Lead Cybersecurity Detection Engineer

ITSMF

Atlanta (GA)

On-site

USD 150,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) plan
Paid time off

Job summary

Cox Automotive is seeking an experienced Lead Cybersecurity Engineer to drive Detection Engineering across our automotive solutions portfolio. You will design, build, and maintain advanced detection capabilities, mentor engineers, and collaborate with Incident Response, Threat Intelligence, and Vulnerability Management to strengthen detection coverage.

The ideal candidate will have expert hands-on SIEM and log ingestion expertise, strong communication, and a track record of raising the technical

Qualifications

  • Bachelor's degree in Computer Science or related field; 6+ years industry experience.
  • Multi-cloud security experience (AWS, Azure, GCP).
  • Experience with AI/ML frameworks for security applications.
  • Expert-level knowledge of Detection Engineering.
  • Strong experience in information security, network security, monitoring, and IR.

Responsibilities

  • Serve as a senior technical lead for detection engineering and build detective solutions.
  • Contribute to and execute the Detection Engineering strategy and roadmap.
  • Architect and deploy AI systems to detect, analyze, and respond to threats.
  • Design multi-agent frameworks for threat hunting and incident investigation.
  • Develop self-improving detection rules and playbooks.
  • Implement detection techniques using SIEM, EDR, and SOAR platforms.
  • Create custom detection rules and automated remediation playbooks.
  • Use MITRE/ATLAS to map coverage and close gaps.
  • Monitor and optimize detection systems for performance and scale.
  • Collaborate with Threat Detection and Response to improve capabilities.
  • Perform attack simulations to validate use cases.
  • Conduct purple-teaming with Vulnerability Management.
  • Manage SIEM/Data Lake data ingestion infrastructure.
  • Evaluate, tune, and sunset detections as needed.
  • Document detection use cases and configurations.
  • Provide off-hours support for security ops.

Skills

Multi-cloud security
AI/ML for security
Detection engineering
SIEM/SOAR
Incident response
Threat intelligence
Leadership
Communication
Python

Education

Bachelor's degree in CS or related field

Tools

SIEM/SOAR platforms
EDR
Data Lake

Job description

Cox Automotive is seeking an experienced Lead Cybersecurity Engineer to serve as a senior technical voice on our Detection Engineering team, supporting next-generation Cyber Defense across our diverse portfolio of automotive solutions including Dealertrack, Manheim, Autotrader, Kelley Blue Book, Central Dispatch, and vAuto.

Reporting to the Director of Cyber Detection Engineering, you'll design, build, and maintain advanced enterprise- and customer-focused detection capabilities - including AI-driven detection agents and automation - while providing hands‑on technical leadership and mentorship to other engineers on the team. You'll partner closely with Incident Response, Threat Intelligence, and Vulnerability Management to strengthen detection coverage, with visibility into detection needs across multiple Cox Automotive business units. The ideal candidate will possess expert‑level, hands‑on knowledge in SIEM implementation and log ingestion, Detection Engineering best practices, Incident Response, and Threat Intelligence, along with strong verbal and written communication skills and a track record of raising the technical bar for engineers around them.

What You'll Do
Cybersecurity Detection Engineering:
  • Serve as a senior technical lead for detection engineering, building and maintaining detective solutions that protect Cox Automotive’s internal systems as well as its domestic and international businesses.
  • Contribute to and help execute the Detection Engineering strategy, roadmap, and objectives.
  • Architect and deploy agentic AI systems that autonomously detect, analyze, and respond to security threats across enterprise infrastructure.
  • Design multi-agent frameworks where specialized AI agents collaborate on threat hunting, incident investigation, and attack pattern recognition.
  • Develop self‑improving detection systems that learn from each investigation and automatically enhance detection rules and playbooks.
  • Design and implement advanced threat detection techniques using tools such as SIEM, EDR, and SOAR platforms.
  • Develop innovative custom detection rules and automated remediation playbooks and alerts tailored to the Cox Automotive’s enterprise and customer threat landscape.
  • Leverage industry standard MITRE/ATLAS frameworks to identify detection coverage and close gaps.
  • Monitor, optimize, and continuously improve detection systems for performance, scalability, and effectiveness.
  • Collaborate with Threat Detection and Response team to continuously improve cybersecurity capabilities in identification, management, and response to threats in the most efficient and effective manner.
  • Perform attack simulation testing to validate efficacy of use cases.
  • Conduct purple teaming exercises in collaboration with the Vulnerability Management team.
  • Manage and maintain SIEM/Data Lake data management and log ingestion infrastructure in collaboration with Cyber Defense Engineering counterparts.
  • Evaluate, validate, tune, and sunset detections as needed.
  • Build and maintain operational guidelines, diagrams, and documentation for security detection and response.
  • Provide off‑hour support as needed for security administration, detection, and response activities.
Incident Response:
  • Collaborate with the Incident Response team to ensure rapid detection and containment of cyber threats.
  • Build threat detection logic during incident response to accelerate threat identification and containment.
  • Continuously improve detection and response processes based on lessons learned from incidents.
Threat Intelligence Integration:
  • Leverage threat intelligence to enhance detection capabilities and proactively mitigate risks.
  • Identify and analyze new and emerging threat vectors and incorporate them into detection strategies.
Stakeholder Collaboration:
  • Partner with other Cybersecurity, Engineering, and Product teams to ensure successful deployment of detection and response solutions.
  • Collaborate with Product teams to design and implement new customer‑focused detection and response solutions.
  • Communicate detection capabilities, findings, and technical recommendations clearly to technical and non-technical stakeholders, escalating to leadership as needed.
Governance and Compliance:
  • Design and implement processes that adhere to regulatory requirements and industry standards (e.g., GDPR, PCI‑DSS, NIST).
  • Maintain documentation of detection use cases, processes, and configurations.
Who You Are
Minimum Qualifications
  • Bachelor’s degree in Computer Science or a related discipline and 6+ years of industry related professional experience
  • Multi‑cloud security experience (AWS, Azure, GCP)
  • Experience with AI/ML frameworks and prompt engineering for security applications
  • Expert level knowledge of Detection Engineering
  • Strong experience with information security, network security, security monitoring, and Incident Response.
  • Strong experience with developing SIEM/SOAR detection and automation use cases.
  • Working experience with industry standard security technologies and services such as threat intelligence, firewalls, SASE, IPS, endpoint security, DLP, SIEM/SOAR, and Data Lakes.
  • Expert level knowledge on the attack kill chain and diamond model.
  • 3+ years experience in a cyber defense role
Preferred Qualifications
  • OSCP, GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA certification(s)
  • Dev Ops / Engineering / Network / System Administration experience
  • Experience developing customer‑focused detection and response systems
About Cox

Cox empowers employees to build a better future and has been doing so for over 120 years. With exciting investments and innovations across transportation, communications, cleantech and healthcare, our family of businesses – which includes Cox Automotive and Cox Communications – is forging a better future for us all. Ready to make your mark? Join us today!

Benefits of working at Cox may include health care insurance (medical, dental, vision), retirement planning (401(k)), and paid days off (sick leave, parental leave, flexible vacation/wellness days, and/or PTO). For more details on what benefits you may be offered, visit our benefits page.

Cox is an Equal Employment Opportunity employer - All qualified applicants/employees will receive consideration for employment without regard to that individual’s age, race, color, religion or creed, national origin or ancestry, sex (including pregnancy), sexual orientation, gender, gender identity, physical or mental disability, veteran status, genetic information, ethnicity, citizenship, or any other characteristic protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Cybersecurity Detection Engineer
Lead Cybersecurity Detection Engineer

cox • Atlanta (GA)

Hybrid
USD 123,000 - 204,000
Incentive program
Hybrid work arrangement
Lead Cybersecurity Detection Engineer
Lead Cybersecurity Detection Engineer

Cox Enterprises • Atlanta (GA)

On-site
USD 150,000 - 190,000
Lead Cybersecurity Detection Engineer
Lead Cybersecurity Detection Engineer

CAI Cox Automotive Corp Svcs., LLC • Atlanta (GA)

Hybrid
USD 123,000 - 204,000
Health insurance
401(k) retirement plan
Paid time off
Lead Cybersecurity Detection Engineer
Lead Cybersecurity Detection Engineer

Cybersecurity Jobs • Atlanta (GA)

On-site
USD 150,000 - 230,000
Health care insurance (medical, dental
Retirement planning (401(k))
Paid days off (sick leave, parental, (
Senior Cybersecurity Manager
Senior Cybersecurity Manager

Amtex Systems Inc • Atlanta (GA)

On-site
USD 120,000 - 150,000
Senior Cyber Defense & Detection Engineer
Senior Cyber Defense & Detection Engineer

cox • Atlanta (GA)

Hybrid
USD 123,000 - 204,000
Incentive program
Hybrid work arrangement
Lead AI-Driven Cybersecurity Detection Engineer
Lead AI-Driven Cybersecurity Detection Engineer

CAI Cox Automotive Corp Svcs., LLC • Atlanta (GA)

Hybrid
USD 123,000 - 204,000
Health insurance
401(k) retirement plan
Paid time off
Senior Detection Engineer — AI-Driven Cyber Defense
Senior Detection Engineer — AI-Driven Cyber Defense

ITSMF • Atlanta (GA)

On-site
USD 150,000 - 190,000
Health insurance
401(k) plan
Paid time off
Lead AI-Driven Cybersecurity Detection Engineer
Lead AI-Driven Cybersecurity Detection Engineer

Cybersecurity Jobs • Atlanta (GA)

On-site
USD 150,000 - 230,000
Health care insurance (medical, dental
Retirement planning (401(k))
Paid days off (sick leave, parental, (
Senior Systems Engineer
Senior Systems Engineer

Cox • Atlanta (GA)

On-site
USD 92,000 - 154,000
Hybrid work model
Health insurance
Paid time off