Cyber Threat Management Senior Associate
Location: Allen Park, MI (Fairlane Business Park III)
Work Model: Shift-based 24x7 Operations Environment
Position Overview
Client is seeking a Cyber Threat Management Senior Associate to join its Product Security Operations Center (PSOC). This role is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats affecting connected vehicles, cloud services, APIs, and embedded automotive systems.
The ideal candidate will have experience in Security Operations Center (SOC) environments, incident response, cloud security operations, and API security. This position plays a key role in protecting Ford's connected vehicle ecosystem by analyzing security events, coordinating response activities, and improving detection capabilities across the enterprise.
Key Responsibilities
- Monitor and triage security alerts generated through PSOC monitoring tools.
- Investigate cybersecurity incidents across cloud applications, APIs, vehicle telemetry, and embedded systems.
- Support the full incident response lifecycle, including identification, containment, eradication, recovery, and closure.
- Analyze logs, alerts, and telemetry data to identify potential threats and malicious activity.
- Collaborate with Cyber Incident Response Teams (CIRT), Product Security, Cloud Engineering, and Enterprise IT teams.
- Escalate and coordinate security incidents according to established procedures and response playbooks.
- Conduct root cause analysis and document investigation findings.
- Contribute to the development and enhancement of security monitoring and detection capabilities.
- Assist with alert tuning, threat detection optimization, and operational process improvements.
- Coordinate incident handoffs with global PSOC teams to ensure seamless 24x7 coverage.
- Maintain accurate incident documentation and communicate findings to technical stakeholders.
Required Qualifications
Education
- Bachelor's Degree in Computer Science, Cybersecurity, Information Security, Engineering, or a related discipline.
Experience
- 3-5 years of cybersecurity, security operations, or incident response experience.
- At least 2 years of hands-on SOC or cybersecurity operations experience.
- Experience supporting and coordinating security incidents throughout the response lifecycle.
- Experience investigating security alerts and performing threat triage.
- Experience with API security concepts and security monitoring.
- Exposure to cloud security operations within AWS, Azure, or Google Cloud Platform (GCP).
- Ability to work in a fast-paced, shift-based 24x7 operational environment.
Required Technical Skills
- Cybersecurity Operations
- Security Operations Center (SOC)
- API Security
- Cloud Security Operations
- Identity & Access Management (IAM)
- Security Event Analysis
- SIEM Technologies
- Security Documentation & Reporting
Preferred Qualifications
- Experience investigating threats across cloud environments and connected devices.
- Knowledge of vehicle cybersecurity, embedded systems security, or IoT security.
- Experience working with SIEM and SOAR platforms such as:
- Splunk
- QRadar
- Google SecOps
- LogRhythm
- Experience developing or improving runbooks and response playbooks.
- Familiarity with MITRE ATT&CK framework.
- Understanding of automotive cybersecurity concepts and standards:
- ISO/SAE 21434
- UNECE R155
- Experience with alert tuning and detection engineering.
- Security certifications such as:
- Security+
- CySA+
- GIAC Certifications
- AWS Security Specialty
- Azure Security Engineer (AZ-500)
- Google Cloud Security Engineer
Ideal Candidate Profile
The successful candidate will be a SOC Analyst, Security Operations Analyst, Incident Response Analyst, or Cloud Security Analyst with strong experience investigating security incidents and monitoring enterprise environments.
Candidates with experience in API security, cloud security operations, SIEM monitoring, and threat detection will be highly preferred. Automotive cybersecurity experience is a plus but not mandatory. Individuals who demonstrate a strong willingness to learn connected vehicle security and embedded systems will also be considered.
Target Candidate Titles
- SOC Analyst II / III
- Security Operations Analyst
- Cybersecurity Analyst
- Cyber Defense Analyst
- Cloud Security Analyst
- Product Security Analyst
- Detection & Response Analyst
- Security Monitoring Analyst
- API Security Analyst
- Automotive Cybersecurity Analyst
- Security Engineer (Operations)
Cyber Threat Management Senior Associate
Job Number: 331986
Location: Allen Park, MI (Fairlane Business Park III)
Pay Rate: $48 - $58/hour W2
Client: Ford Motor Company
Work Schedule: Shift-based 24x7 Operations Coverage
Position Overview
Ford Motor Company is seeking a Cyber Threat Management Senior Associate to join its Product Security Operations Center (PSOC). This role is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats impacting connected vehicles, cloud-based services, APIs, and embedded automotive systems.
The ideal candidate will have hands‑on experience in Security Operations (SOC), Incident Response, Threat Detection, Cloud Security Operations, and API Security. This position will work closely with Product Security, Cloud Engineering, Enterprise IT, Vehicle Security, and Cyber Incident Response teams to protect Ford's connected vehicle ecosystem.
Key Responsibilities
- Monitor, analyze, and triage security alerts generated from PSOC monitoring tools.
- Investigate cybersecurity incidents across cloud platforms, APIs, vehicle telemetry, and embedded systems.
- Support the complete incident response lifecycle, including:
- Identification
- Containment
- Remediation
- Recovery
- Closure
- Analyze logs, alerts, and telemetry data to identify malicious activity and security threats.
- Coordinate investigations with Cyber Incident Response Teams (CIRT), Product Security, Cloud Security, and Enterprise IT teams.
- Escalate incidents and coordinate mitigation activities when required.
- Document investigations, findings, root cause analysis, and remediation activities.
- Improve detection logic, security monitoring processes, and alerting capabilities.
- Participate in shift-based monitoring and ensure seamless handoff between global PSOC teams.
- Assist with development and refinement of security runbooks and response playbooks.
Required Qualifications
Education
- Bachelor's Degree in:
- Cybersecurity
- Computer Science
- Information Security
- Related Technical Discipline
Experience
- 3-5 years of cybersecurity experience.
- Minimum 2 years of Security Operations, SOC, or Incident Response experience.
- Experience managing security incidents throughout the incident response lifecycle.
- Strong understanding of threat detection and alert triage.
- Experience with API Security.
- Exposure to cloud security operations.
- Experience investigating security events and analyzing logs.
- Ability to work in a fast-paced 24x7 operational environment.
Required Technical Skills
- Security Operations Center (SOC)
- Cybersecurity Operations
- Security Event Analysis
- API Security
- Cloud Security Operations
- Identity & Access Management (IAM)
- Security Documentation
- Security Monitoring
Preferred Qualifications
- Experience with SIEM and SOAR Platforms:
- Splunk
- Microsoft Sentinel
- QRadar
- LogRhythm
- Google SecOps
- CrowdStrike SIEM
- Familiarity with:
- MITRE ATT&CK Framework
- Threat Hunting
- Detection Engineering
- Alert Tuning
- Automotive cybersecurity knowledge.
- Embedded systems security experience.
- Connected vehicle security exposure.
- Experience with vehicle telemetry monitoring.