Senior Cybersecurity Incident Analyst
Job Description
The Role
As a Senior Cyber Detection Incident Analyst, you will play a critical role in protecting General Motors' global enterprise by identifying, analyzing, and helping mitigate advanced cyber threats across cloud, identity, endpoint, network, application, and manufacturing ecosystems.
You will serve as a senior technical leader within the Cyber Detection organization, driving detection engineering initiatives, leading complex investigations, and continuously improving the technologies, analytics, and processes used to identify malicious activity. This role combines deep technical expertise, threat-focused analysis, and cross-functional collaboration to enhance GM's overall cybersecurity posture.
The ideal candidate possesses a passion for cyber defense, strong analytical and investigative skills, and experience developing scalable detection capabilities across modern enterprise environments.
What You'll Do
Lead advanced investigations involving complex security incidents, emerging threats, and high-severity escalations
Develop, implement, and optimize detection logic across SIEM, EDR, NDR, SOAR, cloud-native security platforms, and other security monitoring technologies
Conduct threat hunting activities to proactively identify adversary behaviors, attack techniques, and detection gaps
Apply threat intelligence, adversary tradecraft, and MITRE ATT&CK methodologies to improve detection coverage effectiveness
Design, tune, and validate analytics to reduce false positives and improve alert fidelity
Develop automation, enrichment workflows, and operational efficiencies using AI, scripting and security orchestration technologies
Partner with Incident Response, Threat Intelligence, Cloud Security, Product Security, Manufacturing Security, and other cybersecurity teams to improve detection capabilities
Mentor and provide technical guidance to analysts and detection engineers
Drive continuous improvement initiatives that increase visibility, reduce investigative effort, and improve operational effectiveness
Evaluate emerging technologies, AI capabilities, and security monitoring solutions to advance GM's detection maturity
Your Skills & Abilities (Required Qualifications)
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent practical experience
5+ years of experience in cybersecurity with a focus on detection engineering, security operations, incident response, threat hunting, intrusion detection, or security event analysis
Experience working with enterprise SIEM platforms and log-centric detection methodologies
Experience developing and tuning security detections using correlation logic, behavioral analytics, and threat intelligence
Strong understanding of endpoint security technologies and EDR platforms
Experience investigating security events across endpoint, network, cloud, identity, and application environments
Knowledge of attacker tactics, techniques, and procedures (TTPs) and familiarity with the MITRE ATT&CK framework
Experience using scripting and query languages such as Python, PowerShell, or similar technologies
Strong analytical, troubleshooting, and investigative skills
Experience communicating technical findings to both technical and non-technical audiences
Ability to lead investigations during cybersecurity incidents
Demonstrated ability to collaborate effectively across multiple teams and stakeholders
Ability and willingness to participate in a 24x7 on-call rotation
What Can Give You a Competitive Advantage (Preferred Qualifications)
Experience with cloud security monitoring and detection engineering in Azure, AWS, and GCP environments
Experience with SaaS security monitoring and identity threat detection
Experience with network security monitoring, IDS/IPS technologies, packet analysis, and network telemetry
Experience supporting manufacturing, operational technology (OT), or industrial control system environments
Experience with vehicle cybersecurity, automotive architectures, or embedded security telemetry
Experience with application security monitoring, API security, runtime protection, and CI/CD security telemetry
Experience with malware analysis, reverse engineering, or digital forensics
Experience developing SOAR workflows and security automation solutions
Security certifications such as GCIA, GCIH, GCFA, GCDA, AWS Security Specialty, or equivalent
Proven ability to mentor, coach, and develop cybersecurity professionals
Demonstrated success leading technical initiatives and influencing cybersecurity strategy
Strong written and verbal communication skills
Continuous learning mindset with a passion for innovation and cybersecurity excellence
#LI-SB3


GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc).

This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.

This job may be eligible for relocation benefits.

About GM
Our vision is a world with Zero Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more equitable for all.
Why Join Us
We believe we all must make a choice every day – individually and collectively – to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team.
Benefits Overview
From day one, we're looking out for your well-being–at work and at home–so you can focus on realizing your ambitions. Learn how GM supports a rewarding career that rewards you personally by visiting Total Rewards resources.
Non-Discrimination and Equal Employment Opportunities (U.S.)
General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.
All employment decisions are made on a non-discriminatory basis without regard to sex, race, color, national origin, citizenship status, religion, age, disability, pregnancy or maternity status, sexual orientation, gender identity, status as a veteran or protected veteran, or any other similarly protected status in accordance with federal, state and local laws.
We encourage interested candidates to review the key responsibilities and qualifications for each role and apply for any positions that match their skills and capabilities. Applicants in the recruitment process may be required, where applicable, to successfully complete a role-related assessment(s) and/or a pre-employment screening prior to beginning employment. To learn more, visit How we Hire.
Accommodations
General Motors offers opportunities to all job seekers including individuals with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, email us or call us at 1-800-865-7580. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.
More jobs at Generalmotors
- Manufacturing Group Leader - Production - Marion — Marion, Indiana, United States of America
- Staff Software Engineer – MBFF Platform / Microservices Architecture — Austin, Texas, United States of America
- Construction Project Manager — Mountain View Technical Center - Mountain View Technical Center
- Assistant Manager, OnStar Fleet Transformation — Warren, Michigan, United States of America
Similar roles
- Incident Commander at Twilio
- Incident Operations Specialist at Zapier
- CSOC CIR Tier II Analyst at Pingwind
- Incident and Escalation Manager at Vapi