Quick Overview
Job Description
Note:
- Someone with connected vehicle experience/embedded background will really stand out above basic experienced candidates
- 4 days a week onsite
- LOCAL candidates will likely get an offer/submitted first. Local meaning they have jobs here at clients that are know. Yes relocation is fine but again not likely to be hired. All candidates must be here day 1
Location: Dearborn, MI (4 days onsite, 1 remote)
Duration: ongoing long term
Interview Mode: Generally remote
Must provide: last 4 of SSN, all degree info
Cyber Threat Management Senior Associate #1065490
Position Description:
This role within the Vehicle and Connected Cybersecurity organization is responsible for hands-on operational monitoring and incident response for connected vehicle and cloud environments. As part of the Product Security Operations Center (PSOC) team, you will triage alerts, support investigations, and help drive timely resolution across vehicle telematics, embedded systems, and cloud-native application stacks. This role contributes directly to our continuous cybersecurity monitoring capability for connected vehicles and the cloud services that support them. Reporting to the Manager of Monitoring Operations, this role focuses on alert triage, incident support, and continuous improvement of monitoring processes. We are seeking candidates with a solid cybersecurity foundation, including API security experience, along with embedded-vehicle exposure or a demonstrated aptitude and eagerness to learn. You will partner with cloud, vehicle, enterprise, incident-response, and global PSOC teams to help ensure effective investigation and resolution of security events affecting connected vehicles and the cloud services that power them.
Skills Required:
· Cyber Security, API, Information Security
Experience Required:
· Senior Associate Exp: 3 to 5 years' experience in relevant field- Bachelor’s degree in Computer Science, Cybersecurity, or Engineering, or related field.
· 2+ years in cybersecurity, security operations, or a related technical field. Working understanding of incident response lifecycles, escalation, and incident management practices.
· Experience with API security and exposure to cloud security operations on one or more major cloud platforms, including logging, monitoring, identity, and response workflows.
· Embedded vehicle cybersecurity exposure, or a demonstrated aptitude and eagerness to learn.
· Ability to work effectively in a fast-paced 24x7 operations environment, including shift-based coverage.
· Clear written and verbal communication for documenting incidents and coordinating with technical team
Experience Preferred:
· Exposure to detecting and investigating threats across cloud and vehicle telemetry data, including log correlation and alert tuning.
· Experience using/refining runbooks, playbooks, and escalation procedures in an operations setting.
· Relevant certifications such as Security+, GIAC, or foundational cloud security certifications across AWS, Azure, or Google Cloud Platform. Familiarity with embedded or automotive environments and the security considerations of cloud architecture.
· Ability to turn recurring incidents into process or detection improvement suggestions
Education Required:
· Bachelor's Degree
Education Preferred:
· Certification Program
Additional Information:
· Responsibilities Operational Monitoring and Incident Response: Perform daily PSOC alert triage and support incident coordination, containment, remediation, recovery, and closure.
· Cloud & Embedded Investigation and Resolution: Support investigations of security events across cloud application stacks and embedded vehicle architectures using available logging and telemetry.
· Global PSOC Collaboration and Continuity: Partner with PSOC teams across regions to deliver consistent monitoring, investigation, and incident-response services; maintain effective continuity and handoffs for active security events.
· Operational Improvement and Feedback Loop: Surface operational friction points and provide feedback to help improve detection logic, tooling, and response workflows.
· Cross-Functional Partnership: Collaborate closely with the Cyber Incident Response Team (CIRT), Product Development, and Enterprise IT to execute response playbooks and coordinate complex mitigations.
Similar jobs
- MR
Sr. Developer - Web
NewMotion Recruitment Partners, LLC
Atlanta, GA🇺🇸HybridYesterdayMicroservicesAPI GatewayAWS+8Technology - IS
Azure Architect
NewInternational Solutions Group
United States🇺🇸HybridYesterdayDockerAzureKubernetes+2Technology - MA
Lead AI Engineer - Data Science and Algorithms
NewMaximus, Inc.
United States🇺🇸$180k - $200k/yrRemoteYesterdayRustAWSMachine Learning+5Technology - MR
Data Engineer (Snowflake / dbt / Fivetran)
NewMotion Recruitment Partners, LLC
Addison, TX🇺🇸HybridYesterdaySnowflakeAzureData Pipeline+2Technology - RI
Python/Gen AI Developer
NewRose International
Tampa, FL🇺🇸RemoteYesterdayDockerAWSMLOps+11Technology - LT
Senior Microsoft Fabric Integration Developer
NewLedgent Technology
Houston, TX🇺🇸$70 - $85/hrHybridYesterdaySQLSQL ServerAWS+8Technology