Cummins

Cybersecurity Threat Detection & Automation Manager

Cummins$120K — $145K *
Troy, MI 48085In-Person
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity with expertise in threat detection and response
  • Proven track record in SIEM and SOAR technologies
  • Experience in detection engineering, automation design, and incident response
  • Strong leadership and mentoring skills in a technical environment
  • Ability to translate complex threat intelligence into actionable detections
  • Proficient in MITRE ATT&CK and designing detection strategies for various environments
  • Experience with managing detection lifecycles and program metrics

Responsibilities

  • Lead and mentor a team focused on advanced threat detection and automation
  • Create and cultivate a culture of engineering excellence and continuous improvement
  • Involve directly in the development and tuning of threat detection logic
  • Define and implement the strategy for threat detection aligned with organizational needs
  • Manage operational processes including backlog, prioritization, and team metrics
  • Coach team members on effective detection and automation practices
  • Collaborate with various cross-functional teams to strengthen security posture

Benefits

  • Opportunity to shape the organization's cybersecurity strategy
  • Hands-on leadership role with direct involvement in technical challenges
  • Engage in continuous improvement and innovation practices
  • Work within a collaborative environment across diverse teams
  • Impact on reducing security risks and improving operational efficiency
Full Job Description
Job Description

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.

This is a hands-on player/coach leadership role. The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.

The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization's overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.

The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

The Impact You Will Make

In this role, you will help modernize and mature the organization's threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.

You will directly influence:
  • Detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments
  • Alert fidelity and false-positive reduction
  • Investigation speed and analyst consistency
  • SOAR automation maturity and response scalability
  • Detection lifecycle governance, testing, validation, and documentation
  • SecOps modernization across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms
  • Reduced manual triage and improved operational repeatability
  • Stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams


Responsibilities

Key Responsibilities

Leadership and Team Management
  • Manage, mentor, and develop a team of detection engineering and automation professionals.
  • Build a culture of engineering rigor, operational discipline, innovation, accountability, quality, and continuous improvement.
  • Operate as a hands-on manager by personally owning, reviewing, and contributing to key detections, automation workflows, technical initiatives, and program improvements.
  • Define and execute the threat detection and automation strategy aligned to business risk, operational needs, threat landscape, compliance requirements, and organizational priorities.
  • Establish the team's operating rhythm, including intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement.
  • Coach team members on detection logic, investigation quality, automation design, threat modeling, analyst usability, operational impact, and stakeholder communication.
  • Partner closely with SOC Monitoring, Incident Response, Threat Intelligence, SIEM Engineering, Cloud, Identity, Network, OT, IT Infrastructure, Vulnerability Management, GRC, and business stakeholders.


Threat Detection Engineering
  • Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms.
  • Personally own a portfolio of high-impact detections focused on complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats.
  • Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, kill-chain models, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk.
  • Conduct detection gap analysis and threat modeling to prioritize improvements based on exposure, telemetry readiness, attacker behavior, business impact, and operational value.
  • Build and maintain detection validation practices, including test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback loops.
  • Ensure detections are operationally useful by including clear context, enrichment, severity guidance, response steps, escalation paths, and containment recommendations.
  • Measure and expand detection coverage across ATT&CK tactics and techniques, critical assets, identities, cloud platforms, OT environments, and enterprise telemetry sources.
  • Stay current with emerging threats, adversary tradecraft, tools, vulnerabilities, and detection methods.


SIEM, SOAR, and Security Automation
  • Lead the design, development, and continuous improvement of SIEM and SOAR-driven detection and response workflows.
  • Build and optimize SIEM content, including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment.
  • Develop and mature SOAR playbooks that automate enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support.
  • Identify repetitive, high-volume, or high-value SOC activities that can be safely and effectively automated.
  • Define automation standards covering human-in-the-loop approvals, reversible actions, audit trails, exception handling, failure modes, escalation criteria, and rollback considerations.
  • Partner with SOC and Incident Response teams to ensure automation improves investigation speed, consistency, quality, and response outcomes without creating unnecessary operational risk.
  • Measure automation effectiveness using metrics such as analyst time saved, touch reduction, playbook success rate, case consistency, response acceleration, and manual effort reduction.
  • Drive integrations across SIEM, SOAR, EDR, email security, identity platforms, threat intelligence, ITSM, cloud security, network security, PAM, DLP/CASB, and OT monitoring platforms.


Detection Lifecycle, Governance, and Program Management
  • Build and mature the detection and automation lifecycle from intake through retirement.
  • Own standards for request intake, prioritization, design, build, peer review, testing, deployment, tuning, production monitoring, and continuous improvement.
  • Create and maintain use case standards, templates, documentation requirements, acceptance criteria, release gates, change history, and ownership models.
  • Manage the detection and automation roadmap based on threat intelligence, incident trends, MITRE coverage gaps, telemetry gaps, crown jewel risks, regulatory requirements, and business priorities.
  • Develop and maintain program metrics that demonstrate detection coverage, alert fidelity, false-positive trends, automation value, telemetry readiness, backlog health, delivery throughput, and investigation quality.
  • Partner with stakeholders to identify and resolve telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and unclear ownership across the detection and response ecosystem.
  • Ensure detection and automation practices support internal policies, audit expectations, and applicable regulatory requirements.
  • Maintain audit-ready documentation and evidence, including rationale, test results, tuning notes, change history, ownership, approvals, validation results, and monitoring insights.
  • Communicate detection strategy, risk coverage, maturity, roadmap, and outcomes clearly to both technical and non-technical stakeholders, including executive leadership.


