> Markdown version of [/jobs/ext/2643801-cyber-automation-analyst-security-operations-center](https://www.wearedevelopers.com/jobs/ext/2643801-cyber-automation-analyst-security-operations-center). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Automation Analyst - Security Operations Center - **Company:** Ford Motor Company - **Location:** Dearborn, MI, United States - **Experience:** Experienced - **Salary:** $99,600.0 - $192,900.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Audit Trail, Unit Testing, Cloud Computing, Code Review, Cyber Security, Information Systems, Digital Data, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Security Information and Event Management, Software Engineering, TCP/IP, Software Vulnerability Management, Data Logging, Data Processing, Enterprise Software Applications, Large Language Models, Generative AI, Malware, Information Technology, Restful APIs, Cyber Warfare, Data Pipelines, Security Orchestration, Automation & Response - **Published:** August 30, 2026 - **Apply:** https://www.careerjet.com/job/us05770b0c745e816eb0995db6315943f8/eaa ## About the Role * Bachelor's degree in computer science, cybersecurity, engineering, information systems, or a related technical field, OR a combination of education and equivalent practical experience. * 5 years of experience across the following areas: * Hands-on detection engineering experience creating, tuning, testing, and deploying production security detections in SIEM or security analytics platforms, with preference for Google SecOps. * Hands-on experience building and operating GCP-hosted CI/CD pipelines, including Tekton tasks, Tekton pipelines, pipeline triggers, workload identity or service account usage, secrets handling, and deployment promotion workflows. * Proficiency developing AI-assisted or Agentic SOC capabilities using generative AI, LLMs, RAG, agent skills, tool orchestration, MCP-style integrations, evaluation patterns, and guardrails for secure operational use. * Strong Python programming skills, including REST API integration, structured data handling, automation, unit testing, error handling, and production support practices. * Solid comprehension of cyber defense concepts including malware, attack techniques, cloud threats, identity compromise, vulnerability management, detection logic, and incident response workflows. Even better, you may have... * 2+ years security engineering experience. * Experience with Google SecOps, YARA-L or similar detection languages, and security case management workflows. * Familiarity with Gemini Enterprise Agent Platform concepts, Agent Runtime, Agent Registry, Skills Registry, Model Armor, Agent Gateway, Memory Bank, delegated identity, and secure tool execution patterns. * Sound understanding of cloud, TCP/IP, networking, endpoint, identity, logging, and data pipeline concepts. * Demonstrated independent initiative, strong ownership, quality methods, teamwork, sound judgment, and high integrity., + $99,600-192,900 per year Job Category: Enterprise Technology Degree Level: Bachelor's Degree or equivalent Job Description: We are the movers of the world and the makers of the future. We get up ever… ## Description Enterprise Technology plays a critical part in shaping the future of mobility. If you're looking for the chance to leverage advanced technology to redefine the transportation landscape, enhance the customer experience and improve people's lives, this is the opportunity for you. Join us and challenge your IT expertise and analytical skills to help create vehicles that are as smart as you are. This role will be focused on advancing Ford's Cyber Defense Center (CDC) detection engineering, automation, and Agentic SOC capabilities within the Office of the CETO organization. The CDC mission is to provide proactive and reactive security services to protect Ford Motor Company global digital information assets from compromise. The Detection Engineer will design, build, test, and maintain high-fidelity detections and security automations across SIEM, SOAR, EDR, cloud, identity, and AI-enabled security platforms. This position requires hands-on expertise in Google SecOps, GCP-hosted CI/CD pipelines, Tekton-based delivery workflows, Python automation, and secure Agentic SOC development using modern generative AI patterns. Successful candidates must bring deep cyber defense experience and strong software engineering discipline. The candidate should be able to translate attacker behaviors, cloud telemetry, endpoint signals, identity events, and SOC case history into durable detection logic and automated response workflows. This role also requires the ability to develop, validate, and deploy AI-assisted SOC capabilities, including agent skills, retrieval-augmented workflows, Model Context Protocol integrations, secure prompt and tool governance, and human-in-the-loop guardrails for production security operations. Candidates must be willing to work a Hybrid work pattern, with a currently limited in-office schedule in the southeast Michigan metro area 4 days in-person/week. What you'll do... * Create, enhance, tune, test, and operationalize curated and custom detections across Google SecOps SIEM/SOAR, EDR, cloud, identity, and application telemetry sources. * Build Python-based SOAR orchestration and integrations that enrich cases, normalize security data, execute response actions, and connect security platforms through REST APIs and event-driven workflows. * Engineer Agentic SOC capabilities, including agent skills, agent-to-tool orchestration, RAG-based security workflows, MCP tool integrations, prompt and response guardrails, and human-in-the-loop approval patterns. * Apply secure software development practices, code review, infrastructure-as-code, secrets management, least-privilege access, audit logging, and production readiness standards to detection engineering and Agentic SOC delivery. ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Car's are Technology on Wheels - Impact of Software and IT Competence in Automotive](https://www.wearedevelopers.com/videos/780-car-s-are-technology-on-wheels-impact-of-software-and-it-competence-in-automotive) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)