Cybersecurity Threat Detection & Automation Manager
Cummins Inc.
The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.
This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.
The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.
The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.
The Impact You Will Make
In this role, you will help modernize and mature the organization’s threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.
You will directly influence:
- Detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments
- Alert fidelity and false-positive reduction
- Investigation speed and analyst consistency
- SOAR automation maturity and response scalability
- Detection lifecycle governance, testing, validation, and documentation
- SecOps modernization across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms
- Reduced manual triage and improved operational repeatability
- Stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams
Key Responsibilities
Leadership and Team Management
- Manage, mentor, and develop a team of detection engineering and automation professionals.
- Build a culture of engineering rigor, operational discipline, innovation, accountability, quality, and continuous improvement.
- Operate as a hands-on manager by personally owning, reviewing, and contributing to key detections, automation workflows, technical initiatives, and program improvements.
- Define and execute the threat detection and automation strategy aligned to business risk, operational needs, threat landscape, compliance requirements, and organizational priorities.
- Establish the team’s operating rhythm, including intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement.
- Coach team members on detection logic, investigation quality, automation design, threat modeling, analyst usability, operational impact, and stakeholder communication.
- Partner closely with SOC Monitoring, Incident Response, Threat Intelligence, SIEM Engineering, Cloud, Identity, Network, OT, IT Infrastructure, Vulnerability Management, GRC, and business stakeholders.
Threat Detection Engineering
- Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms.
- Personally own a portfolio of high-impact detections focused on complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats.
- Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, kill-chain models, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk.
- Conduct detection gap analysis and threat modeling to prioritize improvements based on exposure, telemetry readiness, attacker behavior, business impact, and operational value.
- Build and maintain detection validation practices, including test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback loops.
- Ensure detections are operationally useful by including clear context, enrichment, severity guidance, response steps, escalation paths, and containment recommendations.
- Measure and expand detection coverage across ATT&CK tactics and techniques, critical assets, identities, cloud platforms, OT environments, and enterprise telemetry sources.
- Stay current with emerging threats, adversary tradecraft, tools, vulnerabilities, and detection methods.
SIEM, SOAR, and Security Automation
- Lead the design, development, and continuous improvement of SIEM and SOAR-driven detection and response workflows.
- Build and optimize SIEM content, including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment.
- Develop and mature SOAR playbooks that automate enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support.
- Identify repetitive, high-volume, or high-value SOC activities that can be safely and effectively automated.
- Define automation standards covering human-in-the-loop approvals, reversible actions, audit trails, exception handling, failure modes, escalation criteria, and rollback considerations.
- Partner with SOC and Incident Response teams to ensure automation improves investigation speed, consistency, quality, and response outcomes without creating unnecessary operational risk.
- Measure automation effectiveness using metrics such as analyst time saved, touch reduction, playbook success rate, case consistency, response acceleration, and manual effort reduction.
- Drive integrations across SIEM, SOAR, EDR, email security, identity platforms, threat intelligence, ITSM, cloud security, network security, PAM, DLP/CASB, and OT monitoring platforms.
Detection Lifecycle, Governance, and Program Management
- Build and mature the detection and automation lifecycle from intake through retirement.
- Own standards for request intake, prioritization, design, build, peer review, testing, deployment, tuning, production monitoring, and continuous improvement.
- Create and maintain use case standards, templates, documentation requirements, acceptance criteria, release gates, change history, and ownership models.
- Manage the detection and automation roadmap based on threat intelligence, incident trends, MITRE coverage gaps, telemetry gaps, crown jewel risks, regulatory requirements, and business priorities.
- Develop and maintain program metrics that demonstrate detection coverage, alert fidelity, false-positive trends, automation value, telemetry readiness, backlog health, delivery throughput, and investigation quality.
- Partner with stakeholders to identify and resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and unclear ownership across the detection and response ecosystem.
- Ensure detection and automation practices support internal policies, audit expectations, and applicable regulatory requirements.
- Maintain audit-ready documentation and evidence, including rationale, test results, tuning notes, change history, ownership, approvals, validation results, and monitoring insights.
- Communicate detection strategy, risk coverage, maturity, roadmap, and outcomes clearly to both technical and non-technical stakeholders, including executive leadership.
Preferred Qualifications
- Master’s degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related discipline.
- 10+ years of cybersecurity experience working in SOC and in creating SEIM correlations/detections and automating incident information enrichment tasks
- Experience in building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases.
- Experience building SOAR playbooks and automation workflows for phishing, malware, suspicious sign-ins, account compromise, endpoint containment, cloud alerts, privileged access activity, and threat intelligence enrichment.
- Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns.
- Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks.
- Experience designing detections for identity-based attacks such as token theft, MFA bypass, device code phishing, OAuth abuse, suspicious consent grants, impossible travel, privileged role changes, and anomalous sign-ins.
- Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases.
- Experience working in large, complex enterprise or manufacturing environments with distributed stakeholders, shared ownership models, and operational constraints.
- Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams.
- Ability to distinguish between detection gaps, telemetry gaps, control gaps, ownership gaps, and response process gaps.