Preferred Qualifications
  • Master's degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related discipline.
  • 10+ years of cybersecurity experience working in SOC and in creating SEIM correlations/detections and automating incident information enrichment tasks
  • Experience in building mature detection lifecycle practices, including intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases.
  • Experience building SOAR playbooks and automation workflows for phishing, malware, suspicious sign-ins, account compromise, endpoint containment, cloud alerts, privileged access activity, and threat intelligence enrichment.
  • Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns.
  • Experience operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks.
  • Experience designing detections for identity-based attacks such as token theft, MFA bypass, device code phishing, OAuth abuse, suspicious consent grants, impossible travel, privileged role changes, and anomalous sign-ins.
  • Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases.
  • Experience working in large, complex enterprise or manufacturing environments with distributed stakeholders, shared ownership models, and operational constraints.
  • Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams.
  • Ability to distinguish between detection gaps, telemetry gaps, control gaps, ownership gaps, and response process gaps.
  • Excellent analytical and problem-solving skills, with the ability to balance precision, scale, operational usability, and business risk.
  • Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries.
  • Passion for automation, continuous improvement, high-quality engineering practices, and building durable security systems that scale.


Technical Competency Profile

  • Writing and tuning SIEM detections
  • Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches
  • SOAR playbook design and automation guardrails
  • Detection validation, regression testing, tuning, and release readiness
  • MITRE ATT&CK mapping and coverage measurement
  • Threat-informed detection engineering
  • Identity attack detection, including Entra ID, MFA abuse, token theft, OAuth abuse, suspicious consent grants, and privileged role changes
  • Endpoint detection and response workflows
  • Phishing, malware, suspicious email, and account compromise use cases
  • Cloud security detections and CNAPP telemetry
  • Network, DNS, proxy, firewall, VPN, and GlobalProtect telemetry
  • OT/ICS monitoring considerations in manufacturing environments
  • Privileged access monitoring and CyberArk-style PAM telemetry
  • Threat intelligence enrichment and operationalization
  • Case management, ITSM integration, and analyst workflow improvement
  • Detection-as-code, Git, CI/CD, reusable templates, and content lifecycle management


Qualifications

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.

This is a hands-on player/coach leadership role. The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.

The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization's overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.

The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

About Cummins

Cummins Power Generation is a world leader in the design and manufacture of power generation equipment, including PowerCommand standby and prime power systems. They also provide single-source warranty, planned maintenance, and round-the-clock emergency service 24 hours a day, seven days a week including back-up power rental through their network of distributors. Part of the world-wide power systems business which has annual sales of more than $1.2 billion, Cummins Power Generation's strength comes from being a division of Cummins Inc. Cummins Power Generation has unique expertise in that all aspects of generator set design, manufacture and service have been brought together in one company. All the major components - the engine, alternator and control systems - are manufactured by divisions of Cummins. This integral approach means each element of a generating set is matched to work in harmony from the start. Providing what the customer wants is at the core of Cummins' manufacturing philosophy. For generating set customers this means a choice of mobile, stationary, open or sound attenuated versions is available for all models.

Cummins Careers

Join the dynamic world of Cummins, a global leader in power solutions, where innovation and leadership drive our mission to power a more prosperous world. At Cummins, we offer unparalleled job opportunities in engineering, technology, and business management, making it an ideal place for professionals seeking meaningful and impactful careers. Work You’ll Do At Cummins, you’ll be part of a team that values diversity and is committed to creating inclusive growth opportunities for all employees. Our culture thrives on intellectual curiosity, cognitive diversity, and bringing your whole self to work. We believe in your potential and encourage every team member to reach their personal and professional goals. Join our industry-leading team to help develop groundbreaking solutions and technologies that impact markets and communities across the globe. Your work at Cummins will not only contribute to global innovation but also ensure sustainable practices that benefit future generations. Professional Growth and Development Cummins is dedicated to the professional growth of its employees. We offer a variety of leadership and diversity training programs designed to enhance your skills and advance your career. From hands-on internships for emerging talents to leadership programs for seasoned professionals, Cummins provides resources and global opportunities to learn, thrive, and lead in your respective field. Innovative Work Environment Our commitment to innovation is at the core of what we do. At Cummins, you will collaborate with skilled colleagues who are eager to share knowledge and ideas. We foster an environment where creative thinking and proactive leadership are encouraged, driving us forward in the areas of clean energy and environmental sustainability. Benefits and Culture Cummins employees enjoy a range of benefits designed to support their physical, financial, and emotional well-being. Among these are comprehensive health care options, competitive retirement plans, and flexible work arrangements. Our supportive culture champions community involvement and a work-life balance that accommodates the diverse needs of our team members. Join Our Team Explore the numerous job opportunities at Cummins where your skills and interests can be matched with the right position, helping you to excel. We are continuously hiring and looking for ambitious, curious, and innovative individuals ready to make a significant impact. Stay Connected Keep up to date with the latest at Cummins by following our careers blog. Gain insights from insiders, learn about our employment practices, and discover how our team is leading the charge in global power solutions. Job Alert Emails Customize your experience by subscribing to Cummins job alerts. Receive updates on new postings, company news, and insider tips directly tailored to your career interests. See what exciting and rewarding opportunities await at Cummins. At Cummins, your career is just beginning. Join us, and power your potential on a global stage.
Learn more about Cummins
Size
59,900 employees
Market Cap
$34.3 billion
Industry
Net Income
$1.7 billion
Founded
1919
5 Year Trend
+6.5%
Revenue
$19.8 billion
NASDAQ

Similar Jobs

More Jobs at Cummins

More Information Technology Jobs

Find similar Cybersecurity Threat Detection & Automation Manager jobs: