> Markdown version of [/jobs/ext/2596779-senior-cybersecurity-incident-analyst](https://www.wearedevelopers.com/jobs/ext/2596779-senior-cybersecurity-incident-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Incident Analyst - **Company:** General Motors - **Location:** Warren, MI, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Query Languages, Digital Forensics, Monitoring of Systems, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Security, Packet Analyzer, Windows PowerShell, Reverse Engineering, Security Information and Event Management, Scripting, Google Cloud, Software Security, Mitre Att&ck, Malware, Cyber Threat Analysis, Information Technology, Cybercrime, Process Control Systems, Operational Systems, Cyber Warfare - **Published:** August 14, 2026 - **Apply:** https://generalmotors.wd5.myworkdayjobs.com/Careers_GM/job/Warren-Michigan-United-States-of-America/Senior-Cybersecurity-Incident-Analyst_JR-202616771-1 ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent practical experience * 5+ years of experience in cybersecurity with a focus on detection engineering, security operations, incident response, threat hunting, intrusion detection, or security event analysis * Experience working with enterprise SIEM platforms and log-centric detection methodologies * Experience developing and tuning security detections using correlation logic, behavioral analytics, and threat intelligence * Strong understanding of endpoint security technologies and EDR platforms * Experience investigating security events across endpoint, network, cloud, identity, and application environments * Knowledge of attacker tactics, techniques, and procedures (TTPs) and familiarity with the MITRE ATT&CK framework * Experience using scripting and query languages such as Python, PowerShell, or similar technologies * Strong analytical, troubleshooting, and investigative skills * Experience communicating technical findings to both technical and non-technical audiences * Ability to lead investigations during cybersecurity incidents * Demonstrated ability to collaborate effectively across multiple teams and stakeholders * Ability and willingness to participate in a 24x7 on-call rotation What Can Give You a Competitive Advantage (Preferred Qualifications) * Experience with cloud security monitoring and detection engineering in Azure, AWS, and GCP environments * Experience with SaaS security monitoring and identity threat detection * Experience with network security monitoring, IDS/IPS technologies, packet analysis, and network telemetry * Experience supporting manufacturing, operational technology (OT), or industrial control system environments * Experience with vehicle cybersecurity, automotive architectures, or embedded security telemetry * Experience with application security monitoring, API security, runtime protection, and CI/CD security telemetry * Experience with malware analysis, reverse engineering, or digital forensics * Experience developing SOAR workflows and security automation solutions * Security certifications such as GCIA, GCIH, GCFA, GCDA, AWS Security Specialty, or equivalent * Proven ability to mentor, coach, and develop cybersecurity professionals * Demonstrated success leading technical initiatives and influencing cybersecurity strategy * Strong written and verbal communication skills * Continuous learning mindset with a passion for innovation and cybersecurity excellence ## Description As a Senior Cyber Detection Incident Analyst, you will play a critical role in protecting General Motors' global enterprise by identifying, analyzing, and helping mitigate advanced cyber threats across cloud, identity, endpoint, network, application, and manufacturing ecosystems. You will serve as a senior technical leader within the Cyber Detection organization, driving detection engineering initiatives, leading complex investigations, and continuously improving the technologies, analytics, and processes used to identify malicious activity. This role combines deep technical expertise, threat-focused analysis, and cross-functional collaboration to enhance GM's overall cybersecurity posture. The ideal candidate possesses a passion for cyber defense, strong analytical and investigative skills, and experience developing scalable detection capabilities across modern enterprise environments. What You'll Do * Lead advanced investigations involving complex security incidents, emerging threats, and high-severity escalations * Develop, implement, and optimize detection logic across SIEM, EDR, NDR, SOAR, cloud-native security platforms, and other security monitoring technologies * Conduct threat hunting activities to proactively identify adversary behaviors, attack techniques, and detection gaps * Apply threat intelligence, adversary tradecraft, and MITRE ATT&CK methodologies to improve detection coverage effectiveness * Design, tune, and validate analytics to reduce false positives and improve alert fidelity * Develop automation, enrichment workflows, and operational efficiencies using AI, scripting and security orchestration technologies * Partner with Incident Response, Threat Intelligence, Cloud Security, Product Security, Manufacturing Security, and other cybersecurity teams to improve detection capabilities * Mentor and provide technical guidance to analysts and detection engineers * Drive continuous improvement initiatives that increase visibility, reduce investigative effort, and improve operational effectiveness * Evaluate emerging technologies, AI capabilities, and security monitoring solutions to advance GM's detection maturity, This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)