# Cybersecurity Operations Manager, Ford Energy

**Company**: Ford Motor Company
**Location**: Dearborn, MI
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Salary**: $115,500-$218,100
**Category**: IT
**Industry**: Automotive
**Wikidata**: https://www.wikidata.org/wiki/Q44294

**Apply**: https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/70635?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_e9ced698-4cf

## Description

We are seeking a Cybersecurity Operations Manager to lead, operationalize, and modernize our global security monitoring and incident response capabilities.

## Responsibilities

- Hybrid Team Leadership: Direct, mentor, and manage a high-performing security operations team while overseeing performance, SLAs, escalation pathways, and day-to-day operations of external MSSP partners.

- Broad-Scope Security Operations: Lead 24/7 security monitoring, incident triage, and response capabilities covering Enterprise IT networks, Cloud platforms, Product/IoT telemetry, customer-facing portals and mobile/web applications, and Manufacturing/OT facilities.

- Customer-Facing Application Security Monitoring: Own security monitoring, threat detection, and incident response for customer-facing applications, portals, and APIs , including authentication systems and customer data pathways.

- Connected Platform Monitoring: Lead threat monitoring and security telemetry analysis for external-facing platforms and the connected infrastructure linking customer environments to Ford Energy's cloud and support systems.

- SOC Engineering & Detection Quality: Drive continuous optimization of SIEM/SOAR platforms, detection rules, threat hunting playbooks, and automated response workflows to decrease mean time to detect (MTTD) and mean time to respond (MTTR) across enterprise, product, and customer-facing systems.

- Incident Response Leadership: Act as the primary escalation lead and incident commander during complex cybersecurity incidents , including those impacting customer-facing services and applications , leading cross-functional containment, eradication, root-cause analysis, and customer communication efforts.

- Manufacturing & OT Security: Collaborate with plant operations and industrial control system (ICS) engineers to ensure real-time visibility, anomaly detection, and incident handling across manufacturing plants.

- Compliance & Regulatory Alignment: Support operational security logging, audit readiness, and incident response procedures aligned with applicable industry security frameworks and critical infrastructure requirements as needed.

- Operational Excellence & Metrics: Develop, track, and present operational security metrics, threat landscapes, customer application security posture, and SOC effectiveness KPIs to executive leadership and key business stakeholders.

- Availability: Serve as the senior operational contact and manage on-call escalation rotations for critical security incidents, including those affecting customer-facing platforms.

## Qualifications

- Experience: Minimum of 5–7 years of experience in Security Operations (SOC), Threat Intelligence, or Incident Response, with at least 3+ years in a supervisory, management, or technical lead role.

- Hybrid & MSSP Management: Demonstrated success managing vendor/MSSP contracts, driving service delivery SLAs, and leading combined teams of internal engineers and external contractor resources.

- Multi-Domain SOC Experience: Hands-on leadership experience running security operations that span enterprise IT, cloud infrastructure, customer-facing applications/platforms, and operational technology (OT) / industrial control systems (ICS).

- Application Security Awareness: Working knowledge of application security monitoring, web/API threat detection, and securing customer-facing digital platforms and portals.

- Regulatory Compliance: Proven understanding of ISO 27001, NIST SP 800-82, IEC 62443, or similar security frameworks relevant to connected products and critical infrastructure.

- Incident Management: Strong experience acting as an Incident Commander during major breach responses, cyber-attacks, or critical infrastructure outages.

- Education: Bachelor's or master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent related work experience.

## Benefits

- Immediate medical, dental, vision and prescription drug coverage

- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more

- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more

- Vehicle discount program for employees and family members and management leases

- Tuition assistance

- Established and active employee resource groups

- Paid time off for individual and team community service

- A generous schedule of paid holidays, including the week between Christmas and New Year’s Day

- Paid time off and the option to purchase additional vacation time.

## Skills

### Required
- Security Operations
- Threat Intelligence
- Incident Response
- Hybrid Team Leadership
- MSSP Management
- Multi-Domain SOC Experience
- Application Security Awareness
- Regulatory Compliance
- Incident Management

### Nice to have
- CISSP
- CISM
- GCIH
- GCFA
- GRID
- GICSP
- Microsoft Sentinel
- Defender XDR
- Palo Alto Networks

---

Source: [Apply at efds.fa.em5.oraclecloud.com](https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/70635?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
