Job Information
Southern Company Detection Engineering & Automation Manager in Atlanta, Georgia
Cyber Security - Detection Engineering & Automation Manager
Position Overview: We are seeking a highly skilled and experienced Detection Engineering & Automation Manager to lead our cybersecurity initiatives. The ideal candidate will have a strong background in Security Operations Center (SOC) operations, expertise in the MITRE ATT&CK Framework, and a proven track record in implementing Security Orchestration, Automation, and Response (SOAR) solutions. This role is pivotal in enhancing our Digital Defense Center detection capabilities and streamlining security processes through automation.
Key Responsibilities:
Lead the detection engineering team in designing, implementing, and optimizing detection strategies and solutions for the Cyber Security organization.
Map security threats and incidents to the MITRE ATT&CK Framework to enhance threat intelligence and response strategies.
Develop and manage SOC, Cyber Threat Intelligence, and other ops team automations to improve efficiency and effectiveness in threat detection and response.
Collaborate with cross-functional teams to integrate SOAR solutions into existing operational workflows.
Oversee the continuous improvement of detection and response processes through innovative automation techniques.
Provide technical leadership and mentorship to the detection engineering team.
Stay abreast of the latest cybersecurity trends, tools, and technologies to ensure the organization remains ahead of emerging threats.
Define and track Outcome Based Metrics and KPIs for the Detection Engineering & Automation team
Qualifications:
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field preferred.
8 years working experience in Cyber Security Operations required.
2+ years of SOC Analyst working experience required.
2+ years of Detection Engineering work experience with Splunk ES or another analytic platform required.
2+ years of SOAR working experience required.
2+ years of cyber security management or technical lead experience required.
Relevant certifications such as OSCP, SANS GCIA/GCIH, CISSP, CISM are highly desired.
Extensive knowledge of the MITRE ATT&CK Framework and its application in threat detection and response.
Proven experience in implementing and managing SOAR solutions and SOC automations.
Strong understanding of cybersecurity principles, threat intelligence, and incident response.
Excellent leadership, communication, and interpersonal skills.
Ability to work collaboratively in a fast-paced, dynamic environment.
About Southern Company
Southern Company (NYSE: SO ) is a leading energy provider serving 9 million customers across the Southeast and beyond through its family of companies. Providing clean, safe, reliable and affordable energy with excellent service is our mission. The company has electric operating companies in three states, natural gas distribution companies in four states, a competitive generation company, a leading distributed energy solutions provider with national capabilities, a fiber optics network and telecommunications services. Through an industry-leading commitment to innovation, resilience and sustainability, we are taking action to meet customers' and communities' needs while advancing our goal of net-zero greenhouse gas emissions by 2050. Our uncompromising values ensure we put the needs of those we serve at the center of everything we do and are the key to our sustained success. We are transforming energy into economic, environmental and social progress for tomorrow. Our corporate culture has been recognized by a variety of organizations, earning the company awards and recognitions that reflect Our Values and dedication to service. To learn more, visit www.southerncompany.com .
Southern Company invests in the well-being of its employees and their families through a comprehensive total rewards strategy that includes competitive base salary, annual incentive awards for eligible employees and health, welfare and retirement benefits designed to support physical, financial, and emotional/social well-being. This position may also be eligible for additional compensation, such as an incentive program, with the amount of any bonus/awards subject to the terms and conditions of the applicable incentive plan(s). A summary of the benefits offered for this position can be found here https://seo.nlx.org/southernco/pdf/SOCO-Benefits.pdf . Additional and specific details about total compensation and beneļ¬ts will also be provided during the hiring process.
Southern Company is an equal opportunity employer where an applicant's qualifications are considered without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity or expression, or any other basis prohibited by law.
Job Identification: 12641
Job Category: Cybersecurity
Job Schedule: Full time
Company: Southern Company Services
Southern Company
-
- Southern Company Jobs