Cybersecurity Operations Manager, Ford Energy
Ford Motor Company Dearborn, Michigan, United States
Motor Vehicle Manufacturing · 10,001+ employees
About the role
The Cybersecurity Operations Manager will lead and modernize global security monitoring and incident response across IT, OT, and product platforms. This role involves managing hybrid teams and MSSP partners while driving continuous optimization of detection capabilities and incident response workflows.
What they look for
Requirements
Candidates must have 5-7 years of experience in security operations or incident response, including at least 3 years in a leadership capacity. A bachelor's or master's degree in a technical field is required, along with proven expertise in multi-domain security environments and regulatory compliance.
Benefits
Full description
The Opportunity
We are seeking a Cybersecurity Operations Manager to lead, operationalize, and modernize our global security monitoring and incident response capabilities. This role oversees a hybrid operational model comprising internal direct reports and a managed security service provider (MSSP). The scope spans Enterprise IT, Product Cybersecurity, customer-facing applications and connected platforms, and Manufacturing/Operational Technology (OT) environments, ensuring robust detection, defense, and response across our entire digital and physical footprint.
Responsibilities
What You'll Do... Key Responsibilities
- Hybrid Team Leadership: Direct, mentor, and manage a high-performing security operations team while overseeing performance, SLAs, escalation pathways, and day-to-day operations of external MSSP partners.
- Broad-Scope Security Operations: Lead 24/7 security monitoring, incident triage, and response capabilities covering Enterprise IT networks, Cloud platforms, Product/IoT telemetry, customer-facing portals and mobile/web applications, and Manufacturing/OT facilities.
- Customer-Facing Application Security Monitoring: Own security monitoring, threat detection, and incident response for customer-facing applications, portals, and APIs — including authentication systems and customer data pathways.
- Connected Platform Monitoring: Lead threat monitoring and security telemetry analysis for external-facing platforms and the connected infrastructure linking customer environments to Ford Energy's cloud and support systems.
- SOC Engineering & Detection Quality: Drive continuous optimization of SIEM/SOAR platforms, detection rules, threat hunting playbooks, and automated response workflows to decrease mean time to detect (MTTD) and mean time to respond (MTTR) across enterprise, product, and customer-facing systems.
- Incident Response Leadership: Act as the primary escalation lead and incident commander during complex cybersecurity incidents — including those impacting customer-facing services and applications — leading cross-functional containment, eradication, root-cause analysis, and customer communication efforts.
- Manufacturing & OT Security: Collaborate with plant operations and industrial control system (ICS) engineers to ensure real-time visibility, anomaly detection, and incident handling across manufacturing plants.
- Compliance & Regulatory Alignment: Support operational security logging, audit readiness, and incident response procedures aligned with applicable industry security frameworks and critical infrastructure requirements as needed.
- Operational Excellence & Metrics: Develop, track, and present operational security metrics, threat landscapes, customer application security posture, and SOC effectiveness KPIs to executive leadership and key business stakeholders.
- Availability: Serve as the senior operational contact and manage on-call escalation rotations for critical security incidents, including those affecting customer-facing platforms.
Qualifications
You'll Have... Required
- Experience: Minimum of 5–7 years of experience in Security Operations (SOC), Threat Intelligence, or Incident Response, with at least 3+ years in a supervisory, management, or technical lead role.
- Hybrid & MSSP Management: Demonstrated success managing vendor/MSSP contracts, driving service delivery SLAs, and leading combined teams of internal engineers and external contractor resources.
- Multi-Domain SOC Experience: Hands-on leadership experience running security operations that span enterprise IT, cloud infrastructure, customer-facing applications/platforms, and operational technology (OT) / industrial control systems (ICS).
- Application Security Awareness: Working knowledge of application security monitoring, web/API threat detection, and securing customer-facing digital platforms and portals.
- Regulatory Compliance: Proven understanding of ISO 27001, NIST SP 800-82, IEC 62443, or similar security frameworks relevant to connected products and critical infrastructure.
- Incident Management: Strong experience acting as an Incident Commander during major breach responses, cyber-attacks, or critical infrastructure outages.
- Education: Bachelor's or master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent related work experience.
Even Better, You May Have... (Preferred)
- Relevant industry certifications such as CISSP, CISM, GCIH, GCFA, GRID, or GICSP.
- Experience securing customer-facing SaaS platforms, IoT/connected product ecosystems, or remote monitoring applications in Electric Utility, Automotive (EV/BMS), or Advanced Manufacturing sectors.
- Deep technical familiarity with enterprise and application security platforms (e.g., Microsoft Sentinel, Defender XDR, Palo Alto Networks, web application firewalls, API security tools, and OT monitoring solutions like Dragos, Claroty, or Nozomi).
- Experience partnering with product and customer experience teams to embed security monitoring into customer-facing application development and support lifecycles.
- Strong capability to clearly articulate technical incident details, business risks, and remediation strategies to C-level executives and customer-facing stakeholders.
Leadership Attributes
- A decisive, strategic leader capable of unifying diverse operational domains (IT, OT, Product, Customer-Facing Applications) into a seamless, proactive defense posture.
Location & Travel
- Location: Dearborn, MI/Hybrid
Company
- As Ford establishes a wholly owned subsidiary focused on Battery Energy Storage Systems, this role will initially be employed by Ford and is expected to transition to the subsidiary within one year.
Why Ford Energy? At Ford Energy, you have the backing of an industrial manufacturing powerhouse with the agility of a dedicated energy startup offering industry leading technology. We offer a competitive compensation package including performance-based bonuses, Ford vehicle discounts, and the opportunity to shape the energy strategy of one of the world's most iconic brands.
Similar roles
-
Sr. Analyst, Cybersecurity
TMRW Sports Inc Orlando, Florida, United States
-
Cybersecurity Analyst IAM II Intermediate
Five Stones Research Corporation Madison County, Alabama, United States
-
Founding Member, Senior AI & Application Security Specialist (Delhi NCR - Hybrid)
J.S. Held LLC Delhi, Delhi, India
-
Security Engineer - Vulnerability Management
Accenture Federal Services Washington, District of Columbia, United States · $106K–$221K/yr
-
Cybersecurity Engineer I (Grade 13)
Space Coast Credit Union Broward County, Florida, United States · $99K–$105K/yr
- Cybersecurity Specialist (DISA)