... management, least-privilege access, audit logging, and production readiness standards to detection engineering and Agentic SOC delivery.
... management, least-privilege access, audit logging, and production readiness standards to detection engineering and Agentic SOC delivery.
Manager, Technical Security Operations REPORTS TO: Director, Protection Services CLASSIFICATION ... Lead and oversee the efficient operation of the Integrated Operations Center , a 24-hour operations ...
Manager, Technical Security Operations REPORTS TO: Director, Protection Services CLASSIFICATION ... Lead and oversee the efficient operation of the Integrated Operations Center , a 24-hour operations ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to ... Developing and managing integrations across third-party platforms, security tools, and Google ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to ... Developing and managing integrations across third-party platforms, security tools, and Google ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to ... Developing and managing integrations across third-party platforms, security tools, and Google ...
Collaborating with security operations center (SOC) analysts and threat detection engineers to ... Developing and managing integrations across third-party platforms, security tools, and Google ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
IT Security College Co-Op
Detroit, MI · On-site
Job Posting Title IT Security College Co-Op Summary This co-op position focuses on managing alerts and handling security events within a Security Operations Center (SOC). The IT Security Engineering ...
IT Security College Co-Op
Detroit, MI · On-site
Job Posting Title IT Security College Co-Op Summary This co-op position focuses on managing alerts and handling security events within a Security Operations Center (SOC). The IT Security Engineering ...
IT Security College Co-Op
Detroit, MI · On-site
Job Posting Title IT Security College Co-Op Summary This co-op position focuses on managing alerts and handling security events within a Security Operations Center (SOC). The IT Security Engineering ...
IT Security College Co-Op
Detroit, MI · On-site
Job Posting Title IT Security College Co-Op Summary This co-op position focuses on managing alerts and handling security events within a Security Operations Center (SOC). The IT Security Engineering ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Actively manages and escalates risk and customer-impacting issues within the day-to-day role of management. * Act as a Subject Matter Expert (SME) for the Global Security Operations Center. * Handle ...
Manager, Security Operations (Sentinel)
Detroit, MI · On-site +1
$150K - $178K/yr
This role sits within Security Operations and focuses on delivering managed and co-managed security ... Cyber Defense / SOC / XDR Identity & Access Management Data Protection & Compliance Cloud ...
Manager, Security Operations (Sentinel)
Detroit, MI · On-site +1
$150K - $178K/yr
This role sits within Security Operations and focuses on delivering managed and co-managed security ... Cyber Defense / SOC / XDR Identity & Access Management Data Protection & Compliance Cloud ...
In this role, you will support Next-Generation Security Operations Center (SOC) capabilities, including platforms such as Cortex XSIAM, to help clients operate with confidence and proactively manage ...
In this role, you will support Next-Generation Security Operations Center (SOC) capabilities, including platforms such as Cortex XSIAM, to help clients operate with confidence and proactively manage ...
In this role, you will support Next-Generation Security Operations Center (SOC) capabilities, including platforms such as Cortex XSIAM, to help clients operate with confidence and proactively manage ...
In this role, you will support Next-Generation Security Operations Center (SOC) capabilities, including platforms such as Cortex XSIAM, to help clients operate with confidence and proactively manage ...
Security Operations Manager SCOPE: Operations Managers are responsible for providing leadership and management of our contract and temporary security contracts in the assigned region. We are looking ...
Quick apply
Security Operations Manager SCOPE: Operations Managers are responsible for providing leadership and management of our contract and temporary security contracts in the assigned region. We are looking ...
Head Of Information Security
Troy, MI · On-site +1
... manage our total risk exposure. You will oversee the complete lifecycle of security systems ... Govern Security Operations Center (SOC) capabilities, evaluating high-level threat telemetry ...
Quick apply
Head Of Information Security
Troy, MI · On-site +1
... manage our total risk exposure. You will oversee the complete lifecycle of security systems ... Govern Security Operations Center (SOC) capabilities, evaluating high-level threat telemetry ...
Head Of Information Security
Troy, MI · On-site
... manage our total risk exposure. You will oversee the complete lifecycle of security systems ... Govern Security Operations Center (SOC) capabilities, evaluating high-level threat telemetry ...
Head Of Information Security
Troy, MI · On-site
... manage our total risk exposure. You will oversee the complete lifecycle of security systems ... Govern Security Operations Center (SOC) capabilities, evaluating high-level threat telemetry ...
... manage our total risk exposure. You will oversee the complete lifecycle of security systems ... Govern Security Operations Center (SOC) capabilities, evaluating high-level threat telemetry ...
... manage our total risk exposure. You will oversee the complete lifecycle of security systems ... Govern Security Operations Center (SOC) capabilities, evaluating high-level threat telemetry ...
SOC Platform Engineer
Holland, MI · On-site
Voor het Cyber Defense Center (CDC) is Stedin op zoek naar een ervaren SOC Platform Engineer die ... De Platform Architect vormt de brug tussen business, security operations, engineeringteams en ...
SOC Platform Engineer
Holland, MI · On-site
Voor het Cyber Defense Center (CDC) is Stedin op zoek naar een ervaren SOC Platform Engineer die ... De Platform Architect vormt de brug tussen business, security operations, engineeringteams en ...
IT Security Auditor
Potterville, MI · On-site
This position is not a member of the Security Operations Center, rather it is dedicated to working with software development teams on secure coding practices. Candidates must have a strong ...
IT Security Auditor
Potterville, MI · On-site
This position is not a member of the Security Operations Center, rather it is dedicated to working with software development teams on secure coding practices. Candidates must have a strong ...
Soc Security Operations Center Manager information
What is a Soc Security Operations Center Manager?
What are the key skills and qualifications needed to thrive as a Security Operations Center (SOC) Manager?
What are some common challenges faced by a Security Operations Center (SOC) Manager, and how can they effectively address them?
What is the difference between Soc Security Operations Center Manager vs Soc Security Analyst?
| Aspect | Soc Security Operations Center Manager | Soc Security Analyst |
|---|---|---|
| Credentials | Typically requires CISSP, CISM, or GIAC certifications | Often holds CompTIA Security+, SSCP, or GIAC certifications |
| Work Environment | Leads SOC team, manages incident response, oversees security operations | Monitors security alerts, analyzes threats, supports incident investigations |
| Employer & Industry Usage | Common in large enterprises, government agencies, cybersecurity firms | Found across various industries, including finance, healthcare, and tech |
The Soc Security Operations Center Manager focuses on leading security teams and managing overall security operations, while the Soc Security Analyst primarily monitors and analyzes security threats. Both roles require relevant certifications and are vital in cybersecurity teams, but the manager has broader responsibilities in leadership and strategy.
Cyber Automation Analyst - Security Operations Center
Dearborn, MI • On-site
Full-time
Medical, Dental, Vision, Life, PTO
Posted 14 days ago
Ford Motor Company rating
7.6
Based on 529 frontline employees who took The Breakroom Quiz
Job description
We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we're all a part of something bigger than ourselves. Are you ready to change the way the world moves?
Enterprise Technology plays a critical part in shaping the future of mobility. If you're looking for the chance to leverage advanced technology to redefine the transportation landscape, enhance the customer experience and improve people's lives, this is the opportunity for you. Join us and challenge your IT expertise and analytical skills to help create vehicles that are as smart as you are.
This role will be focused on advancing Ford's Cyber Defense Center (CDC) detection engineering, automation, and Agentic SOC capabilities within the Office of the CETO organization. The CDC mission is to provide proactive and reactive security services to protect Ford Motor Company global digital information assets from compromise. The Detection Engineer will design, build, test, and maintain high-fidelity detections and security automations across SIEM, SOAR, EDR, cloud, identity, and AI-enabled security platforms. This position requires hands-on expertise in Google SecOps, GCP-hosted CI/CD pipelines, Tekton-based delivery workflows, Python automation, and secure Agentic SOC development using modern generative AI patterns.
Successful candidates must bring deep cyber defense experience and strong software engineering discipline. The candidate should be able to translate attacker behaviors, cloud telemetry, endpoint signals, identity events, and SOC case history into durable detection logic and automated response workflows. This role also requires the ability to develop, validate, and deploy AI-assisted SOC capabilities, including agent skills, retrieval-augmented workflows, Model Context Protocol integrations, secure prompt and tool governance, and human-in-the-loop guardrails for production security operations.
Candidates must be willing to work a Hybrid work pattern, with a currently limited in-office schedule in the southeast Michigan metro area 4 days in-person/week.
You'll have...
- Bachelor's degree in computer science, cybersecurity, engineering, information systems, or a related technical field, OR a combination of education and equivalent practical experience.
- 5 years of experience across the following areas:
- Hands-on detection engineering experience creating, tuning, testing, and deploying production security detections in SIEM or security analytics platforms, with preference for Google SecOps.
- Hands-on experience building and operating GCP-hosted CI/CD pipelines, including Tekton tasks, Tekton pipelines, pipeline triggers, workload identity or service account usage, secrets handling, and deployment promotion workflows.
- Proficiency developing AI-assisted or Agentic SOC capabilities using generative AI, LLMs, RAG, agent skills, tool orchestration, MCP-style integrations, evaluation patterns, and guardrails for secure operational use.
- Strong Python programming skills, including REST API integration, structured data handling, automation, unit testing, error handling, and production support practices.
- Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats, identity compromise, vulnerability management, detection logic, and incident response workflows.
Even better, you may have...
- 2+ years security engineering experience.
- Experience with Google SecOps, YARA-L or similar detection languages, and security case management workflows.
- Familiarity with Gemini Enterprise Agent Platform concepts, Agent Runtime, Agent Registry, Skills Registry, Model Armor, Agent Gateway, Memory Bank, delegated identity, and secure tool execution patterns.
- Sound understanding of cloud, TCP/IP, networking, endpoint, identity, logging, and data pipeline concepts.
- Demonstrated independent initiative, strong ownership, quality methods, teamwork, sound judgment, and high integrity.
You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder...or all of the above? No matter what you choose, we offer a work life that works for you, including:
- Immediate medical, dental, vision and prescription drug coverage
- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
- Vehicle discount program for employees and family members and management leases
- Tuition assistance
- Established and active employee resource groups
- Paid time off for individual and team community service
- A generous schedule of paid holidays, including the week between Christmas and New Year's Day
- Paid time off and the option to purchase additional vacation time.
For a detailed look at our benefits, click here: https://fordcareers.co/GSR
*Note: This is a hybrid role, you are expected to relocate if you are not within commutable distance, and responsible to be on site 4 days a week
This position is a range of salary grade(s) 7-8 | $99,600 - $192,900
Visa sponsorship is not available for this position.
Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.
We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, if you need a reasonable accommodation for the online application process due to a disability, please call 1-888-336-0660.
#LI-Hybrid
#LI-AH1
You'll have...
- Bachelor's degree in computer science, cybersecurity, engineering, information systems, or a related technical field, OR a combination of education and equivalent practical experience.
- 5 years of experience across the following areas:
- Hands-on experience building and operating GCP-hosted CI/CD pipelines, including Tekton tasks, Tekton pipelines, pipeline triggers, workload identity or service account usage, secrets handling, and deployment promotion workflows.
- Proficiency developing Agentic capabilities using generative AI, LLMs, RAG, agent skills, tool orchestration, MCP-style integrations, evaluation patterns, and guardrails for secure operational use.
- Strong Python programming skills, including REST API integration, structured data handling, automation, unit testing, error handling, and production support practices.
- Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats, identity compromise, vulnerability management, detection logic, and incident response workflows.
Even better, you may have...
- 2+ years security engineering experience.
- Experience with Google SecOps, YARA-L or similar detection languages, and security case management workflows.
- Familiarity with Gemini Enterprise Agent Platform concepts, Agent Runtime, Agent Registry, Skills Registry, Model Armor, Agent Gateway, Memory Bank, delegated identity, and secure tool execution patterns.
- Sound understanding of cloud, TCP/IP, networking, endpoint, identity, logging, and data pipeline concepts.
- Demonstrated independent initiative, strong ownership, quality methods, teamwork, sound judgment, and high integrity.
You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder...or all of the above? No matter what you choose, we offer a work life that works for you, including:
- Immediate medical, dental, vision and prescription drug coverage
- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
- Vehicle discount program for employees and family members and management leases
- Tuition assistance
- Established and active employee resource groups
- Paid time off for individual and team community service
- A generous schedule of paid holidays, including the week between Christmas and New Year's Day
- Paid time off and the option to purchase additional vacation time.
For a detailed look at our benefits, click here: https://fordcareers.co/GSR
*Note: This is a hybrid role, you are expected to relocate if you are not within commutable distance, and responsible to be on site 4 days a week
This position is a range of salary grade(s) 7-8 | $99,600 - $192,900
Visa sponsorship is not available for this position.
Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.
We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, if you need a reasonable accommodation for the online application process due to a disability, please call 1-888-336-0660.
#LI-Hybrid
#LI-AH1
What you’ll do...
- Create, enhance, tune, test, and operationalize curated and custom detections across Google SecOps SIEM/SOAR, EDR, cloud, identity, and application telemetry sources.
- Build Python-based SOAR orchestration and integrations that enrich cases, normalize security data, execute response actions, and connect security platforms through REST APIs and event-driven workflows.
- Engineer Agentic SOC capabilities, including agent skills, agent-to-tool orchestration, RAG-based security workflows, MCP tool integrations, prompt and response guardrails, and human-in-the-loop approval patterns.
- Apply secure software development practices, code review, infrastructure-as-code, secrets management, least-privilege access, audit logging, and production readiness standards to detection engineering and Agentic SOC delivery.
What Ford Motor Company employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Ford Motor Company
Sourced by ZipRecruiter
Industry
Motor vehicle manufacturing and trucking
Company size
10,000+ Employees
Headquarters location
Dearborn, MI, US