Ford Motor Company

Cybersecurity Operations Manager, Ford Energy

Ford Motor Company Dearborn, Michigan, United States

Motor Vehicle Manufacturing · 10,001+ employees

8 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Cybersecurity Operations Manager will lead and modernize global security monitoring and incident response across IT, OT, and product platforms. This role involves managing hybrid teams and MSSP partners while driving continuous optimization of detection capabilities and incident response workflows.

What they look for

Cybersecurity Operations Incident Response Threat Intelligence MSSP Management Cloud Security OT Security ICS Security SIEM SOAR Application Security Risk Management Compliance Leadership Vendor Management Network Security Telemetry Analysis

Requirements

Candidates must have 5-7 years of experience in security operations or incident response, including at least 3 years in a leadership capacity. A bachelor's or master's degree in a technical field is required, along with proven expertise in multi-domain security environments and regulatory compliance.

Benefits

Performance-based bonuses Ford vehicle discounts

Full description

The Opportunity

We are seeking a Cybersecurity Operations Manager to lead, operationalize, and modernize our global security monitoring and incident response capabilities. This role oversees a hybrid operational model comprising internal direct reports and a managed security service provider (MSSP). The scope spans Enterprise IT, Product Cybersecurity, customer-facing applications and connected platforms, and Manufacturing/Operational Technology (OT) environments, ensuring robust detection, defense, and response across our entire digital and physical footprint.

Responsibilities

What You'll Do... Key Responsibilities

  • Hybrid Team Leadership: Direct, mentor, and manage a high-performing security operations team while overseeing performance, SLAs, escalation pathways, and day-to-day operations of external MSSP partners.
  • Broad-Scope Security Operations: Lead 24/7 security monitoring, incident triage, and response capabilities covering Enterprise IT networks, Cloud platforms, Product/IoT telemetry, customer-facing portals and mobile/web applications, and Manufacturing/OT facilities.
  • Customer-Facing Application Security Monitoring: Own security monitoring, threat detection, and incident response for customer-facing applications, portals, and APIs — including authentication systems and customer data pathways.
  • Connected Platform Monitoring: Lead threat monitoring and security telemetry analysis for external-facing platforms and the connected infrastructure linking customer environments to Ford Energy's cloud and support systems.
  • SOC Engineering & Detection Quality: Drive continuous optimization of SIEM/SOAR platforms, detection rules, threat hunting playbooks, and automated response workflows to decrease mean time to detect (MTTD) and mean time to respond (MTTR) across enterprise, product, and customer-facing systems.
  • Incident Response Leadership: Act as the primary escalation lead and incident commander during complex cybersecurity incidents — including those impacting customer-facing services and applications — leading cross-functional containment, eradication, root-cause analysis, and customer communication efforts.
  • Manufacturing & OT Security: Collaborate with plant operations and industrial control system (ICS) engineers to ensure real-time visibility, anomaly detection, and incident handling across manufacturing plants.
  • Compliance & Regulatory Alignment: Support operational security logging, audit readiness, and incident response procedures aligned with applicable industry security frameworks and critical infrastructure requirements as needed.
  • Operational Excellence & Metrics: Develop, track, and present operational security metrics, threat landscapes, customer application security posture, and SOC effectiveness KPIs to executive leadership and key business stakeholders.
  • Availability: Serve as the senior operational contact and manage on-call escalation rotations for critical security incidents, including those affecting customer-facing platforms.

Qualifications

You'll Have... Required

  • Experience: Minimum of 5–7 years of experience in Security Operations (SOC), Threat Intelligence, or Incident Response, with at least 3+ years in a supervisory, management, or technical lead role.
  • Hybrid & MSSP Management: Demonstrated success managing vendor/MSSP contracts, driving service delivery SLAs, and leading combined teams of internal engineers and external contractor resources.
  • Multi-Domain SOC Experience: Hands-on leadership experience running security operations that span enterprise IT, cloud infrastructure, customer-facing applications/platforms, and operational technology (OT) / industrial control systems (ICS).
  • Application Security Awareness: Working knowledge of application security monitoring, web/API threat detection, and securing customer-facing digital platforms and portals.
  • Regulatory Compliance: Proven understanding of ISO 27001, NIST SP 800-82, IEC 62443, or similar security frameworks relevant to connected products and critical infrastructure.
  • Incident Management: Strong experience acting as an Incident Commander during major breach responses, cyber-attacks, or critical infrastructure outages.
  • Education: Bachelor's or master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent related work experience.

Even Better, You May Have... (Preferred)

  • Relevant industry certifications such as CISSP, CISM, GCIH, GCFA, GRID, or GICSP.
  • Experience securing customer-facing SaaS platforms, IoT/connected product ecosystems, or remote monitoring applications in Electric Utility, Automotive (EV/BMS), or Advanced Manufacturing sectors.
  • Deep technical familiarity with enterprise and application security platforms (e.g., Microsoft Sentinel, Defender XDR, Palo Alto Networks, web application firewalls, API security tools, and OT monitoring solutions like Dragos, Claroty, or Nozomi).
  • Experience partnering with product and customer experience teams to embed security monitoring into customer-facing application development and support lifecycles.
  • Strong capability to clearly articulate technical incident details, business risks, and remediation strategies to C-level executives and customer-facing stakeholders.

Leadership Attributes

  • A decisive, strategic leader capable of unifying diverse operational domains (IT, OT, Product, Customer-Facing Applications) into a seamless, proactive defense posture.

Location & Travel

  • Location: Dearborn, MI/Hybrid

Company

  • As Ford establishes a wholly owned subsidiary focused on Battery Energy Storage Systems, this role will initially be employed by Ford and is expected to transition to the subsidiary within one year.

Why Ford Energy? At Ford Energy, you have the backing of an industrial manufacturing powerhouse with the agility of a dedicated energy startup offering industry leading technology. We offer a competitive compensation package including performance-based bonuses, Ford vehicle discounts, and the opportunity to shape the energy strategy of one of the world's most iconic brands.

Similar roles