Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Threat Detection & Automation Manager

Cummins Inc.

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.

This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.

The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.

The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

The Impact You Will Make

In this role, you will help modernize and mature the organization’s threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.

You will directly influence:

  • Detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments
  • Alert fidelity and false-positive reduction
  • Investigation speed and analyst consistency
  • SOAR automation maturity and response scalability
  • Detection lifecycle governance, testing, validation, and documentation
  • SecOps modernization across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms
  • Reduced manual triage and improved operational repeatability
  • Stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams

Key Responsibilities

Leadership and Team Management

  • Manage, mentor, and develop a team of detection engineering and automation professionals.
  • Build a culture of engineering rigor, operational discipline, innovation, accountability, quality, and continuous improvement.
  • Operate as a hands-on manager by personally owning, reviewing, and contributing to key detections, automation workflows, technical initiatives, and program improvements.
  • Define and execute the threat detection and automation strategy aligned to business risk, operational needs, threat landscape, compliance requirements, and organizational priorities.
  • Establish the team’s operating rhythm, including intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement.
  • Coach team members on detection logic, investigation quality, automation design, threat modeling, analyst usability, operational impact, and stakeholder communication.
  • Partner closely with SOC Monitoring, Incident Response, Threat Intelligence, SIEM Engineering, Cloud, Identity, Network, OT, IT Infrastructure, Vulnerability Management, GRC, and business stakeholders.

Threat Detection Engineering

  • Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms.
  • Personally own a portfolio of high-impact detections focused on complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats.
  • Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, kill-chain models, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk.
  • Conduct detection gap analysis and threat modeling to prioritize improvements based on exposure, telemetry readiness, attacker behavior, business impact, and operational value.
  • Build and maintain detection validation practices, including test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback loops.
  • Ensure detections are operationally useful by including clear context, enrichment, severity guidance, response steps, escalation paths, and containment recommendations.
  • Measure and expand detection coverage across ATT&CK tactics and techniques, critical assets, identities, cloud platforms, OT environments, and enterprise telemetry sources.
  • Stay current with emerging threats, adversary tradecraft, tools, vulnerabilities, and detection methods.

SIEM, SOAR, and Security Automation

  • Lead the design, development, and continuous improvement of SIEM and SOAR-driven detection and response workflows.
  • Build and optimize SIEM content, including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment.
  • Develop and mature SOAR playbooks that automate enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support.
  • Identify repetitive, high-volume, or high-value SOC activities that can be safely and effectively automated.
  • Define automation standards covering human-in-the-loop approvals, reversible actions, audit trails, exception handling, failure modes, escalation criteria, and rollback considerations.
  • Partner with SOC and Incident Response teams to ensure automation improves investigation speed, consistency, quality, and response outcomes without creating unnecessary operational risk.
  • Measure automation effectiveness using metrics such as analyst time saved, touch reduction, playbook success rate, case consistency, response acceleration, and manual effort reduction.
  • Drive integrations across SIEM, SOAR, EDR, email security, identity platforms, threat intelligence, ITSM, cloud security, network security, PAM, DLP/CASB, and OT monitoring platforms.

Detection Lifecycle, Governance, and Program Management

  • Build and mature the detection and automation lifecycle from intake through retirement.
  • Own standards for request intake, prioritization, design, build, peer review, testing, deployment, tuning, production monitoring, and continuous improvement.
  • Create and maintain use case standards, templates, documentation requirements, acceptance criteria, release gates, change history, and ownership models.
  • Manage the detection and automation roadmap based on threat intelligence, incident trends, MITRE coverage gaps, telemetry gaps, crown jewel risks, regulatory requirements, and business priorities.
  • Develop and maintain program metrics that demonstrate detection coverage, alert fidelity, false-positive trends, automation value, telemetry readiness, backlog health, delivery throughput, and investigation quality.
  • Partner with stakeholders to identify and resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and unclear ownership across the detection and response ecosystem.
  • Ensure detection and automation practices support internal policies, audit expectations, and applicable regulatory requirements.
  • Maintain audit-ready documentation and evidence, including rationale, test results, tuning notes, change history, ownership, approvals, validation results, and monitoring insights.
  • Communicate detection strategy, risk coverage, maturity, roadmap, and outcomes clearly to both technical and non-technical stakeholders, including executive leadership.

Preferred Qualifications

  • Master’s degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related discipline.
  • 10+ years of cybersecurity experience working in SOC and in creating SEIM correlations/detections and automating incident information enrichment tasks
  • Experience in building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases.
  • Experience building SOAR playbooks and automation workflows for phishing, malware, suspicious sign-ins, account compromise, endpoint containment, cloud alerts, privileged access activity, and threat intelligence enrichment.
  • Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns.
  • Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks.
  • Experience designing detections for identity-based attacks such as token theft, MFA bypass, device code phishing, OAuth abuse, suspicious consent grants, impossible travel, privileged role changes, and anomalous sign-ins.
  • Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases.
  • Experience working in large, complex enterprise or manufacturing environments with distributed stakeholders, shared ownership models, and operational constraints.
  • Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams.
  • Ability to distinguish between detection gaps, telemetry gaps, control gaps, ownership gaps, and response process gaps.
  • Excellent analytical and problem-solving skills, with the ability to balance precision, scale, operational usability, and business risk.
  • Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries.
  • Passion for automation, continuous improvement, high-quality engineering practices, and building durable security systems that scale.

Technical Competency Profile

  • Writing and tuning SIEM detections
  • Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches
  • SOAR playbook design and automation guardrails
  • Detection validation, regression testing, tuning, and release readiness
  • MITRE ATT&CK mapping and coverage measurement
  • Threat-informed detection engineering
  • Identity attack detection, including Entra ID, MFA abuse, token theft, OAuth abuse, suspicious consent grants, and privileged role changes
  • Endpoint detection and response workflows
  • Phishing, malware, suspicious email, and account compromise use cases
  • Cloud security detections and CNAPP telemetry
  • Network, DNS, proxy, firewall, VPN, and GlobalProtect telemetry
  • OT/ICS monitoring considerations in manufacturing environments
  • Privileged access monitoring and CyberArk-style PAM telemetry
  • Threat intelligence enrichment and operationalization
  • Case management, ITSM integration, and analyst workflow improvement
  • Detection-as-code, Git, CI/CD, reusable templates, and content lifecycle management

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.

This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.

The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.

The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

Job Systems/Information Technology

Organization Cummins Inc.

Role Category Off-site Remote

Job Type Exempt - Experienced

ReqID 2434879

Relocation Package No

100% On-Site No

Cummins and E-Verify

At Cummins, we are an equal opportunity and affirmative action employer dedicated to diversity in the workplace. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law. Cummins validates the right to work using E-Verify and will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee’s Form I-9 to confirm work authorization. Visit to know your rights on workplace discrimination.

Vacancy posted 15 hours ago
Similar jobs that could be interesting for youBased on the Cybersecurity Threat Detection & Automation Manager in Troy, MI vacancy
  •  ...Midmarket Account Executive: Detection & Response Antigen...  ...specializing in comprehensive cybersecurity solutions. By leveraging top...  ...products tailored to specific threats and systems, we help organizations...  .... As a Microsoft Top 150 Managed Partner and exclusive... 
    Suggested
    Work experience placement
    Remote work

    Antigen Security

    Royal Oak, MI
    3 days ago
  • OverviewThe Manager, IT Security, is a key leadership role within...  ..., network security, threat detection, monitoring, logging, encryption...  ....Designs and implements automated security monitoring, alerting...  ...Degree in Information Security, Cybersecurity or related field (Preferred... 
    Suggested

    Sun Communities

    Southfield, MI
    5 days ago
  •  ...of-the-art vehicles across the world.Job Responsibilities:The Manager of IT Controls advances Magna IT standards alignment across the...  ...enterprise standards and divisional execution to strengthen cybersecurity posture and reduce operational risk. The position contributes... 
    Suggested
    Full time
    Work at office
    Local area

    Magna International

    Troy, MI
    2 days ago
  •  ...Rochester Hills, MIHire Type:DirectCompensation:120-145k.Job Duties: Senior Project Manager - Medical & Pharmaceutical AutomationSterling Engineering is partnering with a leading custom automation company that is seeking a Senior Project Manager to oversee complex automation... 
    Suggested

    Sterling Engineering

    Rochester Hills, MI
    3 days ago
  •  ...everywhere. Contract Details : Job Title : Industrial Manager Batteries Type of contract : Long-term At-will Location...  ...and develop direct reports. Plan to organically grow automation, welding and EOL test expertise related to battery pack line... 
    Suggested
    Permanent employment
    Contract work
    Local area

    OP Mobility

    Troy, MI
    a month ago
  •  ...Job Description Job Description Title : Senior Project Manager Location : Rochester Hills, MI Hire Type :Direct Compensation...  ...: Senior Project Manager – Medical & Pharmaceutical Automation Sterling Engineering is partnering with a leading custom... 

