Cybersecurity Operations Manager, Ford Energy

FordDearborn, MI
$115,500 - $218,100Hybrid

About The Position

In this position, we are seeking a Cybersecurity Operations Manager to lead, operationalize, and modernize our global security monitoring and incident response capabilities. This role oversees a hybrid operational model comprising internal direct reports and a managed security service provider (MSSP). The scope spans Enterprise IT, Product Cybersecurity, customer-facing applications and connected platforms, and Manufacturing/Operational Technology (OT) environments, ensuring robust detection, defense, and response across our entire digital and physical footprint.

Requirements

  • Minimum of 5–7 years of experience in Security Operations (SOC), Threat Intelligence, or Incident Response, with at least 3+ years in a supervisory, management, or technical lead role.
  • Demonstrated success managing vendor/MSSP contracts, driving service delivery SLAs, and leading combined teams of internal engineers and external contractor resources.
  • Hands-on leadership experience running security operations that span enterprise IT, cloud infrastructure, customer-facing applications/platforms, and operational technology (OT) / industrial control systems (ICS).
  • Working knowledge of application security monitoring, web/API threat detection, and securing customer-facing digital platforms and portals.
  • Proven understanding of ISO 27001, NIST SP 800-82, IEC 62443, or similar security frameworks relevant to connected products and critical infrastructure.
  • Strong experience acting as an Incident Commander during major breach responses, cyber-attacks, or critical infrastructure outages.
  • Bachelor's or master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent related work experience.
  • Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.

Nice To Haves

  • Relevant industry certifications such as CISSP, CISM, GCIH, GCFA, GRID, or GICSP.
  • Experience securing customer-facing SaaS platforms, IoT/connected product ecosystems, or remote monitoring applications in Electric Utility, Automotive (EV/BMS), or Advanced Manufacturing sectors.
  • Deep technical familiarity with enterprise and application security platforms (e.g., Microsoft Sentinel, Defender XDR, Palo Alto Networks, web application firewalls, API security tools, and OT monitoring solutions like Dragos, Claroty, or Nozomi).
  • Experience partnering with product and customer experience teams to embed security monitoring into customer-facing application development and support lifecycles.
  • Strong capability to clearly articulate technical incident details, business risks, and remediation strategies to C-level executives and customer-facing stakeholders.
  • A decisive, strategic leader capable of unifying diverse operational domains (IT, OT, Product, Customer-Facing Applications) into a seamless, proactive defense posture.

Responsibilities

  • Direct, mentor, and manage a high-performing security operations team while overseeing performance, SLAs, escalation pathways, and day-to-day operations of external MSSP partners.
  • Lead 24/7 security monitoring, incident triage, and response capabilities covering Enterprise IT networks, Cloud platforms, Product/IoT telemetry, customer-facing portals and mobile/web applications, and Manufacturing/OT facilities.
  • Own security monitoring, threat detection, and incident response for customer-facing applications, portals, and APIs — including authentication systems and customer data pathways.
  • Lead threat monitoring and security telemetry analysis for external-facing platforms and the connected infrastructure linking customer environments to Ford Energy's cloud and support systems.
  • Drive continuous optimization of SIEM/SOAR platforms, detection rules, threat hunting playbooks, and automated response workflows to decrease mean time to detect (MTTD) and mean time to respond (MTTR) across enterprise, product, and customer-facing systems.
  • Act as the primary escalation lead and incident commander during complex cybersecurity incidents — including those impacting customer-facing services and applications — leading cross-functional containment, eradication, root-cause analysis, and customer communication efforts.
  • Collaborate with plant operations and industrial control system (ICS) engineers to ensure real-time visibility, anomaly detection, and incident handling across manufacturing plants.
  • Support operational security logging, audit readiness, and incident response procedures aligned with applicable industry security frameworks and critical infrastructure requirements as needed.
  • Develop, track, and present operational security metrics, threat landscapes, customer application security posture, and SOC effectiveness KPIs to executive leadership and key business stakeholders.
  • Serve as the senior operational contact and manage on-call escalation rotations for critical security incidents, including those affecting customer-facing platforms.

Benefits

  • Immediate medical, dental, vision and prescription drug coverage
  • Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
  • Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
  • Vehicle discount program for employees and family members and management leases
  • Tuition assistance
  • Established and active employee resource groups
  • Paid time off for individual and team community service
  • A generous schedule of paid holidays, including the week between Christmas and New Year’s Day
  • Paid time off and the option to purchase additional vacation time.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service