Cyber Threat Management Senior AssociateOverview / Summary We are seeking a Cyber Threat Management Senior Associate to support hands-on operational monitoring and incident response across connected vehicle and cloud environments. This role will focus on alert triage, security investigations, incident support, and continuous improvement of monitoring and response processes.
The position will support cybersecurity monitoring for connected vehicles and the cloud services that support them. The ideal candidate will have a solid cybersecurity foundation, including API security experience, along with exposure to embedded vehicle cybersecurity or a demonstrated aptitude and eagerness to learn.
Key Responsibilities - Perform daily security alert triage and support incident coordination, containment, remediation, recovery, and closure.
- Support investigations of security events across cloud application stacks and embedded vehicle architectures using available logging and telemetry.
- Partner with cybersecurity operations teams across regions to support consistent monitoring, investigation, and incident-response services.
- Maintain effective continuity and handoffs for active security events.
- Identify operational challenges and provide feedback to improve detection logic, tooling, and response workflows.
- Collaborate with incident response, product development, and enterprise IT teams to execute response playbooks and coordinate complex mitigations.
- Support detection and investigation of threats across cloud and vehicle telemetry data, including log correlation and alert tuning.
- Use and refine runbooks, playbooks, and escalation procedures in an operations environment.
- Identify recurring incidents and provide suggestions for process or detection improvements.
Required Qualifications - 3-5 years of experience in a relevant field.
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field.
- 2+ years of experience in cybersecurity, security operations, or a related technical field.
- Cybersecurity, API, and information security knowledge.
- Working understanding of incident response lifecycles, escalation, and incident management practices.
- Experience with API security.
- Exposure to cloud security operations on one or more major cloud platforms, including logging, monitoring, identity, and response workflows.
- Embedded vehicle cybersecurity exposure or a demonstrated aptitude and eagerness to learn.
- Ability to work effectively in a fast-paced 24x7 operations environment, including shift-based coverage.
- Clear written and verbal communication skills for documenting incidents and coordinating with technical teams.
Preferred Qualifications - Experience detecting and investigating threats across cloud and vehicle telemetry data, including log correlation and alert tuning.
- Experience using or refining runbooks, playbooks, and escalation procedures in an operations setting.
- Relevant certifications such as Security+, GIAC, or foundational cloud security certifications across AWS, Azure, or GCP.
- Familiarity with embedded or automotive environments and the security considerations of cloud architecture.
- Ability to turn recurring incidents into process or detection improvement suggestions.
#LI-RM1