- Excellent analytical and problem-solving skills, with the ability to balance precision, scale, operational usability, and business risk.
- Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries.
- Passion for automation, continuous improvement, high-quality engineering practices, and building durable security systems that scale.
Technical Competency Profile
- Writing and tuning SIEM detections
- Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches
- SOAR playbook design and automation guardrails
- Detection validation, regression testing, tuning, and release readiness
- MITRE ATT&CK mapping and coverage measurement
- Threat-informed detection engineering
- Identity attack detection, including Entra ID, MFA abuse, token theft, OAuth abuse, suspicious consent grants, and privileged role changes
- Endpoint detection and response workflows
- Phishing, malware, suspicious email, and account compromise use cases
- Cloud security detections and CNAPP telemetry
- Network, DNS, proxy, firewall, VPN, and GlobalProtect telemetry
- OT/ICS monitoring considerations in manufacturing environments
- Privileged access monitoring and CyberArk-style PAM telemetry
- Threat intelligence enrichment and operationalization
- Case management, ITSM integration, and analyst workflow improvement
- Detection-as-code, Git, CI/CD, reusable templates, and content lifecycle management
The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.
This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.
The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.
The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.
Job Systems/Information Technology
Organization Cummins Inc.
Role Category Off-site Remote
Job Type Exempt - Experienced
ReqID 2434879
Relocation Package No
100% On-Site No
Cummins and E-Verify
At Cummins, we are an equal opportunity and affirmative action employer dedicated to diversity in the workplace. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law. Cummins validates the right to work using E-Verify and will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS), with information from each new employee’s Form I-9 to confirm work authorization. Visit to know your rights on workplace discrimination.
- ...Midmarket Account Executive: Detection & Response Antigen... ...specializing in comprehensive cybersecurity solutions. By leveraging top... ...products tailored to specific threats and systems, we help organizations... .... As a Microsoft Top 150 Managed Partner and exclusive...SuggestedWork experience placementRemote work
- OverviewThe Manager, IT Security, is a key leadership role within... ..., network security, threat detection, monitoring, logging, encryption... ....Designs and implements automated security monitoring, alerting... ...Degree in Information Security, Cybersecurity or related field (Preferred...Suggested
- ...of-the-art vehicles across the world.Job Responsibilities:The Manager of IT Controls advances Magna IT standards alignment across the... ...enterprise standards and divisional execution to strengthen cybersecurity posture and reduce operational risk. The position contributes...SuggestedFull timeWork at officeLocal area
- ...Rochester Hills, MIHire Type:DirectCompensation:120-145k.Job Duties: Senior Project Manager - Medical & Pharmaceutical AutomationSterling Engineering is partnering with a leading custom automation company that is seeking a Senior Project Manager to oversee complex automation...Suggested
- ...everywhere. Contract Details : Job Title : Industrial Manager Batteries Type of contract : Long-term At-will Location... ...and develop direct reports. Plan to organically grow automation, welding and EOL test expertise related to battery pack line...SuggestedPermanent employmentContract workLocal area
- ...Job Description Job Description Title : Senior Project Manager Location : Rochester Hills, MI Hire Type :Direct Compensation... ...: Senior Project Manager – Medical & Pharmaceutical Automation Sterling Engineering is partnering with a leading custom...
$2,500 per month
...Job Description Job Description Overview: The Project Manager Lead oversees complex automation projects from initiation through delivery, ensuring alignment with customer expectations, technical requirements, and organizational objectives. This role drives cross...Relocation packageFlexible hours- PositionBusiness Unit Regional IT Senior Manager, DMS Americas LocationAuburn Hills -... ...technology, assures compliance with IT and cybersecurity standards, and leads the regional IT... ...data pipelines, and plant level‑level automation.Strengthening IT/OT cybersecurity posture...Full timeLocal areaImmediate startVisa sponsorshipWork visaFree visa
- REPORTS TO: Department Manager JOB TYPE: Full-Time DAYS/HOURS: Monday - Friday. Standard business hours LOCATION: 2831 Research Drive... ...approach to technology, leveraging cost-effective business automation solutions for our customers. Our solutions include software...Full timeWork at officeMonday to FridayFlexible hoursNight shiftWeekend workEarly shift
- ...roles and responsibilitiesForvia is building a North American Automation Center of Excellence (COE) to define and deploy next-generation... ...across our manufacturing network.As an Automation Project Manager, you will play a critical role in shaping and executing this strategy...
- .... Because we win together.Are you ready for a better career? A better future?Job DescriptionAs a member of the Automation team, the Automation Project Manager will be responsible for Leading, Supporting, Implementing, and Managing Automation projections while driving innovation...
