Overview
Join our team as the Senior Cybersecurity Detection Engineering Manager, where you will lead a dynamic group of Detection Engineers in crafting, implementing, and maintaining state-of-the-art detection capabilities to protect our organization from emerging cyber threats. This crucial role enhances Cox Automotive's next-generation Cyber Defense practice, fostering rapid threat response and automated remediation. You will define and execute the strategy for the Detection Engineering program and establish metrics for continuous improvement. The ideal candidate will bring expertise in SIEM implementation, log ingestion, SOAR, Incident Response, and Threat Intelligence, along with strong communication and leadership skills.
Key Responsibilities
- Develop and refine the detection engineering strategy, roadmap, and objectives.
- Design and implement advanced threat detection techniques using tools such as SIEM, EDR, NDR, and SOAR platforms.
- Create innovative detection rules, automated remediation playbooks, and alerts tailored to our threat landscape.
- Utilize industry standard MITRE frameworks to identify coverage gaps in detection.
- Monitor, optimize, and enhance detection systems for peak performance and effectiveness.
- Collaborate with the Threat Detection and Response team to boost cybersecurity capabilities in threat identification and management.
- Conduct attack simulation testing to validate detection use cases and engage in purple teaming exercises.
- Oversee SIEM / Data Lake infrastructure maintenance and log ingestion in collaboration with Cyber Defense Engineering.
- Evaluate and fine-tune detection capabilities continuously.
- Maintain comprehensive operational guidelines and documentation for security detection and response.
Incident Response Support
Work with the incident response team to ensure timely detection and containment of cyber threats.Provide technical guidance to develop detection use cases during high-severity incidents.Continuously refine detection and response processes based on lessons learned.Support additional security tasks as needed to address new threats.Offer support outside regular hours for security administration and response activities.Threat Intelligence Integration
Utilize threat intelligence to bolster detection capabilities and proactively manage risks.Analyze new and emerging threat vectors and incorporate findings into detection strategies.Stakeholder Collaboration
Partner with Cybersecurity, Engineering, and Product teams to align detection efforts with organizational goals.Communicate detection capabilities and findings effectively to both technical and non-technical stakeholders.Governance and Compliance
Ensure detection processes adhere to regulatory requirements and industry standards (e.g., GDPR, PCI-DSS, NIST).Document detection strategies, processes, and configurations thoroughly.Professional Technology Skills
Proven ability to build scalable teams with world-class detection capabilities.Technical proficiency in conducting security investigations across various systems.Collaborate with internal IT teams and external MSSPs on detection use cases for various security technologies.Practical experience with Detection & Response tools across network, endpoints, cloud, and identity.Utilize security Threat Intelligence to recognize new threat vectors.Lead initiatives to enhance security monitoring and response capabilities.Strong background in security engineering and architecture.Proficient in Linux, MacOS, and Windows operating systems.Capable of effectively communicating security issues to management and stakeholders.Maintain standards for detection use cases and SIEM configurations.Create and manage metrics to boost team efficiency and quality.Passionate about mentoring individuals in detection engineering careers.Skilled in building strong relationships with leaders to drive initiatives to completion.Understanding of Machine Learning concepts related to predictive analytics.Knowledge, Experience & Qualifications
Essential
Bachelor's degree in Computer Science or a related field with 8+ years of relevant professional experience; alternative combinations of education and experience will be considered.Experience with multi-cloud security (AWS, Azure, GCP).Expert-level knowledge in Detection Engineering and Security Operations.3+ years of leadership experience with direct management responsibilities.Strong background in Information Security, Network Security, Security Monitoring, and Incident Response.Proficient in developing SIEM / SOAR detection and automation use cases.Experience with standard security technologies and services.Expert knowledge of the attack kill chain and diamond model.5+ years in an Incident Response or Security Operations role.3+ years of leadership experience in a SOC or equivalent.Willingness to commute to North Hills, NY, or Atlanta, GA, onsite 3 times a week.Desirable
Certification(s) such as GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA.Development / DevOps / Engineering / Network / System Administration experience.Compensation
The compensation for this position ranges from $173,900.00 to $289,800.00 based on various factors including location and applicant qualifications. The role may also be eligible for additional incentives.
Benefits
Cox Automotive offers eligible employees flexible vacation policies, seven paid holidays, and up to 160 hours of paid wellness leave annually. Additional paid time off includes bereavement leave, military leave, and parental leave among others.