Remotery

Cybersecurity Threat Detection – Automation Manager

Posted 9 hours ago

This is a fully remote position, open to applicants in Alabama, +45 more states.

📋 Description

• Lead, manage, mentor, and nurture a team of professionals in detection engineering and automation.

• Define and implement a threat detection and automation strategy that aligns with business risks, threats, compliance, and organizational priorities.

• Establish processes for intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement.

• Design, develop, fine-tune, and optimize threat detections across various platforms including SIEM, EDR, identity, cloud, email, network, OT, SaaS, and others.

• Own high-impact detections for complex use cases, critical risks, advanced adversary behaviors, and enterprise threats.

• Translate adversary behavior, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk into actionable analytics.

• Conduct analyses to identify detection gaps and perform threat modeling.

• Create detection validation practices that include test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback.

• Lead detection and response workflows using SIEM and SOAR.

• Develop SIEM content such as correlation rules, notable events, dashboards, risk-based alerts, data models, investigation views, and alert enrichment.

• Create SOAR playbooks for enrichment, triage, evidence collection, case creation, containment recommendations, response actions, and analyst decision support.

• Identify and automate repetitive, high-volume, or high-value activities within the SOC.

• Drive integrations across platforms such as SIEM, SOAR, EDR, email security, identity, threat intelligence, ITSM, cloud, network, PAM, DLP/CASB, and OT.

• Build and enhance the detection and automation lifecycle from intake through retirement.

• Oversee the detection and automation roadmap along with program metrics.

• Address telemetry gaps, data quality issues, logging deficiencies, enrichment needs, and ambiguous ownership.

• Maintain documentation that is ready for audits and communicate strategy, risk coverage, maturity, roadmap, and outcomes to both technical and non-technical stakeholders, including executives.


⛳️ Requirements

• Over 10 years of experience in cybersecurity, specifically in SOC roles involving the creation of SIEM correlations/detections and automation of incident information enrichment tasks.

• Proven experience in building mature detection lifecycle practices, encompassing intake, prioritization, testing, tuning, monitoring, regression checks, peer review, and controlled releases.

• Experience in developing SOAR playbooks and automation workflows.

• Familiarity with detection-as-code, Git-based content management, CI/CD pipelines, automated testing, reusable detection templates, and scalable engineering patterns.

• Experience in operationalizing threat intelligence into detection priorities, hunting queries, enrichment workflows, and response playbooks.

• Skilled in designing detections for identity-based attacks, as well as for endpoint, email, network, cloud, SaaS, OT/ICS, DLP, and privileged access use cases.

• Experience working in large, complex enterprise or manufacturing settings.

• Collaborative experience with SOC, Incident Response, Threat Intelligence, Vulnerability Management, Cloud, Identity, Network, OT, Legal, Privacy, GRC, and IT teams.

• Ability to identify gaps in detection, telemetry, control, ownership, and response processes.

• Strong analytical and problem-solving abilities.

• Proven capability to lead, coach, and guide team members across diverse cultural, geographic, technical, and generational backgrounds.

• A strong passion for automation, continuous improvement, high-quality engineering practices, and scalable security systems.

• Technical proficiency with Splunk SPL, risk-based alerting, notable events, dashboards, correlation searches, SOAR, MITRE ATT&CK, Entra ID, EDR, CNAPP, DNS, proxy, firewall, VPN, GlobalProtect, OT/ICS, PAM, CyberArk-style telemetry, ITSM, Git, and CI/CD.

• A Master’s degree is preferred but not mandatory.


🏝️ Benefits

• Comprehensive health and wellness benefits.

• Opportunities for professional development and training.

• Flexible work arrangements and a supportive work environment.

• Competitive compensation package.

• Engaging company culture focused on innovation and collaboration.

People also viewed

Corteva Agriscience8 hours ago

Email Security Engineer

US flagIowa OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Fortive8 hours ago

Principal Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Corteva Agriscience10 hours ago

Email Security Engineer

US flagIowa OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Logically10 hours ago

Senior Engineer, Security Implementation

US flagOhio OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
FastSpring11 hours ago

Senior Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$155k – $187k/year
ApplyView job
Danaher Corporation11 hours ago

Director, Identity Security – Privileged Access Management

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$175k – $210k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers