Cyber Detection Event Analyst
Core
Monitor, triage, and investigate security alerts across endpoint, network, cloud, identity, application, and manufacturing environments to identify and respond to cyber threats.
Role type
Cyber Detection Event Analyst (Security Operations)
Builds
Detection logic, correlation rules, analytics, alerting content, and automation workflows for GM's global security posture.
Domain
Cybersecurity / Threat Detection / Security Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Security event investigation, SIEM log analytics, EDR behavioral detection, NDR packet/flow analysis, cloud security (Azure/AWS/GCP), Python/PowerShell scripting, MITRE ATT&CK/TTPs, API integrations, threat hunting, alert tuning
Preferred skills
SOAR platforms, detection engineering, cloud-native/identity/manufacturing security, AI-assisted security workflows, industry certifications (GCIH, GCIA, SC-200, etc.)
Technologies
SIEM, EDR, NDR, SOAR, Microsoft Azure, Amazon Web Services, Google Cloud Platform, Python, PowerShell, MITRE ATT&CK
Responsibilities
Monitor and triage security alerts, analyze events for indicators of compromise, develop detection logic and automation scripts, conduct threat hunting, collaborate with incident response and engineering teams, document investigative findings, support tool onboarding and log integration.
Seniority
Mid-level, hands-on IC