Cybersecurity Threat Detection & Automation Manager
Cummins Inc.
The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.
This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.
The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.
The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.
The Impact You Will Make
In this role, you will help modernize and mature the organization’s threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.
You will directly influence:
- Detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments
- Alert fidelity and false-positive reduction
- Investigation speed and analyst consistency
- SOAR automation maturity and response scalability
- Detection lifecycle governance, testing, validation, and documentation
- SecOps modernization across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms
- Reduced manual triage and improved operational repeatability
- Stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams
Key Responsibilities
Leadership and Team Management
- Manage, mentor, and develop a team of detection engineering and automation professionals.
- Build a culture of engineering rigor, operational discipline, innovation, accountability, quality, and continuous improvement.
- Operate as a hands-on manager by personally owning, reviewing, and contributing to key detections, automation workflows, technical initiatives, and program improvements.
- Define and execute the threat detection and automation strategy aligned to business risk, operational needs, threat landscape, compliance requirements, and organizational priorities.
- Establish the team’s operating rhythm, including intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement.
- Coach team members on detection logic, investigation quality, automation design, threat modeling, analyst usability, operational impact, and stakeholder communication.
- Partner closely with SOC Monitoring, Incident Response, Threat Intelligence, SIEM Engineering, Cloud, Identity, Network, OT, IT Infrastructure, Vulnerability Management, GRC, and business stakeholders.
Threat Detection Engineering
- Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms.
- Personally own a portfolio of high-impact detections focused on complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats.
- Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, kill-chain models, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk.
- Conduct detection gap analysis and threat modeling to prioritize improvements based on exposure, telemetry readiness, attacker behavior, business impact, and operational value.
- Build and maintain detection validation practices, including test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback loops.
- Ensure detections are operationally useful by including clear context, enrichment, severity guidance, response steps, escalation paths, and containment recommendations.
- Measure and expand detection coverage across ATT&CK tactics and techniques, critical assets, identities, cloud platforms, OT environments, and enterprise telemetry sources.
- Stay current with emerging threats, adversary tradecraft, tools, vulnerabilities, and detection methods.
SIEM, SOAR, and Security Automation
- Lead the design, development, and continuous improvement of SIEM and SOAR-driven detection and response workflows.
- Build and optimize SIEM content, including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment.
- Develop and mature SOAR playbooks that automate enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support.
- Identify repetitive, high-volume, or high-value SOC activities that can be safely and effectively automated.
- Define automation standards covering human-in-the-loop approvals, reversible actions, audit trails, exception handling, failure modes, escalation criteria, and rollback considerations.
- Partner with SOC and Incident Response teams to ensure automation improves investigation speed, consistency, quality, and response outcomes without creating unnecessary operational risk.
- Measure automation effectiveness using metrics such as analyst time saved, touch reduction, playbook success rate, case consistency, response acceleration, and manual effort reduction.
- Drive integrations across SIEM, SOAR, EDR, email security, identity platforms, threat intelligence, ITSM, cloud security, network security, PAM, DLP/CASB, and OT monitoring platforms.
Detection Lifecycle, Governance, and Program Management
- Build and mature the detection and automation lifecycle from intake through retirement.
- Own standards for request intake, prioritization, design, build, peer review, testing, deployment, tuning, production monitoring, and continuous improvement.
- Create and maintain use case standards, templates, documentation requirements, acceptance criteria, release gates, change history, and ownership models.
- Manage the detection and automation roadmap based on threat intelligence, incident trends, MITRE coverage gaps, telemetry gaps, crown jewel risks, regulatory requirements, and business priorities.
- Develop and maintain program metrics that demonstrate detection coverage, alert fidelity, false-positive trends, automation value, telemetry readiness, backlog health, delivery throughput, and investigation quality.
- Partner with stakeholders to identify and resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and unclear ownership across the detection and response ecosystem.
- Ensure detection and automation practices support internal policies, audit expectations, and applicable regulatory requirements.
- Maintain audit-ready documentation and evidence, including rationale, test results, tuning notes, change history, ownership, approvals, validation results, and monitoring insights.
- Communicate detection strategy, risk coverage, maturity, roadmap, and outcomes clearly to both technical and non-technical stakeholders, including executive leadership.
Preferred Qualifications
- Master’s degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related discipline.
- 10+ years of cybersecurity experience working in SOC and in creating SEIM correlations/detections and automating incident information enrichment tasks
- Experience in building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases.
- Experience building SOAR playbooks and automation workflows for phishing, malware, suspicious sign-ins, account compromise, endpoint containment, cloud alerts, privileged access activity, and threat intelligence enrichment.
- Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns.
- Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks.
- Experience designing detections for identity-based attacks such as token theft, MFA bypass, device code phishing, OAuth abuse, suspicious consent grants, impossible travel, privileged role changes, and anomalous sign-ins.
- Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases.
- Experience working in large, complex enterprise or manufacturing environments with distributed stakeholders, shared ownership models, and operational constraints.
- Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams.
- Ability to distinguish between detection gaps, telemetry gaps, control gaps, ownership gaps, and response process gaps.
- Excellent analytical and problem-solving skills, with the ability to balance precision, scale, operational usability, and business risk.
- Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries.
- Passion for automation, continuous improvement, high-quality engineering practices, and building durable security systems that scale.
Technical Competency Profile
- Writing and tuning SIEM detections
- Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches
- SOAR playbook design and automation guardrails
- Detection validation, regression testing, tuning, and release readiness
- MITRE ATT&CK mapping and coverage measurement
- Threat-informed detection engineering
- Identity attack detection, including Entra ID, MFA abuse, token theft, OAuth abuse, suspicious consent grants, and privileged role changes
- Endpoint detection and response workflows
- Phishing, malware, suspicious email, and account compromise use cases
- Cloud security detections and CNAPP telemetry
- Network, DNS, proxy, firewall, VPN, and GlobalProtect telemetry
- OT/ICS monitoring considerations in manufacturing environments
- Privileged access monitoring and CyberArk-style PAM telemetry
- Threat intelligence enrichment and operationalization
- Case management, ITSM integration, and analyst workflow improvement
- Detection-as-code, Git, CI/CD, reusable templates, and content lifecycle management
The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.
This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.
The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.
The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.
Job Systems/Information Technology
Organization Cummins Inc.
Role Category Off-site Remote
Job Type Exempt - Experienced
ReqID 2434879
Relocation Package No
100% On-Site No
Cummins and E-Verify
At Cummins, we are an equal opportunity and affirmative action employer dedicated to diversity in the workplace. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law. Cummins validates the right to work using E-Verify and will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee’s Form I-9 to confirm work authorization. Visit to know your rights on workplace discrimination.
- OverviewThe Manager, IT Security, is a key leadership role within... ..., network security, threat detection, monitoring, logging, encryption... ....Designs and implements automated security monitoring, alerting... ...Degree in Information Security, Cybersecurity or related field (Preferred...Suggested
- ...Rochester Hills, MIHire Type:DirectCompensation:120-145k.Job Duties: Senior Project Manager - Medical & Pharmaceutical AutomationSterling Engineering is partnering with a leading custom automation company that is seeking a Senior Project Manager to oversee complex automation...Suggested
- ...of-the-art vehicles across the world.Job Responsibilities:The Manager of IT Controls advances Magna IT standards alignment across the... ...enterprise standards and divisional execution to strengthen cybersecurity posture and reduce operational risk. The position contributes...SuggestedFull timeWork at officeLocal area
- PositionBusiness Unit Regional IT Senior Manager, DMS Americas LocationAuburn Hills -... ...technology, assures compliance with IT and cybersecurity standards, and leads the regional IT... ...data pipelines, and plant level‑level automation.Strengthening IT/OT cybersecurity posture...SuggestedFull timeLocal areaImmediate startVisa sponsorshipWork visaFree visa
- REPORTS TO: Department Manager JOB TYPE: Full-Time DAYS/HOURS: Monday - Friday. Standard business hours LOCATION: 2831 Research Drive... ...approach to technology, leveraging cost-effective business automation solutions for our customers. Our solutions include software...SuggestedFull timeWork at officeMonday to FridayFlexible hoursNight shiftWeekend workEarly shift
- .... Because we win together.Are you ready for a better career? A better future?Job DescriptionAs a member of the Automation team, the Automation Project Manager will be responsible for Leading, Supporting, Implementing, and Managing Automation projections while driving innovation...
- ...roles and responsibilitiesForvia is building a North American Automation Center of Excellence (COE) to define and deploy next-generation... ...across our manufacturing network.As an Automation Project Manager, you will play a critical role in shaping and executing this strategy...
- ...the Best Value supplier in the industry. The Manager of the Electrical Insights Systems Integration... ...Cabling, Video Surveillance, Access Control, Intrusion Detection, Audio/Visual, Fiber Optics ERCES, DAS, and Automation & Controls. ~ Experience in multiple vertical...Full timeTemporary workFor contractorsFor subcontractorWork at officeFlexible hours
$130k
...Account Manager Automation Solutions Our client is a prominent company specializing in state-of-the-art automation solutions across multiple sectors. Part of a global conglomerate with significant market presence, our client is renowned for innovation and engineering...Work at officeRemote work- ...execution discipline, and steadfast progress across supplier-managed Value-Added Assembly (VAA) projects supporting GMNA. The position... ...engineering budget trade-offs, evaluating manual versus SMART automation opportunities, incorporating lessons learned into standards...Full timeContract workLocal areaWork from homeRelocationRelocation package
- Milton Hershey School, a cost-free pre-K through 12th grade residential school, is seeking a Youth Development Specialist in the Education, Training & E-Learning department. This role supports students’ academic, social, and emotional growth through mentoring, small-group...