    Sterling Engineering Inc.

    Rochester Hills, MI
    21 days ago
  • $2,500 per month

     ...Job Description Job Description Overview: The Project Manager Lead oversees complex automation projects from initiation through delivery, ensuring alignment with customer expectations, technical requirements, and organizational objectives. This role drives cross... 
    Relocation package
    Flexible hours

    Automated Industrial Robotics Rochester Hills

    Rochester, MI
    29 days ago
  • PositionBusiness Unit Regional IT Senior Manager, DMS Americas LocationAuburn Hills -...  ...technology, assures compliance with IT and cybersecurity standards, and leads the regional IT...  ...data pipelines, and plant level‑level automation.Strengthening IT/OT cybersecurity posture... 
    Full time
    Local area
    Immediate start
    Visa sponsorship
    Work visa
    Free visa

    BorgWarner

    Auburn Hills, MI
    1 day ago
  • REPORTS TO: Department Manager JOB TYPE: Full-Time DAYS/HOURS: Monday - Friday. Standard business hours LOCATION: 2831 Research Drive...  ...approach to technology, leveraging cost-effective business automation solutions for our customers. Our solutions include software... 
    Full time
    Work at office
    Monday to Friday
    Flexible hours
    Night shift
    Weekend work
    Early shift

    SolvIT, Inc.

    Rochester, MI
    6 days ago
  •  ...roles and responsibilitiesForvia is building a North American Automation Center of Excellence (COE) to define and deploy next-generation...  ...across our manufacturing network.As an Automation Project Manager, you will play a critical role in shaping and executing this strategy... 

    FORVIA Faurecia

    Auburn Hills, MI
    3 days ago
  •  .... Because we win together.Are you ready for a better career? A better future?Job DescriptionAs a member of the Automation team, the Automation Project Manager will be responsible for Leading, Supporting, Implementing, and Managing Automation projections while driving innovation... 

    Lear

    Southfield, MI
    19 hours ago
  • $130k

     ...Account Manager Automation Solutions Our client is a prominent company specializing in state-of-the-art automation solutions across multiple sectors. Part of a global conglomerate with significant market presence, our client is renowned for innovation and engineering... 
    Work at office
    Remote work

    Thornley Corporate Solutions

    Troy, MI
    2 days ago
  •  ...execution discipline, and steadfast progress across supplier-managed Value-Added Assembly (VAA) projects supporting GMNA. The position...  ...engineering budget trade-offs, evaluating manual versus SMART automation opportunities, incorporating lessons learned into standards... 
    Full time
    Contract work
    Local area
    Work from home
    Relocation
    Relocation package

    General Motors

    Warren, MI
    4 days ago
  •  ...Sales Executive to drive growth in our Cybersecurity practice. You will originate new opportunities...  ...through assessment, transformation, and managed services offerings. This role requires a...  ...articulate EY's differentiated value in a complex threat landscape. #J-18808-Ljbffr EY

    EY

    Southfield, MI
    3 days ago
  • Job DescriptionThe RoleThe Manufacturing Launch Program Manager owns the successful deployment of all IT systems required to launch...  ...execution across applications, infrastructure, controls, and cybersecurity technologies.This role requires strong expertise in plant floor... 
    Full time
    For contractors
    H1b
    Local area
    Work from home
    Relocation
    Relocation package

    General Motors

    Warren, MI
    2 days ago
  •  ...company focused on uncrewed systems, satellite communications, cybersecurity, microwave electronics, missile defense, training, and combat...  ...effective solutions. GENERAL JOB SUMMARY The Human Resources Manager leads and administers the siteis Human Resources function while... 
    Temporary work
    Internship
    Work at office

    Kratos Unmanned Systems

    Auburn Hills, MI
    5 days ago
  • $190k - $210k

    General Cognizant’s Intuitive Operations & Automation (IOA) business unit is one of Cognizant’s highest growth businesses. To accelerate...  ...Industry. Demonstrated ability of building sales and account management teams and supporting clients at all levels. Deep... 
    Temporary work

    Cognizant

    Troy, MI
    5 days ago
  • $144.9k - $302.1k

     ...significant impact on global cybersecurity. The opportunity The Zscaler Engineer Manager will be responsible for overseeing...  ...Zscaler security trends, threats, and technologies. Skills...  ...Python, PowerShell, or Bash for automation and configuration management.... 
    Full time
    Summer holiday
    Flexible hours

