Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Threat Detection & Automation Manager

Cummins Inc.

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.

This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.

The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.

The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

The Impact You Will Make

In this role, you will help modernize and mature the organization’s threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.

You will directly influence:

  • Detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments
  • Alert fidelity and false-positive reduction
  • Investigation speed and analyst consistency
  • SOAR automation maturity and response scalability
  • Detection lifecycle governance, testing, validation, and documentation
  • SecOps modernization across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms
  • Reduced manual triage and improved operational repeatability
  • Stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams

Key Responsibilities

Leadership and Team Management

  • Manage, mentor, and develop a team of detection engineering and automation professionals.
  • Build a culture of engineering rigor, operational discipline, innovation, accountability, quality, and continuous improvement.
  • Operate as a hands-on manager by personally owning, reviewing, and contributing to key detections, automation workflows, technical initiatives, and program improvements.
  • Define and execute the threat detection and automation strategy aligned to business risk, operational needs, threat landscape, compliance requirements, and organizational priorities.
  • Establish the team’s operating rhythm, including intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement.
  • Coach team members on detection logic, investigation quality, automation design, threat modeling, analyst usability, operational impact, and stakeholder communication.
  • Partner closely with SOC Monitoring, Incident Response, Threat Intelligence, SIEM Engineering, Cloud, Identity, Network, OT, IT Infrastructure, Vulnerability Management, GRC, and business stakeholders.

Threat Detection Engineering

  • Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms.
  • Personally own a portfolio of high-impact detections focused on complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats.
  • Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, kill-chain models, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk.
  • Conduct detection gap analysis and threat modeling to prioritize improvements based on exposure, telemetry readiness, attacker behavior, business impact, and operational value.
  • Build and maintain detection validation practices, including test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback loops.
  • Ensure detections are operationally useful by including clear context, enrichment, severity guidance, response steps, escalation paths, and containment recommendations.
  • Measure and expand detection coverage across ATT&CK tactics and techniques, critical assets, identities, cloud platforms, OT environments, and enterprise telemetry sources.
  • Stay current with emerging threats, adversary tradecraft, tools, vulnerabilities, and detection methods.

SIEM, SOAR, and Security Automation

  • Lead the design, development, and continuous improvement of SIEM and SOAR-driven detection and response workflows.
  • Build and optimize SIEM content, including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment.
  • Develop and mature SOAR playbooks that automate enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support.
  • Identify repetitive, high-volume, or high-value SOC activities that can be safely and effectively automated.
  • Define automation standards covering human-in-the-loop approvals, reversible actions, audit trails, exception handling, failure modes, escalation criteria, and rollback considerations.
  • Partner with SOC and Incident Response teams to ensure automation improves investigation speed, consistency, quality, and response outcomes without creating unnecessary operational risk.
  • Measure automation effectiveness using metrics such as analyst time saved, touch reduction, playbook success rate, case consistency, response acceleration, and manual effort reduction.
  • Drive integrations across SIEM, SOAR, EDR, email security, identity platforms, threat intelligence, ITSM, cloud security, network security, PAM, DLP/CASB, and OT monitoring platforms.

Detection Lifecycle, Governance, and Program Management

  • Build and mature the detection and automation lifecycle from intake through retirement.
  • Own standards for request intake, prioritization, design, build, peer review, testing, deployment, tuning, production monitoring, and continuous improvement.
  • Create and maintain use case standards, templates, documentation requirements, acceptance criteria, release gates, change history, and ownership models.
  • Manage the detection and automation roadmap based on threat intelligence, incident trends, MITRE coverage gaps, telemetry gaps, crown jewel risks, regulatory requirements, and business priorities.
  • Develop and maintain program metrics that demonstrate detection coverage, alert fidelity, false-positive trends, automation value, telemetry readiness, backlog health, delivery throughput, and investigation quality.
  • Partner with stakeholders to identify and resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and unclear ownership across the detection and response ecosystem.
  • Ensure detection and automation practices support internal policies, audit expectations, and applicable regulatory requirements.
  • Maintain audit-ready documentation and evidence, including rationale, test results, tuning notes, change history, ownership, approvals, validation results, and monitoring insights.
  • Communicate detection strategy, risk coverage, maturity, roadmap, and outcomes clearly to both technical and non-technical stakeholders, including executive leadership.

