Cyber Automation Analyst - Security Operations Center
Listed on 2026-08-31
-
Software Development
AI Engineer (Applied/Software)
Cyber Defense Detection Engineer
We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we're all a part of something bigger than ourselves. Are you ready to change the way the world moves?
Enterprise Technology plays a critical part in shaping the future of mobility. If you're looking for the chance to leverage advanced technology to redefine the transportation landscape, enhance the customer experience and improve people's lives, this is the opportunity for you. Join us and challenge your IT expertise and analytical skills to help create vehicles that are as smart as you are.
This role will be focused on advancing Ford's Cyber Defense Center (CDC) detection engineering, automation, and Agentic SOC capabilities within the Office of the Chief Enterprise Technology Officer (CETO) organization. The CDC mission is to provide proactive and reactive security services to protect Ford Motor Company global digital information assets from compromise. The Detection Engineer will design, build, test, and maintain high-fidelity detections and security automations across SIEM, SOAR, EDR, cloud, identity, and AI-enabled security platforms.
This position requires hands-on expertise in Google Sec Ops, GCP-hosted CI/CD pipelines, Tekton-based delivery workflows, Python automation, and secure Agentic SOC development using modern generative AI patterns.
Successful candidates must bring deep cyber defense experience and strong software engineering discipline. The candidate should be able to translate attacker behaviors, cloud telemetry, endpoint signals, identity events, and SOC case history into durable detection logic and automated response workflows. This role also requires the ability to develop, validate, and deploy AI-assisted SOC capabilities, including agent skills, retrieval-augmented workflows, Model Context Protocol integrations, secure prompt and tool governance, and human-in-the-loop guardrails for production security operations.
Candidates must be willing to work a hybrid work pattern, with a currently limited in-office schedule in the southeast Michigan metro area 4 days in-person/week.
ResponsibilitiesWhat you'll do...
- Create, enhance, tune, test, and operationalize curated and custom detections across Google Sec Ops SIEM/SOAR, EDR, cloud, identity, and application telemetry sources.
- Build Python-based SOAR orchestration and integrations that enrich cases, normalize security data, execute response actions, and connect security platforms through REST APIs and event-driven workflows.
- Engineer Agentic SOC capabilities, including agent skills, agent-to-tool orchestration, RAG-based security workflows, MCP tool integrations, prompt and response guardrails, and human-in-the-loop approval patterns.
- Apply secure software development practices, code review, infrastructure-as-code, secrets management, least-privilege access, audit logging, and production readiness standards to detection engineering and Agentic SOC delivery.
You'll have...
- Bachelor's degree in computer science, cybersecurity, engineering, information systems, or a related technical field, OR a combination of education and equivalent practical experience.
- 5 years of experience across the following areas:
- Hands-on detection engineering experience creating, tuning, testing, and deploying production security detections in SIEM or security analytics platforms, with preference for Google Sec Ops.
- Hands-on experience building and operating GCP-hosted CI/CD pipelines, including Tekton tasks, Tekton pipelines, pipeline triggers, workload identity or service account usage, secrets handling, and deployment promotion workflows.
- Proficiency developing AI-assisted or Agentic SOC capabilities using generative AI, LLMs, RAG, agent skills, tool orchestration, MCP-style integrations, evaluation patterns, and guardrails for secure operational use.
- Strong Python programming skills, including REST API integration, structured data handling, automation, unit testing, error handling, and production support practices.
- Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats, identity compromise, vulnerability management, detection logic, and incident response workflows.
Even better, you may have...
- 2+ years security engineering experience.
- Experience with Google Sec Ops, YARA-L or similar detection languages, and security case management workflows.
- Familiarity with Gemini Enterprise Agent Platform concepts, Agent Runtime, Agent Registry, Skills Registry, Model Armor, Agent Gateway, Memory Bank, delegated identity, and secure tool execution patterns.
- Sound understanding of cloud, TCP/IP, networking, endpoint, identity, logging, and data pipeline concepts.
- Demonstrated independent initiative, strong ownership, quality methods, teamwork, sound judgment, and high integrity.
You may not check every box, or your experience may look a little different from what…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).