ...​ Primary Function The General Manager serves as the senior site leader with full...  ...with all applicable aerospace, cybersecurity, safety, environmental, and regulatory... 
    Contract work
    Temporary work
    For contractors
    Local area

    Lincoln Electric

    Macomb, MI
    more than 2 months ago
  •  ...sharing JOB DESCRIPTION TITLE: Construction Technology Manager LOCATION: Auburn Hills, Michigan 48326     OBJECTIVE...  ...Microsoft Office (Excel, Project) ~ Familiarity with APIs & automation (e.g., Python) is a plus ~ Strong leadership, communication,... 
    Contract work
    For contractors
    Work at office

    Commercial Contracting Corporation

    Auburn Hills, MI
    9 days ago
  •  ...Rochester Hills, MIHire Type:DirectCompensation:120-145k.Job Duties: Senior Project Manager - Medical & Pharmaceutical AutomationSterling Engineering is partnering with a leading custom automation company that is seeking a Senior Project Manager to oversee complex automation... 

    Sterling Engineering

    Rochester Hills, MI
    6 days ago
  • $97.2k - $129.5k

     ...buildings, infrastructure, and workplace services through the management of internal staff, service providers, and contractors. Supports...  ...electrical distribution, plumbing, fire protection, building automation systems, and general facility infrastructure. Coordinate and... 
    Full time
    Contract work
    For contractors
    Shift work

    UL Solutions

    Auburn Hills, MI
    2 days ago
  • Comau LLC is seeking a Site Manager to lead day-to-day operations at a manufacturing/automation site. You will oversee production, maintenance, and installation activities, ensuring safety, quality, and on-time delivery for global automotive and industrial customers. Responsibilities... 

    Comau LLC

    Southfield, MI
    12 days ago
  •  ...HVAC Manager Founded by Detroit philanthropists George and Ellen Booth in 1904, Cranbrook Educational Community is one of the...  ...and related regulatory requirements. Knowledge of building automation systems, including JCI Metasys or similar platforms. Valid... 
    Temporary work
    For contractors
    Local area
    Afternoon shift

    Cranbrook Educational Community

    Bloomfield Hills, MI
    4 days ago
  • $50k

     ...Aqua Tots Swim School - Aqua Tots Sterling Heights, LLC in Rochester Hills is looking for an Aquatics Manager to join their team. This full-time position offers a salary starting at $50,000+ per year, depending on experience, and requires strong multitasking and organizational... 
    Weekly pay
    Full time
    Flexible hours

    Aqua-Tots Swim School

    Rochester Hills, MI
    5 days ago
  • $50k

     ...looking for a FUN and AWESOME place to work, then look no more. Aqua Tots Swim Schools Sterling Heights is looking for an Aquatics Manager. Must be able to multitask, be extremely organized, manage a team, and work in a fast-paced environment. Looking to fill position ASAP... 
    Weekly pay
    Full time
    Immediate start
    Monday to Friday
    Flexible hours
    Shift work
    Rotating shift
    Weekday work

    Aqua-Tots Swim School

    Rochester Hills, MI
    2 days ago
  • $50k

     ...for a FUN and AWESOME place to work, look no further! Aqua-Tots Swim Schools is looking for an energetic and organized Aquatics Manager to join our team. This is a leadership role in a fast-paced environment, so candidates must be comfortable multitasking,... 
    Weekly pay
    Full time
    Monday to Friday
    Flexible hours
    Shift work
    Weekend work
    Day shift
    Afternoon shift
    Early shift
    1 day per week
    Weekday work

    Aqua-Tots Swim School

    Rochester, MI
    3 days ago
  • $140k - $160k

     ...Logicalis' clients. Works with RMO and PMO in scheduling and managing engagements. Works with Logicalis' clients to perform...  ...security analytics ~ Microsoft Entra ID Protection for identity threat detection and remediation Strong understanding of Microsoft... 
    Full time
    Work at office
    Local area

    Logicalis, Inc.

    Troy, MI
    4 days ago
  •  ...transformation. By leveraging the power of design thinking, AI, and automation, we create seamless, enjoyable digital experiences that make...  ...strategy. Job Description The Engagement Manager is expected to function as an account manager with responsibility... 
    Temporary work

    QuantumWork Advisory

    Troy, MI
    5 days ago
  •  ...Job Description Job Description Operations Manager – Managed IT Services AG Schwallbach LLC (AGS)   On-Site – Madison Heights...  ...•        Direct experience in managed IT services and cybersecurity •        Experience leading client onboarding, offboarding and... 
    Full time
    Contract work
    Temporary work
    Work at office
    Remote work

    AG Schwallbach LLC

    Madison Heights, MI
    7 days ago
  •  ...Mill Manager Oversee mill operations, ensure quality and compliance, lead continuous improvements, and manage cross-functional teams...  ...driving a quality culture preferred. Knowledge of automated control systems. Broad technological background in hot and... 
    Work experience placement

    Talascend

    Troy, MI
    5 days ago
  •  ...multiple locations to learn the business and the organization. Previous experience in auto repair, building construction, and/or retail management is highly recommended. Assistant Managers (Managers in Training) are responsible for all facets of customer service, order... 
    Work at office
    Local area

    Henderson Glass

    Rochester, MI
    2 days ago
  •  ...General Manager A General Manager provides leadership at and supports the management team as well as the hourly team. You will help to develop, direct, and supervise hourly Team Members, while also making great strides in your own professional development! What you... 
    Hourly pay
    Flexible hours

    The Red Wagon Shoppe

    Troy, MI
    3 days ago
  •  ...Subway® Manager As part of the Subway® Team, you will focus on providing an excellent guest experience, ensuring that great food is prepared and served, keeping our restaurants functional, clean and beautiful, managing inventory and money control systems, coordinating... 
    Full time
    Part time
    Local area
    Weekend work
    Day shift
    Afternoon shift

    Subway - 14627-0

    Troy, MI
    2 days ago
  •  ...Job Title Automotive Sales Manager Job Overview CarGuys Inc. works with dealerships across the country. We are seeking an Automotive Sales Manager to lead and develop high-performance sales teams at our dealership partners. Benefits An above-average salary based on industry... 

    Car Guys

    Troy, MI
    1 day ago
  •  ...Manager Trainee Make BIG Money at Menards! Extra $3 per hour on Sat/Sun Store Discount Profit Sharing Exclusive Discounts for gyms, car dealerships, cell phone plans, and more! Flexible Scheduling Medical Insurance and Dental Plans On-the-job training... 
    Hourly pay
    Full time
    Traineeship
    Work at office
    Immediate start
    Flexible hours

    Menards

    Bloomfield Hills, MI
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Threat Detection & Automation Manager. Be the first to apply!