This role within the Cybersecurity organization is responsible for hands‑on operational monitoring and incident response for connected vehicle and cloud environments. As part of the team, you will triage alerts, support investigations, and help drive timely resolution across vehicle telematics, embedded systems, and cloud‑native application stacks. This role contributes directly to continuous cybersecurity monitoring capability for connected vehicles and the cloud services that support them. Reporting to the Manager of Monitoring Operations, this role focuses on alert triage, incident support, and continuous improvement of monitoring processes. We are seeking candidates with a solid cybersecurity foundation, including API security experience, along with embedded‑vehicle exposure or a demonstrated aptitude and eagerness to learn. You will partner with cloud, vehicle, enterprise, incident‑response, and global PSOC teams to help ensure effective investigation and resolution of security events affecting connected vehicles and the cloud services that power them.
Responsibilities
- Operational Monitoring and Incident Response: Perform daily PSOC alert triage and support incident coordination, containment, remediation, recovery, and closure.
- Cloud & Embedded Investigation and Resolution: Support investigations of security events across cloud application stacks and embedded vehicle architectures using available logging and telemetry.
- Global PSOC Collaboration and Continuity: Partner with PSOC teams across regions to deliver consistent monitoring, investigation, and incident‑response services; maintain effective continuity and handoffs for active security events. Operational Improvement and Feedback Loop: Surface operational friction points and provide feedback to help improve detection logic, tooling, and response workflows.
- Cross‑Functional Partnership: Collaborate closely with the Cyber Incident Response Team (CIRT), Product Development, and Enterprise IT to execute response playbooks and coordinate complex mitigations.
Experience Required
- 3 to 5 years' experience in Cyber Security, API, Information Security
- 2+ years in cybersecurity, security operations, or a related technical field.
- Working understanding of incident response lifecycles, escalation, and incident management practices.
- Experience with API security and exposure to cloud security operations on one or more major cloud platforms, including logging, monitoring, identity, and response workflows.
- Embedded vehicle cybersecurity exposure, or a demonstrated aptitude and eagerness to learn.
- Ability to work effectively in a fast‑paced 24x7 operations environment, including shift‑based coverage.
- Clear written and verbal communication for documenting incidents and coordinating with technical team
Experience Preferred
- Exposure to detecting and investigating threats across cloud and vehicle telemetry data, including log correlation and alert tuning.
- Experience using/refining runbooks, playbooks, and escalation procedures in an operations setting.
- Familiarity with embedded or automotive environments and the security considerations of cloud architecture.
- Ability to turn recurring incidents into process or detection improvement suggestions
Education Required
- Bachelor's degree in computer science, Cybersecurity, Engineering, or related field.
Education Preferred
- Certification Program - Relevant certifications such as Security+, GIAC, or foundational cloud security certifications across AWS, Azure, or GCP.
Listed salary ranges may vary based on experience, qualifications, and local market. Also, some positions may include bonuses or other incentives***