설명
The Role
As a Senior Cyber Detection Incident Analyst, you will play a critical role in protecting General Motors' global enterprise by identifying, analyzing, and helping mitigate advanced cyber threats across cloud, identity, endpoint, network, application, and manufacturing ecosystems.
You will serve as a senior technical leader within the Cyber Detection organization, driving detection engineering initiatives, leading complex investigations, and continuously improving the technologies, analytics, and processes used to identify malicious activity. This role combines deep technical expertise, threat-focused analysis, and cross-functional collaboration to enhance GM's overall cybersecurity posture.
The ideal candidate possesses a passion for cyber defense, strong analytical and investigative skills, and experience developing scalable detection capabilities across modern enterprise environments.
What You'll Do
-
Lead advanced investigations involving complex security incidents, emerging threats, and high-severity escalations
-
Develop, implement, and optimize detection logic across SIEM, EDR, NDR, SOAR, cloud-native security platforms, and other security monitoring technologies
-
Conduct threat hunting activities to proactively identify adversary behaviors, attack techniques, and detection gaps
-
Apply threat intelligence, adversary tradecraft, and MITRE ATT&CK methodologies to improve detection coverage effectiveness
-
Design, tune, and validate analytics to reduce false positives and improve alert fidelity
-
Develop automation, enrichment workflows, and operational efficiencies using AI, scripting and security orchestration technologies
-
Partner with Incident Response, Threat Intelligence, Cloud Security, Product Security, Manufacturing Security, and other cybersecurity teams to improve detection capabilities
-
Mentor and provide technical guidance to analysts and detection engineers
-
Drive continuous improvement initiatives that increase visibility, reduce investigative effort, and improve operational effectiveness
-
Evaluate emerging technologies, AI capabilities, and security monitoring solutions to advance GM's detection maturity
Your Skills & Abilities (Required Qualifications)
-
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent practical experience
-
5+ years of experience in cybersecurity with a focus on detection engineering, security operations, incident response, threat hunting, intrusion detection, or security event analysis
-
Experience working with enterprise SIEM platforms and log-centric detection methodologies
-
Experience developing and tuning security detections using correlation logic, behavioral analytics, and threat intelligence
-
Strong understanding of endpoint security technologies and EDR platforms
-
Experience investigating security events across endpoint, network, cloud, identity, and application environments
-
Knowledge of attacker tactics, techniques, and procedures (TTPs) and familiarity with the MITRE ATT&CK framework
-
Experience using scripting and query languages such as Python, PowerShell, or similar technologies
-
Strong analytical, troubleshooting, and investigative skills
-
Experience communicating technical findings to both technical and non-technical audiences
-
Ability to lead investigations during cybersecurity incidents
-
Demonstrated ability to collaborate effectively across multiple teams and stakeholders
-
Ability and willingness to participate in a 24x7 on-call rotation
What Can Give You a Competitive Advantage (Preferred Qualifications)
-
Experience with cloud security monitoring and detection engineering in Azure, AWS, and GCP environments
-
Experience with SaaS security monitoring and identity threat detection
-
Experience with network security monitoring, IDS/IPS technologies, packet analysis, and network telemetry
-
Experience supporting manufacturing, operational technology (OT), or industrial control system environments
-
Experience with vehicle cybersecurity, automotive architectures, or embedded security telemetry
-
Experience with application security monitoring, API security, runtime protection, and CI/CD security telemetry
-
Experience with malware analysis, reverse engineering, or digital forensics
-
Experience developing SOAR workflows and security automation solutions
-
Security certifications such as GCIA, GCIH, GCFA, GCDA, AWS Security Specialty, or equivalent
-
Proven ability to mentor, coach, and develop cybersecurity professionals
-
Demonstrated success leading technical initiatives and influencing cybersecurity strategy
-
Strong written and verbal communication skills
-
Continuous learning mindset with a passion for innovation and cybersecurity excellence
#LI-SB3
GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc.)
이 직무는 하이브리드 직무로 분류됩니다. 즉, 선발된 지원자는 특정 근무지로 주 3일 이상(또는 관리자가 지정한 다른 빈도로) 특정 근무지로 출근해야 합니다.
이 직무는 리로케이션 혜택을 받을 수 있습니다.
다양성 정보
General Motors는 법적으로 금지된 차별을 배제하는 것은 물론 포용성과 소속감을 진정으로 장려하는 직장이 되기 위해 노력하고 있습니다. 당사는 다양성이 보장되는 환경에서 직원들이 역량을 발휘하고 우리 고객을 위한 더 좋은 제품을 개발할 수 있다고 믿습니다. 따라서 입사에 관심 있는 사람이 있다면 포지션별 주요 업무와 자격을 확인하고 본인이 보유한 기술과 능력에 부합하는 모든 포지션에 적극적으로 지원하기를 장려합니다. 지원자는 채용 과정에서 역할 관련 평가(해당하는 경우) 및/또는 채용 전 스크리닝을 통과해야 합니다. 자세한 정보는 GM 채용 과정 안내를 참고하십시오.
공평한 취업 기회 선언 (미국)
General Motors는 공평한 기회를 제공하는 고용주임을 자부합니다. 자격을 만족하는 지원자는 인종과 피부색, 성별, 성적 지향, 성별 정체성, 국적, 장애, 재향 군인 보호법 적용 여부와 상관없이 채용 후보로서 심사를 받습니다.
숙소 (미국 및 캐나다)
General Motors는 장애인을 포함한 모든 구직자들에게 취업 기회를 제공합니다. 구직이나 취업 지원에 도움이 되는 합리적인 숙소가 필요한 경우 [email protected]으로 이메일을 보내시거나 800-865-7580으로 전화주십시오. 이메일에, 귀하가 요청하는 특정한 숙소에 대한 설명과 귀하가 지원하는 직무와 채용 요청서 번호를 포함해주세요.
