Skip to content

Open nowPosted yesterday

Lead Cybersecurity Detection Engineer

Dealer.com584 open roles

Where
Atlanta GA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowLead Cybersecurity Detection EngineerDealer.com · Atlanta GA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Dealer.com's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Dealer.com postings stay open a median of 6 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted yesterday

Dealer.com median: 6 days open

The posting

Company

Cox Automotive - USA

Job Family Group

Information Technology

Job Profile

Cybersecurity Lead Engineer

Management Level

Manager - Non People Leader

Flexible Work Option

Hybrid - Ability to work remotely part of the week

Travel %

No

Work Shift

Day

Compensation

Compensation includes a base salary in the range of $122,600.00 - $204,400.00. The base salary may vary within the anticipated base pay range based on factors such as the ultimate location of the position and the selected candidate’s knowledge, skills, and abilities. Position may be eligible for additional compensation that may include an incentive program.

Job Description

Cox Automotive is seeking an experienced Lead Cybersecurity Engineer to serve as a senior technical voice on our Detection Engineering team, supporting next-generation Cyber Defense across our diverse portfolio of automotive solutions including Dealertrack, Manheim, Autotrader, Kelley Blue Book, Central Dispatch, and vAuto.

Reporting to the Director of Cyber Detection Engineering, you'll design, build, and maintain advanced enterprise- and customer-focused detection capabilities - including AI-driven detection agents and automation - while providing hands-on technical leadership and mentorship to other engineers on the team. You'll partner closely with Incident Response, Threat Intelligence, and Vulnerability Management to strengthen detection coverage, with visibility into detection needs across multiple Cox Automotive business units. The ideal candidate will possess expert-level, hands-on knowledge in SIEM implementation and log ingestion, Detection Engineering best practices, Incident Response, and Threat Intelligence, along with strong verbal and written communication skills and a track record of raising the technical bar for engineers around them.

What You'll Do

Cybersecurity Detection Engineering:

  • Serve as a senior technical lead for detection engineering, building and maintaining detective solutions that protect Cox Automotive’s internal systems as well as its domestic and international businesses.
  • Contribute to and help execute the Detection Engineering strategy, roadmap, and objectives.
  • Architect and deploy agentic AI systems that autonomously detect, analyze, and respond to security threats across enterprise infrastructure.
  • Design multi-agent frameworks where specialized AI agents collaborate on threat hunting, incident investigation, and attack pattern recognition.
  • Develop self-improving detection systems that learn from each investigation and automatically enhance detection rules and playbooks.
  • Design and implement advanced threat detection techniques using tools such as SIEM, EDR, and SOAR platforms.
  • Develop innovative custom detection rules and automated remediation playbooks and alerts tailored to the Cox Automotive’s enterprise and customer threat landscape.
  • Leverage industry standard MITRE/ATLAS frameworks to identify detection coverage and close gaps.
  • Monitor, optimize, and continuously improve detection systems for performance, scalability, and effectiveness.
  • Collaborate with Threat Detection and Response team to continuously improve cybersecurity capabilities in identification, management, and response to threats in the most efficient and effective manner.
  • Perform attack simulation testing to validate efficacy of use cases.
  • Conduct purple teaming exercises in collaboration with the Vulnerability Management team.
  • Manage and maintain SIEM/Data Lake data management and log ingestion infrastructure in collaboration with Cyber Defense Engineering counterparts.
  • Evaluate, validate, tune, and sunset detections as needed.
  • Build and maintain operational guidelines, diagrams, and documentation for security detection and response.
  • Provide off-hour support as needed for security administration, detection, and response activities.

Incident Response:

  • Collaborate with the Incident Response team to ensure rapid detection and containment of cyber threats.
  • Build threat detection logic during incident response to accelerate threat identification and containment.
  • Continuously improve detection and response processes based on lessons learned from incidents.

Threat Intelligence Integration:

  • Leverage threat intelligence to enhance detection capabilities and proactively mitigate risks.
  • Identify and analyze new and emerging threat vectors and incorporate them into detection strategies.

Stakeholder Collaboration:

  • Partner with other Cybersecurity, Engineering, and Product teams to ensure successful deployment of detection and response solutions.
  • Collaborate with Product teams to design and implement new customer-focused detection and response solutions.
  • Communicate detection capabilities, findings, and technical recommendations clearly to technical and non-technical stakeholders, escalating to leadership as needed.

Governance and Compliance:

  • Design and implement processes that adhere to regulatory requirements and industry standards (e.g., GDPR, PCI-DSS, NIST).
  • Maintain documentation of detection use cases, processes, and configurations.

Who You Are

Minimum Qualifications

  • Bachelor’s degree in Computer Science or a related discipline and 6+ years of industry related professional experience
  • Multi-cloud security experience (AWS, Azure, GCP)
  • Experience with AI/ML frameworks and prompt engineering for security applications
  • Expert level knowledge of Detection Engineering
  • Strong experience with information security, network security, security monitoring, and Incident Response.
  • Strong experience with developing SIEM/SOAR detection and automation use cases.
  • Working experience with industry standard security technologies and services such as threat intelligence, firewalls, SASE, IPS, endpoint security, DLP, SIEM/SOAR, and Data Lakes.
  • Expert level knowledge on the attack kill chain and diamond model.
  • 3+ years experience in a cyber defense role

Preferred Qualifications

  • OSCP, GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA certification(s)
  • Dev Ops / Engineering / Network / System Administration experience
  • Experience developing customer-focused detection and response systems

Drug Testing

To be employed in this role, you’ll need to clear a pre-employment drug test. Cox Automotive does not currently administer a pre-employment drug test for marijuana for this position. However, we are a drug-free workplace, so the possession, use or being under the influence of drugs illegal under federal or state law during work hours, on company property and/or in company vehicles is prohibited.

Benefits

The Company offers eligible employees the flexibility to take as much vacation with pay as they deem consistent with their duties, the company’s needs, and its obligations; seven paid holidays throughout the calendar year; and up to 160 hours of paid wellness annually for their own wellness or that of family members. Employees are also eligible for additional paid time off in the form of bereavement leave, time off to vote, jury duty leave, volunteer time off, military leave, and parental leave.

About Us

Through groundbreaking technology and a commitment to stellar experiences for drivers and dealers alike, Cox Automotive employees are transforming the way the world buys, owns, sells – or simply uses – cars. Cox Automotive employees get to work on iconic consumer brands like Autotrader and Kelley Blue Book and industry-leading dealer-facing companies like vAuto and Manheim, all while enjoying the people-centered atmosphere that is central to our life at Cox. Benefits of working at Cox may include health care insurance (medical, dental, vision), retirement planning (401(k)), and paid days off (sick leave, parental leave, flexible vacation/wellness days, and/or PTO). For more details on what benefits you may be offered, visit our benefits page. Cox is an Equal Employment Opportunity employer – All qualified applicants/employees will receive consideration for employment without regard to that individual’s age, race, color, religion or creed, national origin or ancestry, sex (including pregnancy), sexual orientation, gender, gender identity, physical or mental disability, veteran status, genetic information, ethnicity, citizenship, or any other characteristic protected by law. Cox provides reasonable accommodations when requested by a qualified applicant or employee with disability, unless such accommodations would cause an undue hardship.

EOE, including disability/vets

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Dealer.com's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Dealer.com's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Dealer.com's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.