At Cox Automotive in Atlanta, GA (onsite), a Senior Manager of Cybersecurity Detection Engineering leads a team of detection engineers to design, implement, and maintain advanced detection capabilities as part of the Cyber Defense program. This role shapes the Detection Engineering strategy and works across security, engineering, and product teams to strengthen protection for both the enterprise and its customers.
Responsibilities
- Define detection engineering strategy, roadmap, and objectives to achieve.
- Design and implement advanced threat detection techniques using SIEM, EDR, NDR, and SOAR platforms.
- Develop innovative custom detection rules and automated remediation, playbooks, and alerts tailored to the organization's threat landscape for enterprise and customer security.
- Leverage industry standard MITRE frameworks to identify detection coverage and close gaps.
- Monitor, optimize, and continuously improve detection systems for performance, scalability, and effectiveness.
- Collaborate with Threat Detection and Response teams to improve capabilities in identification, management, and response to threats.
- Perform attack simulation testing to validate efficacy of use cases and purple teaming exercises with the Vulnerability Management team.
- Manage and maintain SIEM/Data Lake data management and log ingestion infrastructure in collaboration with Cyber Defense Engineering.
- Evaluate, validate, tune, and sunset detection capabilities where necessary.
- Maintain operational guidelines, diagrams, and documentation for security detection and response.
- Collaborate with the incident response team to ensure rapid detection and containment of cyber threats.
- Provide technical expertise and guidance to develop detection use cases during high-severity security incidents.
- Continuously improve detection and response processes based on lessons learned from incidents.
- Other duties may be assigned to address new security threats facing the enterprise.
- Provide off hour support as needed for security administration, detection, and response activities.
- Leverage threat intelligence to enhance detection capabilities and proactively mitigate risks.
- Identify and analyze new and emerging threat vectors and incorporate them into detection strategies.
- Partner with other Cybersecurity, Engineering, and Product teams to align detection strategies with organizational objectives.
- Communicate detection capabilities and findings to technical and non-technical stakeholders, including executive leadership.
- Ensure all detection processes and tools adhere to regulatory requirements and industry standards (GDPR, PCI-DSS, NIST).
- Establish and maintain documentation of detection strategies, processes, and configurations.
- Proven track record of building scalable organizations with world-class threat detection capabilities.
- Technical proficiency performing security investigations at scale, including endpoint, cloud, identity, network, and email threats.
- Work with internal IT teams and external MSSPs to create and operationalize detection use cases for WAF, DDoS Protection, Email systems, DLP, AV, and Endpoint security technologies.
- Practical experience with Detection & Response tools for network, endpoints, cloud, and identity as well as SOAR platforms.
- Apply security Threat Intelligence to identify new threat vectors.
- Lead projects to improve security monitoring and response capabilities.
- Demonstrate a strong security engineering and architecture background to deploy effective monitoring solutions.
- Maintain strong fundamentals of Linux, MacOS, and Windows operating system internals.
- Communicate security issues effectively to management and other stakeholders.
- Maintain detection use case and SIEM configuration guidelines and standards for security.
- Develop and manage operational metrics to increase team efficiency and quality.
- Mentor individuals pursuing careers in detection engineering.
- Manage relationships with organizational leaders, build roadmaps, and drive initiatives to completion.
- Understand Machine Learning concepts as related to predictive analytics.
Requirements
- Bachelor's degree in Computer Science or equivalent and 8+ years of related professional experience; alternative combinations are acceptable (master's with 6 years, PhD with 3 years, or 20 years in a related field).
- 3+ years of management or leadership experience with direct people management responsibilities.
- 5+ years of experience in an Incident Response or Security Operations role.
- Multi-cloud security experience (AWS, Azure, GCP).
- Expert level knowledge in Detection Engineering and Security Operations.
- Strong experience with Information Security, Network Security, Security Monitoring, and Incident Response.
- Strong experience with developing SIEM/SOAR detection and automation use cases.
- Working experience with Threat Intelligence, Firewalls, SASE, IPS, Endpoint Security, DLP, SIEM/SOAR, and Data Lakes.
- Expert level knowledge on the attack kill chain and diamond model.
- Applicants must be authorized to work in the United States without current or future sponsorship (no OPT, CPT, STEM/OPT or visa sponsorship now or in future).
- Desirable: certifications such as GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA; development/DevOps/engineering/network/system administration experience.
Technologies
- SIEM, EDR, NDR, SOAR
- MITRE frameworks
- WAF, DDoS Protection, Email systems, DLP, AV, Endpoint security technologies
- Threat Intelligence, Firewalls, SASE, IPS, Data Lakes
- Linux, MacOS, Windows
- Log ingestion, Data Lake data management
Benefits
- Paid vacation with pay
- Seven paid holidays per year
- Up to 160 hours of paid wellness annually
- Bereavement leave
- Time off to vote
- Jury duty leave
- Volunteer time off
- Military leave
- Parental leave
Compensation
USD 178,200.00 - 297,000.00 per year. The base salary falls within this range and may vary based on location and the candidate's knowledge, skills, and abilities. The position may be eligible for additional compensation that could include an incentive program.
Who you are
Minimum qualifications include a bachelor's degree in Computer Science or equivalent with 8+ years of related professional experience; alternative combinations such as a master's degree with 6 years, a PhD with 3 years, or 20 years in a related field are considered. At least 3 years of management or leadership experience with direct people management responsibilities and 5+ years in Incident Response or Security Operations are required. The role demands multi-cloud security experience (AWS, Azure, GCP) and expert knowledge in detection engineering and security operations. Desirable certifications include GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA, along with relevant Development/DevOps/Engineering/Network/System Administration experience.