    EY

    Southfield, MI
    5 hours ago
  • IT Managed Services Account Manager Location: Hybrid Employment Type: Full-Time Join Our Growing Team! Are you passionate...  ...planning sessions. * Identify opportunities for managed services, cybersecurity, cloud, and professional services growth. * Collaborate with... 
    Full time
    Flexible hours

    Hyperion Managed Services

    Troy, MI
    a month ago
  •  ...of position:We are looking for an Information System Security Manager to work in Warren MI Area. The contractor shall serve as an Information...  ...The contractor shall be the lead for maintaining the overall cybersecurity program of the systems and platforms for which they are... 
    Full time
    For contractors
    Local area
    Worldwide

    Feditc LLC

    Warren, MI
    3 days ago
  •  ...Job Description Job Description Description: Job Title: Project Manager I, Factory Automation (ONISTE M-F) About Us Solving your motion control challenges with ingenuity. Evolution Motion Solutions is a leading engineering partner, systems integrator,... 
    Work at office
    Flexible hours

    Evolution Motion Solutions

    Auburn Hills, MI
    a month ago
  • $50 per hour

     ..., cutting, brazing, machining, process automation, and field repair. The Company leverages...  ...​ Primary Function The General Manager serves as the senior site leader with full...  ...with all applicable aerospace, cybersecurity, safety, environmental, and regulatory... 
    Contract work
    Temporary work
    For contractors
    Local area

    Lincoln Electric

    Macomb, MI
    a month ago
  •  ...DescriptionThe RoleGeneral Motors is seeking a Software Engineering Manager to lead delivery, modernization, and operational excellence...  ....Partner with product, business, architecture, platform, cybersecurity, operations, and peer engineering teams to deliver reliable, scalable... 
    Full time
    Local area
    Remote work
    Work from home
    Relocation package
    Flexible hours

    General Motors

    Warren, MI
    3 days ago
  •  ...equipment across customer facilities Drive aftermarket sales of automation equipment, spare parts, service contracts, and system upgrades...  .... Collaborate closely with engineering, service, and project management teams to scope technical requirements and deliver timely... 
    For contractors
    Work at office

    Dürr AG

    Southfield, MI
    6 days ago
  • Technical Recruiter - Engineering @ Zobility | Managing High-Volume Engineering Recruitment We are seeking a highly-skilled and experienced...  ...Manager to oversee the complete lifecycle of our Powertrain Automation systems , specifically focusing on Automated machining lines... 
    Full time
    Contract work
    Night shift
    Weekend work

    Zobility

    Auburn Hills, MI
    2 days ago
  •  ...quality ratings. Conduct training across the organization and manage special process personnel testing and certifications. Oversee both...  ...with advanced technologies such as ATOS 5 Scan Box and automated quality systems. Strong problem-solving skills with a data-driven... 
    Full time
    Remote work

    StaffBright

    Sterling Heights, MI
    2 days ago
  •  ...Director of Advanced Tooling, Advanced Manufacturing, and Automation leads the enterprise-wide strategy, standards, and...  ...Drive standardization of controls documentation, change management, and cybersecurity practices across all automated systems. Partner with suppliers... 
    Work experience placement

    CSP

    Auburn Hills, MI
    6 days ago
  • $73.88k - $100k

     ...Executive is accountable for: Responsibilities Focus within the Automation engineering vertical As an experienced seller in your...  ...executives/decision-makers, engineering directors, engineering managers, etc. Influence and partner with a team of specialized engineering... 
    Contract work
    Temporary work

    Kelly Services

    Troy, MI
    3 days ago
  •  ...Description Description: Job Title: Project Coordinator, Factory Automation (Onsite) About Us For over 80 years, we have pioneered...  ...with disabilities to perform the primary duties. Maintain, manage and prioritize “Open RFQ List”. Organize all RFQ supplied... 
    Work at office
    Flexible hours

    Evolution Motion Solutions

    Auburn Hills, MI
    27 days ago
  •  ...surface inspection to software-controlled robotics systems for smart factory automation.Short DescriptionContribute to the creation/leadership of the MVS strategy and drive, coach, and manage teams to achieve complete customer satisfaction and profitable growth.Key ResponsibilitiesWork... 
    Remote work
    Flexible hours
    Night shift

    Atlas Copco

    Auburn Hills, MI
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Threat Detection & Automation Manager. Be the first to apply!