Cybersecurity Threat Detection – Automation Manager

Job Description:

  • Lead, manage, mentor, and develop a team of detection engineering and automation professionals
  • Define and execute threat detection and automation strategy aligned with business risk, operational needs, threat landscape, compliance requirements, and organizational priorities
  • Establish intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement processes
  • Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms
  • Own high-impact detections for complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats
  • Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk
  • Conduct detection gap analysis and threat modeling
  • Build detection validation practices, test cases, regression checks, tuning evidence, performance monitoring, and analyst feedback loops
  • Lead SIEM and SOAR detection and response workflows
  • Build SIEM content including correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment
  • Develop SOAR playbooks for enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support
  • Drive integrations across SIEM, SOAR, EDR, email security, identity, threat intelligence, ITSM, cloud, network, PAM, DLP/CASB, and OT monitoring platforms
  • Build and mature the detection and automation lifecycle from intake through retirement
  • Manage the detection and automation roadmap and program metrics
  • Maintain audit-ready documentation and evidence
  • Communicate strategy, risk coverage, maturity, roadmap, and outcomes to technical and non-technical stakeholders, including executive leadership

Requirements:

  • 10+ years of cybersecurity experience working in SOC and creating SIEM correlations/detections and automating incident information enrichment tasks
  • Experience building mature detection lifecycle practices
  • Experience building SOAR playbooks and automation workflows
  • Experience with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns
  • Experience operationalizing threat intelligence
  • Experience designing detections for identity-based attacks
  • Experience designing detections across endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases
  • Experience working in large, complex enterprise or manufacturing environments
  • Experience partnering with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams
  • Ability to distinguish between detection, telemetry, control, ownership, and response process gaps
  • Excellent analytical and problem-solving skills
  • Demonstrated ability to lead, coach, and advise team members across cultural, geographic, technical, and generational boundaries
  • Writing and tuning SIEM detections
  • Splunk SPL, risk-based alerting, notable events, dashboards, and correlation searches
  • SOAR playbook design and automation guardrails
  • Detection validation, regression testing, tuning, and release readiness
  • MITRE ATT&CK mapping and coverage measurement
  • Threat-informed detection engineering
  • Identity attack detection, including Entra ID, MFA abuse, token theft, OAuth abuse, suspicious consent grants, and privileged role changes
  • Endpoint detection and response workflows
  • Phishing, malware, suspicious email, and account compromise use cases
  • Cloud security detections and CNAPP telemetry
  • Network, DNS, proxy, firewall, VPN, and GlobalProtect telemetry
  • OT/ICS monitoring considerations in manufacturing environments
  • Privileged access monitoring and CyberArk-style PAM telemetry
  • Threat intelligence enrichment and operationalization
  • Case management, ITSM integration, and analyst workflow improvement
  • Detection-as-code, Git, CI/CD, reusable templates, and content lifecycle management

Benefits:

  • Equal employment opportunity policy
  • Off-site remote work arrangement
Back to blog

Other Jobs To Apply

Remote Customer Support Specialist- Part Time & Full Time

PACS Admin with Site co-ordinator (reputed company and Divrad)

Social Media Lead (m/w/d) | Strategie & Performance | 100 % remote

**Experienced Online Customer Support Specialist – reputed company Chat Support (Remote) – Part-Time Opportunity**

Junior Level/ Entry Level Software Engineer (Remote)

Ramp Agent - Evening Shift

Work from Home Overnight Jobs Late Night Customer Experience Specialist $25-$35/hr ? Enhance customer experiences during late-night hours in a home-based role.

Warehouse Associate - Night Shift- Immediate Hiring

reputed company Careers - Find flexible, work-from-home jobs helping customers while earning $25-$35 per hour.

Call Center Representative- Reno, Nevada- Remote (Any city, NV, US, 99999)

Nurse Consultant (Nursing Home Surveyor)

Warehouse Worker Job at Hayes Company LLC in Forney

SOC Analyst I (Remote)

Remote Part‑Time Customer Service Representative – Flight Operations & Passenger Support – Earn $27/hr at arenaflex

Live Chat Jobs - Remote Position (Up to $35/hour) - No Degree Required, No Experience Necessary

[Remote] DR Systems PACS Administrator / Specialist

-Work From Home Position | Entry-Level | Flexible Hours

Flexible Part-Time Remote Data Entry Specialist | Flexible Hours & Training Provided | Join arenaflex Team

reputed company, Progressive Care, Per-diem

Remote Physical Therapist in ID

Overnight Positions Near Me Online – Non-Phone Digital Chat Role | $25–$35/hr

reputed company RN – Clinical Documentation Specialist – CDIP CCDS Required – 100% Remote, GA

HelpDesk (Customer Support)

Senior Technical Program Manager, Amazon Access - Apply

Entry Level Financial Protection Specialist (Remote)

[Remote] Epic- Clinical Service Desk Specialist-REMOTE

Work from Home as a Game Tester in the United States

Medical Scribe (Remote - Full Time) - Full-time

Part Time Package Handler (Twilight) - YVR Area

Lead Backend Developer – Aviation Systems (Remote, Full-Time)

Remote Cybersecurity Jobs - reputed company

Appeals Nurse (RN) Analyst (670084)

Dealer Development Manager (Nashville, TN)

Entry-Level Data Entry Specialist Remote

Part-Time Remote Typist/Data Entry Clerk

No Experience Necessary | Work from Home Chat Agent Job - $25-$35/hour (Remote), Compensation: $25-$35/hour

**Remote Data Entry Clerk – Part‑Time, Precision‑Focused, Flexible Hours, Global Collaboration**

Remote Product Support Representative (No Degree Required/High Paying)

Entry-Level Data Entry Clerk – No Experience Required – Immediate Start at arenaflex – Grow Your Career in a Dynamic Data‑Driven Environment

**Dedicated Overnight Live Chat Support Agent – Remote, Night Shift Customer Service Specialist with Strong Communication Skills**

**Customer Service & Support Representative – Remote – 6+ Month Engagement – Join arenaflex’s Dynamic Operations & Assurance Team**

Experienced Remote Administrative Support & Data Entry Assistant – Part-Time, Entry Level | Flexible Hours + Great Pay

Weekend Job / Part-time Job - Online Tutor in Türkiye

[Remote] Business Operations Admin

Remote Live Chat & Email Support Specialist – Deliver Outstanding Customer Service from Home, Earn $25–$35 per Hour

Customer Support Jobs No Phone Flexible Schedule – reputed company | $25–$35/hr

**Remote Admin Support - Data Entry Role at blithequark**

**Experienced Customer Support Representative – Night and Weekend Shift – Coppell, TX**

Part-Time Remote Live Chat Support Specialist – No Experience Required, Flexible Hours, Earn Up to $280 Daily

**Experienced Part‑Time Remote Data Entry & Market Research Specialist – Earn Competitive Pay in Paid Focus Groups & Clinical Trials**