Preferred Qualifications

  • Master’s degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related discipline.
  • 10+ years of cybersecurity experience working in SOC and in creating SEIM correlations/detections and automating incident information enrichment tasks
  • Experience in building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases.
  • Experience building SOAR playbooks and automation workflows for phishing, malware, suspicious sign-ins, account compromise, endpoint containment, cloud alerts, privileged access activity, and threat intelligence enrichment.
  • Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns.
  • Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks.
  • Experience designing detections for identity-based attacks such as token theft, MFA bypass, device code phishing, OAuth abuse, suspicious consent grants, impossible travel, privileged role changes, and anomalous sign-ins.
  • Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases.
  • Experience working in large, complex enterprise or manufacturing environments with distributed stakeholders, shared ownership models, and operational constraints.
  • Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams.
  • Ability to distinguish between detection gaps, telemetry gaps, control gaps, ownership gaps, and response process gaps.
  • Excellent analytical and problem-solving skills, with the ability to balance precision, scale, operational usability, and business risk.
  • Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries.
  • Passion for automation, continuous improvement, high-quality engineering practices, and building durable security systems that scale.

Technical Competency Profile

  • Writing and tuning SIEM detections
  • Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches
  • SOAR playbook design and automation guardrails
  • Detection validation, regression testing, tuning, and release readiness
  • MITRE ATT&CK mapping and coverage measurement
  • Threat-informed detection engineering
  • Identity attack detection, including Entra ID, MFA abuse, token theft, OAuth abuse, suspicious consent grants, and privileged role changes
  • Endpoint detection and response workflows
  • Phishing, malware, suspicious email, and account compromise use cases
  • Cloud security detections and CNAPP telemetry
  • Network, DNS, proxy, firewall, VPN, and GlobalProtect telemetry
  • OT/ICS monitoring considerations in manufacturing environments
  • Privileged access monitoring and CyberArk-style PAM telemetry
  • Threat intelligence enrichment and operationalization
  • Case management, ITSM integration, and analyst workflow improvement
  • Detection-as-code, Git, CI/CD, reusable templates, and content lifecycle management

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.

This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.

The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.

The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

Job Systems/Information Technology

Organization Cummins Inc.

Role Category Off-site Remote

Job Type Exempt - Experienced

ReqID 2434879

Relocation Package No

100% On-Site No

Cummins and E-Verify

At Cummins, we are an equal opportunity and affirmative action employer dedicated to diversity in the workplace. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law. Cummins validates the right to work using E-Verify and will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee’s Form I-9 to confirm work authorization. Visit to know your rights on workplace discrimination.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Threat Detection & Automation Manager in Troy, MI vacancy
  • OverviewThe Manager, IT Security, is a key leadership role within...  ..., network security, threat detection, monitoring, logging, encryption...  ....Designs and implements automated security monitoring, alerting...  ...Degree in Information Security, Cybersecurity or related field (Preferred... 
    Suggested

    Sun Communities

    Southfield, MI
    1 day ago
  •  ...Rochester Hills, MIHire Type:DirectCompensation:120-145k.Job Duties: Senior Project Manager - Medical & Pharmaceutical AutomationSterling Engineering is partnering with a leading custom automation company that is seeking a Senior Project Manager to oversee complex automation... 
    Suggested

    Sterling Engineering

    Rochester Hills, MI
    4 days ago
  •  ...of-the-art vehicles across the world.Job Responsibilities:The Manager of IT Controls advances Magna IT standards alignment across the...  ...enterprise standards and divisional execution to strengthen cybersecurity posture and reduce operational risk. The position contributes... 
    Suggested
    Full time
    Work at office
    Local area

    Magna International

    Troy, MI
    3 days ago
  • PositionBusiness Unit Regional IT Senior Manager, DMS Americas LocationAuburn Hills -...  ...technology, assures compliance with IT and cybersecurity standards, and leads the regional IT...  ...data pipelines, and plant level‑level automation.Strengthening IT/OT cybersecurity posture... 
    Suggested
    Full time
    Local area
    Immediate start
    Visa sponsorship
    Work visa
    Free visa

    BorgWarner

    Auburn Hills, MI
    2 days ago
  • REPORTS TO: Department Manager JOB TYPE: Full-Time DAYS/HOURS: Monday - Friday. Standard business hours LOCATION: 2831 Research Drive...  ...approach to technology, leveraging cost-effective business automation solutions for our customers. Our solutions include software... 
    Suggested
    Full time
    Work at office
    Monday to Friday
    Flexible hours
    Night shift
    Weekend work
    Early shift

    SolvIT, Inc.

    Rochester, MI
    2 days ago
  •  .... Because we win together.Are you ready for a better career? A better future?Job DescriptionAs a member of the Automation team, the Automation Project Manager will be responsible for Leading, Supporting, Implementing, and Managing Automation projections while driving innovation... 

    Lear

    Southfield, MI
    2 days ago
  •  ...roles and responsibilitiesForvia is building a North American Automation Center of Excellence (COE) to define and deploy next-generation...  ...across our manufacturing network.As an Automation Project Manager, you will play a critical role in shaping and executing this strategy... 

    FORVIA Faurecia

    Auburn Hills, MI
    4 days ago
  •  ...the Best Value supplier in the industry. The Manager of the Electrical Insights Systems Integration...  ...Cabling, Video Surveillance, Access Control, Intrusion Detection, Audio/Visual, Fiber Optics ERCES, DAS, and Automation & Controls. ~ Experience in multiple vertical... 
    Full time
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Flexible hours

    Tsubaki Holdings

    Clawson, MI
    4 days ago
  • $130k

     ...Account Manager Automation Solutions Our client is a prominent company specializing in state-of-the-art automation solutions across multiple sectors. Part of a global conglomerate with significant market presence, our client is renowned for innovation and engineering... 
    Work at office
    Remote work

    Thornley Corporate Solutions

    Troy, MI
    3 days ago
  •  ...execution discipline, and steadfast progress across supplier-managed Value-Added Assembly (VAA) projects supporting GMNA. The position...  ...engineering budget trade-offs, evaluating manual versus SMART automation opportunities, incorporating lessons learned into standards... 
    Full time
    Contract work
    Local area
    Work from home
    Relocation
    Relocation package

    General Motors

    Warren, MI
    1 day ago
  • Milton Hershey School, a cost-free pre-K through 12th grade residential school, is seeking a Youth Development Specialist in the Education, Training & E-Learning department. This role supports students’ academic, social, and emotional growth through mentoring, small-group...

    Milton Hershey School

    Troy, MI
    2 days ago
  • $40 per hour

    **Project Site Lead - Automation & Material Optimization** Insight Global is seeking a Project Site Lead to support automation implementation...  ...system upgrades while minimizing production disruptions. * Manage short-term schedules and project milestones to ensure timely... 
    Temporary work
    For contractors

    Insight Global

    Warren, MI
    3 days ago
  •  ...Sales Executive to drive growth in our Cybersecurity practice. You will originate new opportunities...  ...through assessment, transformation, and managed services offerings. This role requires a...  ...articulate EY's differentiated value in a complex threat landscape. #J-18808-Ljbffr EY

    EY

    Southfield, MI
    4 days ago
  • Job DescriptionThe RoleThe Manufacturing Launch Program Manager owns the successful deployment of all IT systems required to launch...  ...execution across applications, infrastructure, controls, and cybersecurity technologies.This role requires strong expertise in plant floor... 
    Full time
    For contractors
    H1b
    Local area
    Work from home
    Relocation
    Relocation package

    General Motors

    Warren, MI
    3 days ago
  • $46.92k

     ...development so they can reach their full potential. Responsibilities include: Providing daily supervision and mentorship Managing household routines and student schedules Administering medications and ensuring student wellness Driving students to... 
    Full time
    Work from home
    Relocation
    Relocation package
    Flexible hours
    Weekday work

    Milton Hershey School

    Troy, MI
    4 days ago
  • $144.9k - $302.1k

     ...significant impact on global cybersecurity. The opportunity  The Zscaler Engineer Manager will be responsible for overseeing...  ...Zscaler security trends, threats, and technologies. Skills...  ...Python, PowerShell, or Bash for automation and configuration management.... 
    Full time
    Summer holiday
    Flexible hours

    EY

    Southfield, MI
    2 days ago
  •  ...company focused on uncrewed systems, satellite communications, cybersecurity, microwave electronics, missile defense, training, and combat...  ...effective solutions. GENERAL JOB SUMMARY The Human Resources Manager leads and administers the siteis Human Resources function while... 
    Temporary work
    Internship
    Work at office

    Kratos Unmanned Systems

    Auburn Hills, MI
    1 day ago
  • $190k - $210k

    General Cognizant’s Intuitive Operations & Automation (IOA) business unit is one of Cognizant’s highest growth businesses. To accelerate...  ...Industry. Demonstrated ability of building sales and account management teams and supporting clients at all levels. Deep... 
    Temporary work

    Cognizant

    Troy, MI
    1 day ago
  • IT Managed Services Account Manager Location: Hybrid Employment Type: Full-Time Join Our Growing Team! Are you passionate...  ...planning sessions. * Identify opportunities for managed services, cybersecurity, cloud, and professional services growth. * Collaborate with... 
    Full time
    Flexible hours

    Hyperion Managed Services

    Troy, MI
    a month ago
  • $50 per hour

     ..., cutting, brazing, machining, process automation, and field repair. The Company leverages...  ...​ Primary Function The General Manager serves as the senior site leader with full...  ...with all applicable aerospace, cybersecurity, safety, environmental, and regulatory... 
    Contract work
    Temporary work
    For contractors
    Local area

    Lincoln Electric

    Macomb, MI
    a month ago
  •  ...Information System Security Manager Warren - DEVCOM - GVSC - Warren, MI 48397 Overview Level: Experienced Position Type: Full...  ...The contractor shall be the lead for maintaining the overall cybersecurity program of the systems and platforms for which they are... 
    Full time
    For contractors
    Local area
    Worldwide

    Feditc LLC

    Warren, MI
    4 days ago
  •  ...Construction Technology ManagerThe Construction Technology Manager leads the strategy, implementation, and optimization of construction...  ...in Microsoft Office (Excel, Project)Familiarity with APIs and automation (e.g., Python) is a plusStrong leadership, communication, and... 
    Contract work
    Work at office

    Commercial Contracting

    Auburn Hills, MI
    4 days ago
  •  ...DescriptionThe RoleGeneral Motors is seeking a Software Engineering Manager to lead delivery, modernization, and operational excellence...  ....Partner with product, business, architecture, platform, cybersecurity, operations, and peer engineering teams to deliver reliable, scalable... 
    Full time
    Local area
    Remote work
    Work from home
    Relocation package
    Flexible hours

    General Motors

    Warren, MI
    4 days ago
  •  ...equipment across customer facilities Drive aftermarket sales of automation equipment, spare parts, service contracts, and system upgrades...  .... Collaborate closely with engineering, service, and project management teams to scope technical requirements and deliver timely... 
    For contractors
    Work at office

    Dürr AG

    Southfield, MI
    2 days ago
  • Technical Recruiter - Engineering @ Zobility | Managing High-Volume Engineering Recruitment We are seeking a highly-skilled and experienced...  ...Manager to oversee the complete lifecycle of our Powertrain Automation systems , specifically focusing on Automated machining lines... 
    Full time
    Contract work
    Night shift
    Weekend work

    Zobility

    Auburn Hills, MI
    3 days ago
  •  ...quality ratings. Conduct training across the organization and manage special process personnel testing and certifications. Oversee both...  ...with advanced technologies such as ATOS 5 Scan Box and automated quality systems. Strong problem-solving skills with a data-driven... 
    Full time
    Remote work

    StaffBright

    Sterling Heights, MI
    3 days ago
  •  ...enterprise-wide standards framework for the Advanced Tooling and Automation department, including equipment standards, design...  ...Drive standardization of controls documentation, change management, and cybersecurity practices across all automated systems. 6. Supplier & Vendor... 
    Work experience placement

    CSP Innovations, Inc.

    Auburn Hills, MI
    2 days ago
  • Ironclad Powered by Mersino is seeking a Senior Accounts Receivable Manager to oversee invoicing, cash application, and collections across MI and TX. You will lead the AR team, interpret complex contracts, and drive process improvements to optimize cash flow and minimize... 

    Ironclad Powered by Mersino

    Auburn Hills, MI
    2 days ago
  • $73.88k - $100k

     ...Executive is accountable for: Responsibilities Focus within the Automation engineering vertical As an experienced seller in your...  ...executives/decision-makers, engineering directors, engineering managers, etc. Influence and partner with a team of specialized engineering... 
    Contract work
    Temporary work

    Kelly Services

    Troy, MI
    4 days ago
  •  ...to help our clients transform their businesses and effectively manage operations in the areas of: Sales Performance; Repair Optimization...  ...CRM forecasting and pipeline governance.• Monitor competitive threats and build strategies.QualificationsCandidate Profile• 15+ years... 
    Contract work
    Work at office

    MSX International

    Troy, MI
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Threat Detection & Automation Manager. Be the first to apply!