- Company Name
- Cox Automotive
- Job Title
- Senior Manager of Cybersecurity Detection Engineering
- Job Description
-
**Job Title:**
Senior Manager of Cybersecurity Detection Engineering
**Role Summary:**
Lead a team of detection engineers to develop, deploy, and continuously improve advanced threat detection capabilities across SIEM, SOAR, EDR, NDR, and other security platforms. Own strategy, roadmap, metrics, and governance for the Detection Engineering program, ensuring rapid threat response and automated remediation while aligning with organizational objectives and compliance requirements.
**Expectations:**
- Build and scale a world‑class detection organization.
- Drive end‑to‑end detection lifecycle: research, design, implement, validate, and retire use cases.
- Mentor and develop a high‑performance talent pipeline.
- Deliver measurable improvements in detection coverage, precision, and incident response time.
**Key Responsibilities:**
- Define detection strategy, roadmap, and KPIs.
- Design and create custom detection rules, playbooks, and automated remediation for enterprise and customer environments.
- Leverage MITRE ATT&CK, threat intelligence feeds, and purple‑team exercises to close coverage gaps.
- Manage SIEM/Data Lake ingestion, configuration, tuning, and sunset processes.
- Monitor performance, scalability, and effectiveness of detection systems; optimize for efficiency.
- Collaborate with Threat Detection & Response, Vulnerability Management, and engineering teams.
- Conduct attack simulation testing and validate use cases.
- Support incident response with timely detection, containment, and post‑mortem analysis.
- Integrate threat intelligence to update detection logic proactively.
- Maintain operational documentation, diagrams, and configuration standards.
- Communicate findings and strategy to technical teams and executive stakeholders.
- Ensure compliance with GDPR, PCI‑DSS, NIST, and other regulatory frameworks.
- Provide on‑call/after‑hours support for detection and response operations.
**Required Skills:**
- Proven experience building scalable threat detection teams and programs.
- In‑depth expertise in SIEM (Splunk, ArcSight, QRadar, etc.), SOAR (Demisto, Sentinel, Phantom), EDR, NDR, and cloud detection solutions.
- Strong technical background across endpoint, cloud, identity, network, and email threat analysis.
- Ability to develop and maintain detection use cases for WAF, DDoS, DLP, AV, and endpoint security.
- Proficiency in Linux, MacOS, and Windows internals; strong fundamentals in OS, networking, and scripting.
- Practical knowledge of threat intelligence frameworks and data sources.
- Project management and roadmap development.
- Effective written and verbal communication with technical and non‑technical audiences.
- Experience creating operational metrics, dashboards, and continuous improvement processes.
- Mentorship and team leadership capabilities.
- Familiarity with machine learning concepts applied to predictive security analytics.
- Capability to manage stakeholder relationships across security, engineering, and product domains.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred).
- Professional certifications: CISSP, CEH, GCFA, GCIH, CCSP, or equivalent; SIEM/SOAR‑specific credentials (e.g., Splunk Certified Architect, Palo Alto Prisma Cloud, RSA NetWitness).
- Additional credentials in threat intelligence (CTI) or advanced analytics are advantageous.