Cyber Automation Analyst - Security Operations Center
Ford Global Career Site · Dearborn, MI, United States
About The Role
We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we’re all a part of something bigger than ourselves. Are you ready to change the way the world moves?
Enterprise Technology plays a critical part in shaping the future of mobility. If you’re looking for the chance to leverage advanced technology to redefine the transportation landscape, enhance the customer experience and improve people’s lives, this is the opportunity for you. Join us and challenge your IT expertise and analytical skills to help create vehicles that are as smart as you are.
This role will be focused on advancing Ford’s Cyber Defense Center (CDC) detection engineering, automation, and Agentic SOC capabilities within the Office of the CETO organization. The CDC mission is to provide proactive and reactive security services to protect Ford Motor Company global digital information assets from compromise. The Detection Engineer will design, build, test, and maintain high-fidelity detections and security automations across SIEM, SOAR, EDR, cloud, identity, and AI-enabled security platforms. This position requires hands-on expertise in Google SecOps, GCP-hosted CI/CD pipelines, Tekton-based delivery workflows, Python automation, and secure Agentic SOC development using modern generative AI patterns.
Successful candidates must bring deep cyber defense experience and strong software engineering discipline. The candidate should be able to translate attacker behaviors, cloud telemetry, endpoint signals, identity events, and SOC case history into durable detection logic and automated response workflows. This role also requires the ability to develop, validate, and deploy AI-assisted SOC capabilities, including agent skills, retrieval-augmented workflows, Model Context Protocol integrations, secure prompt and tool governance, and human-in-the-loop guardrails for production security operations.
Candidates must be willing to work a Hybrid work pattern, with a currently limited in-office schedule in the southeast Michigan metro area 4 days in-person/week.
What you’ll do...
- Create, enhance, tune, test, and operationalize curated and custom detections across Google SecOps SIEM/SOAR, EDR, cloud, identity, and application telemetry sources.
- Build Python-based SOAR orchestration and integrations that enrich cases, normalize security data, execute response actions, and connect security platforms through REST APIs and event-driven workflows.
- Engineer Agentic SOC capabilities, including agent skills, agent-to-tool orchestration, RAG-based security workflows, MCP tool integrations, prompt and response guardrails, and human-in-the-loop approval patterns.
- Apply secure software development practices, code review, infrastructure-as-code, secrets management, least-privilege access, audit logging, and production readiness standards to detection engineering and Agentic SOC delivery.
You’ll have...
- Bachelor’s degree in computer science, cybersecurity, engineering, information systems, or a related technical field, OR a combination of education and equivalent practical experience.
- 5 years of experience across the following areas:
- Hands-on detection engineering experience creating, tuning, testing, and deploying production security detections in SIEM or security analytics platforms, with preference for Google SecOps.
- Hands-on experience building and operating GCP-hosted CI/CD pipelines, including Tekton tasks, Tekton pipelines, pipeline triggers, workload identity or service account usage, secrets handling, and deployment promotion workflows.
- Proficiency developing AI-assisted or Agentic SOC capabilities using generative AI, LLMs, RAG, agent skills, tool orchestration, MCP-style integrations, evaluation patterns, and guardrails for secure operational use.
- Strong Python programming skills, including REST API integration, structured data handling, automation, unit testing, error handling, and production support practices.
- Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats, identity compromise, vulnerability management, detection logic, and incident response workflows.
Even better, you may have...
- 2+ years security engineering experience.
- Experience with Google SecOps, YARA-L or similar detection languages, and security case management workflows.
- Familiarity with Gemini Enterprise Agent Platform concepts, Agent Runtime, Agent Registry, Skills Registry, Model Armor, Agent Gateway, Memory Bank, delegated identity, and secure tool execution patterns.
- Sound understanding of cloud, TCP/IP, networking, endpoint, identity, logging, and data pipeline concepts.
- Demonstrated independent initiative, strong ownership, quality methods, teamwork, sound judgment, and high integrity.
You may not check every box, or your experience may look a little different from what we’ve outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder…or all of the above? No matter what you choose, we offer a work life that works for you, including:
- Immediate medical, dental, vision and prescription drug coverage
- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
- Vehicle discount program for employees and family members and management leases
- Tuition assistance
- Established and active employee resource groups
- Paid time off for individual and team community service
- A generous schedule of paid holidays, including the week between Christmas and New Year’s Day
- Paid time off and the option to purchase additional vacation time.
For a detailed look at our benefits, click here: https://fordcareers.co/GSR
*Note: This is a hybrid role, you are expected to relocate if you are not within commutable distance, and responsible to be on site 4 days a week
This position is a range of salary grade(s) 7-8 | $99,600 - $192,900
Visa sponsorship is not available for this position.
Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.
We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, if you need a reasonable accommodation for the online application process due to a disability, please call 1-888-336-0660.
#LI-Hybrid
#LI-AH1
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