$130k
...Account Manager Automation Solutions Our client is a prominent company specializing in state-of-the-art automation solutions across multiple sectors. Part of a global conglomerate with significant market presence, our client is renowned for innovation and engineering...Work at officeRemote work- ...execution discipline, and steadfast progress across supplier-managed Value-Added Assembly (VAA) projects supporting GMNA. The position... ...engineering budget trade-offs, evaluating manual versus SMART automation opportunities, incorporating lessons learned into standards...Full timeContract workLocal areaWork from homeRelocationRelocation package
- ...Sales Executive to drive growth in our Cybersecurity practice. You will originate new opportunities... ...through assessment, transformation, and managed services offerings. This role requires a... ...articulate EY's differentiated value in a complex threat landscape. #J-18808-Ljbffr EY
- Job DescriptionThe RoleThe Manufacturing Launch Program Manager owns the successful deployment of all IT systems required to launch... ...execution across applications, infrastructure, controls, and cybersecurity technologies.This role requires strong expertise in plant floor...Full timeFor contractorsH1bLocal areaWork from homeRelocationRelocation package
- ...company focused on uncrewed systems, satellite communications, cybersecurity, microwave electronics, missile defense, training, and combat... ...effective solutions. GENERAL JOB SUMMARY The Human Resources Manager leads and administers the siteis Human Resources function while...Temporary workInternshipWork at office
$190k - $210k
General Cognizant’s Intuitive Operations & Automation (IOA) business unit is one of Cognizant’s highest growth businesses. To accelerate... ...Industry. Demonstrated ability of building sales and account management teams and supporting clients at all levels. Deep...Temporary work$144.9k - $302.1k
...significant impact on global cybersecurity. The opportunity The Zscaler Engineer Manager will be responsible for overseeing... ...Zscaler security trends, threats, and technologies. Skills... ...Python, PowerShell, or Bash for automation and configuration management....Full timeSummer holidayFlexible hours- IT Managed Services Account Manager Location: Hybrid Employment Type: Full-Time Join Our Growing Team! Are you passionate... ...planning sessions. * Identify opportunities for managed services, cybersecurity, cloud, and professional services growth. * Collaborate with...Full timeFlexible hours
- ...of position:We are looking for an Information System Security Manager to work in Warren MI Area. The contractor shall serve as an Information... ...The contractor shall be the lead for maintaining the overall cybersecurity program of the systems and platforms for which they are...Full timeFor contractorsLocal areaWorldwide
- ...Job Description Job Description Description: Job Title: Project Manager I, Factory Automation (ONISTE M-F) About Us Solving your motion control challenges with ingenuity. Evolution Motion Solutions is a leading engineering partner, systems integrator,...Work at officeFlexible hours
$50 per hour
..., cutting, brazing, machining, process automation, and field repair. The Company leverages... ... Primary Function The General Manager serves as the senior site leader with full... ...with all applicable aerospace, cybersecurity, safety, environmental, and regulatory...Contract workTemporary workFor contractorsLocal area- ...DescriptionThe RoleGeneral Motors is seeking a Software Engineering Manager to lead delivery, modernization, and operational excellence... ....Partner with product, business, architecture, platform, cybersecurity, operations, and peer engineering teams to deliver reliable, scalable...Full timeLocal areaRemote workWork from homeRelocation packageFlexible hours
- ...equipment across customer facilities Drive aftermarket sales of automation equipment, spare parts, service contracts, and system upgrades... .... Collaborate closely with engineering, service, and project management teams to scope technical requirements and deliver timely...For contractorsWork at office
- Technical Recruiter - Engineering @ Zobility | Managing High-Volume Engineering Recruitment We are seeking a highly-skilled and experienced... ...Manager to oversee the complete lifecycle of our Powertrain Automation systems , specifically focusing on Automated machining lines...Full timeContract workNight shiftWeekend work
- ...quality ratings. Conduct training across the organization and manage special process personnel testing and certifications. Oversee both... ...with advanced technologies such as ATOS 5 Scan Box and automated quality systems. Strong problem-solving skills with a data-driven...Full timeRemote work
- ...Director of Advanced Tooling, Advanced Manufacturing, and Automation leads the enterprise-wide strategy, standards, and... ...Drive standardization of controls documentation, change management, and cybersecurity practices across all automated systems. Partner with suppliers...Work experience placement
$73.88k - $100k
...Executive is accountable for: Responsibilities Focus within the Automation engineering vertical As an experienced seller in your... ...executives/decision-makers, engineering directors, engineering managers, etc. Influence and partner with a team of specialized engineering...Contract workTemporary work- ...Description Description: Job Title: Project Coordinator, Factory Automation (Onsite) About Us For over 80 years, we have pioneered... ...with disabilities to perform the primary duties. Maintain, manage and prioritize “Open RFQ List”. Organize all RFQ supplied...Work at officeFlexible hours
- ...surface inspection to software-controlled robotics systems for smart factory automation.Short DescriptionContribute to the creation/leadership of the MVS strategy and drive, coach, and manage teams to achieve complete customer satisfaction and profitable growth.Key ResponsibilitiesWork...Remote workFlexible hoursNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Threat Detection & Automation Manager. Be the first to apply!
- IT cyber security Troy, MI
- cyber security Troy, MI
- cybersecurity specialist Troy, MI
- cybersecurity certificate Troy, MI
- cybersecurity administrator Troy, MI
- senior cybersecurity engineer Troy, MI
- cybersecurity software engineer Troy, MI
- cybersecurity Troy, MI
- building automation manager Troy, MI
- automation project manager Troy, MI