$40 per hour
**Project Site Lead - Automation & Material Optimization** Insight Global is seeking a Project Site Lead to support automation implementation... ...system upgrades while minimizing production disruptions. * Manage short-term schedules and project milestones to ensure timely...Temporary workFor contractors- ...Sales Executive to drive growth in our Cybersecurity practice. You will originate new opportunities... ...through assessment, transformation, and managed services offerings. This role requires a... ...articulate EY's differentiated value in a complex threat landscape. #J-18808-Ljbffr EY
- Job DescriptionThe RoleThe Manufacturing Launch Program Manager owns the successful deployment of all IT systems required to launch... ...execution across applications, infrastructure, controls, and cybersecurity technologies.This role requires strong expertise in plant floor...Full timeFor contractorsH1bLocal areaWork from homeRelocationRelocation package
$46.92k
...development so they can reach their full potential. Responsibilities include: Providing daily supervision and mentorship Managing household routines and student schedules Administering medications and ensuring student wellness Driving students to...Full timeWork from homeRelocationRelocation packageFlexible hoursWeekday work$144.9k - $302.1k
...significant impact on global cybersecurity. The opportunity The Zscaler Engineer Manager will be responsible for overseeing... ...Zscaler security trends, threats, and technologies. Skills... ...Python, PowerShell, or Bash for automation and configuration management....Full timeSummer holidayFlexible hours- ...company focused on uncrewed systems, satellite communications, cybersecurity, microwave electronics, missile defense, training, and combat... ...effective solutions. GENERAL JOB SUMMARY The Human Resources Manager leads and administers the siteis Human Resources function while...Temporary workInternshipWork at office
$190k - $210k
General Cognizant’s Intuitive Operations & Automation (IOA) business unit is one of Cognizant’s highest growth businesses. To accelerate... ...Industry. Demonstrated ability of building sales and account management teams and supporting clients at all levels. Deep...Temporary work- IT Managed Services Account Manager Location: Hybrid Employment Type: Full-Time Join Our Growing Team! Are you passionate... ...planning sessions. * Identify opportunities for managed services, cybersecurity, cloud, and professional services growth. * Collaborate with...Full timeFlexible hours
$50 per hour
..., cutting, brazing, machining, process automation, and field repair. The Company leverages... ... Primary Function The General Manager serves as the senior site leader with full... ...with all applicable aerospace, cybersecurity, safety, environmental, and regulatory...Contract workTemporary workFor contractorsLocal area- ...Information System Security Manager Warren - DEVCOM - GVSC - Warren, MI 48397 Overview Level: Experienced Position Type: Full... ...The contractor shall be the lead for maintaining the overall cybersecurity program of the systems and platforms for which they are...Full timeFor contractorsLocal areaWorldwide
- ...Construction Technology ManagerThe Construction Technology Manager leads the strategy, implementation, and optimization of construction... ...in Microsoft Office (Excel, Project)Familiarity with APIs and automation (e.g., Python) is a plusStrong leadership, communication, and...Contract workWork at office
- ...DescriptionThe RoleGeneral Motors is seeking a Software Engineering Manager to lead delivery, modernization, and operational excellence... ....Partner with product, business, architecture, platform, cybersecurity, operations, and peer engineering teams to deliver reliable, scalable...Full timeLocal areaRemote workWork from homeRelocation packageFlexible hours
- ...equipment across customer facilities Drive aftermarket sales of automation equipment, spare parts, service contracts, and system upgrades... .... Collaborate closely with engineering, service, and project management teams to scope technical requirements and deliver timely...For contractorsWork at office
- Technical Recruiter - Engineering @ Zobility | Managing High-Volume Engineering Recruitment We are seeking a highly-skilled and experienced... ...Manager to oversee the complete lifecycle of our Powertrain Automation systems , specifically focusing on Automated machining lines...Full timeContract workNight shiftWeekend work
- ...quality ratings. Conduct training across the organization and manage special process personnel testing and certifications. Oversee both... ...with advanced technologies such as ATOS 5 Scan Box and automated quality systems. Strong problem-solving skills with a data-driven...Full timeRemote work
- ...enterprise-wide standards framework for the Advanced Tooling and Automation department, including equipment standards, design... ...Drive standardization of controls documentation, change management, and cybersecurity practices across all automated systems. 6. Supplier & Vendor...Work experience placement
- Ironclad Powered by Mersino is seeking a Senior Accounts Receivable Manager to oversee invoicing, cash application, and collections across MI and TX. You will lead the AR team, interpret complex contracts, and drive process improvements to optimize cash flow and minimize...
$73.88k - $100k
...Executive is accountable for: Responsibilities Focus within the Automation engineering vertical As an experienced seller in your... ...executives/decision-makers, engineering directors, engineering managers, etc. Influence and partner with a team of specialized engineering...Contract workTemporary work- ...to help our clients transform their businesses and effectively manage operations in the areas of: Sales Performance; Repair Optimization... ...CRM forecasting and pipeline governance.• Monitor competitive threats and build strategies.QualificationsCandidate Profile• 15+ years...Contract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Threat Detection & Automation Manager. Be the first to apply!
- IT cyber security Troy, MI
- cyber security Troy, MI
- cybersecurity specialist Troy, MI
- cybersecurity certificate Troy, MI
- cybersecurity administrator Troy, MI
- senior cybersecurity engineer Troy, MI
- cybersecurity software engineer Troy, MI
- cybersecurity Troy, MI
- building automation manager Troy, MI
- automation project manager Troy, MI



