We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Cyber Security Incident Response Team Lead (CSIRT Manager) - Auburn Hills, MI

Stellantis
parental leave, paid time off, paid holidays, sick time, tuition reimbursement, 401(k), company vehicle
United States, Michigan, Auburn Hills
Apr 08, 2026
Back
Cyber Security Incident Response Team Lead (CSIRT Manager)
#2012768
Auburn Hills, Michigan, United States
Apply
X Facebook LinkedIn Email Copy
Job Description

Description:


The CSIRT Manager leads the Cyber Security Incident Response Team (CSIRT), operating within Stellantis' Cyber Defense Operations Center (CDOC) and in close partnership with several others cybersecurity teams, and regional stakeholders. You will own the incident response lifecycle, ensure adherence to Stellantis crisis procedures, drive operational excellence (MTTD/MTTR), and cultivate a high performing team in a follow the sun model.


Stellantis is a global mobility leader with the ambition to deliver clean, safe, and affordable freedom of mobility for all, guided by the Dare Forward 2030 strategy and a commitment to carbon net zero by 2038 (Scopes 1-3) with interim 2030 decarbonization targets. Our portfolio of iconic brands and strong operational performance underpin this transformation into a sustainable mobility tech company.



Key responsibilities:



  • Own the Cyber Security IR Lifecycle & Escalation: Direct the end-to-end response across preparation, detection/analysis, containment, eradication, recovery, and post incident, following
  • Lead & Develop the Team: Manage, mentor, and schedule CSIRT analysts and leads across shifts and on call rotations within the distributed regional model; drive skills development and readiness.
  • Command During Crises: Serve as Cyber Security Incident Commander for high/critical events and integrate the right SMEs into the crisis cell, ensuring disciplined communications and handoffs as defined in the CSIR crisis process.
  • Metrics & Reporting: Establish, track, and improve KPIs/SLAs (e.g., MTTD, MTTR, containment time, PIR completion) and present status in monthly business reviews and dashboards.
  • Playbooks, Use Cases & Lessons Learned: Ensure playbooks/response procedures are current and threat informed; feed PIR insights back into detections, SOAR workflows, and control hardening in partnership with platform engineering and detection teams.
  • Cross Functional Orchestration: Coordinate with CDOC other products (CTI, Redteam, Monitoring) and Legal/Privacy, Comms, and business/IT/Cloud owners; align to the SOC Target Operating Model and service catalogue.
  • Threat Informed Response: Consume and task Cyber Threat Intelligence and threat hunting to guide scoping, IOCs, and hypotheses; ensure bidirectional feedback between CTI, Red Team, and CSIRT.
  • Tooling & Case Management: Ensure consistent use of the cyber security incident/case platform and evidence handling procedures; maintain audit ready documentation and artifacts.
  • Vendor & Retainer Oversight: Govern Cyber Security IR retainer(s) and MSSP engagements; validate service performance and integration with internal processes.
  • Compliance & Governance: Ensure incident handling aligns with Stellantis policy, applicable regulations, and internal governance boards; prepare materials for audits, PIRs, and leadership readouts (per SOC governance and crisis documentation).


Sample Duties:



  • Direct major cyber security incident bridges, integrate SMEs, and ensure timely executive updates per crisis process; confirm accurate status tracking and next actions.
  • Oversee investigations (host/network/cloud), evidence handling, and scoping; validate containment/eradication and business recovery while maintaining auditready documentation.
  • Run postincident reviews and feed structured improvements into playbooks/use cases and control posture, track remediation to closure.
  • Report KPIs/SLAs and risk themes in monthly reviews; align resourcing and tooling roadmaps to findings.
  • Coordinate with CTI for threatinformed scoping and proactive hunts; ensure bidirectional intel sharing and IOC packages.


This role is based in Auburn Hills, MI and is required to be on-site in our HQ building 5 days per week.




Location(s)
1000 Chrysler Drive, Auburn Hills , Michigan 48326 , United States
Requirements

Basic Qualifications:



  • Bachelor's degree in Cybersecurity, Computer Science, or related field.
  • 5+ years in SOC / Cyber Security Incident Response roles with 2+ years managing cyber security incident response teams or programs in large, distributed enterprises.
  • Demonstrated leadership during high/critical incidents and familiarity with crisis management communications per established escalation matrices.
  • Hands on knowledge of SIEM/SOAR, EDR, network security monitoring, IA detection & Response tools/ framework and cloud/identity telemetry; strong grasp of attacker TTPs and enterprise hardening.
  • Experience operating to structured IR frameworks (e.g., NIST style lifecycle) and running formal after action/lessons learned cycles integrated with use case/playbook updates.
  • Excellent written/oral communication, stakeholder management, and executive reporting skills; comfortable presenting in MBRs and steering forums.


Preferred Qualifications:



  • Prior leadership within a CSIRT/CSOC supporting multiple regions and product/OT security stakeholders.
  • Certifications : GCIH, GCFA/GNFA, GCIA, CISSP, OSCP(or comparable).
  • Experience with threatinformed defense (MITRE ATT&CK), KPI/SLA governance, and MSSP/retainer management.
  • Familiarity with worldwide privacy/security obligations and incident communication expectations in regulated, multijurisdictional environments (in partnership with Legal/Privacy).



Essential Skills & Competences:



  • Crisis Leadership: Decisive command in high pressure situations, with disciplined adherence to escalation and executive comms playbooks.
  • Operational Excellence: KPI driven mindset; ability to translate PIR insights into upgraded detections, controls, and automations.
  • Collaboration & Influence: Build strong relationships across CSOC, PSOC, CTI, Red Team, platform engineering, and business/IT owners.
  • Communication: Clear incident narratives, timelines, and executive one pager; ability to brief senior leadership succinctly.

Employment Type
Full-time
Stellantis
At Stellantis, we assess candidates based on qualifications, merit, and business needs. We welcome applications from all people without regard to sex, age, ethnicity, nationality, religion, sexual orientation, disability, or any characteristic protected by law. We believe that diverse teams reflect our identity as a global company, enabling us to better address the evolving needs of our customers and care for our future.
Additional Job Posting Information

Our Benefits - Designed with You in Mind

Comprehensive Health & Well-being Coverage

From your very first day, you'll have access to medical, dental, vision, and prescription drug coverage - ensuring you and your family stay healthy and protected.

Generous Paid Time Off

We believe in work-life balance. That's why we offer: 17+ paid holidays, including shut-down from December 24th through New Years Day every year. Vacation, float & wellbeing days, sick time and fully paid parental leave when your family needs you most.

Competitive Retirement Savings Plans

We help you plan for the future with:

    • An employer match on contributions to your 401k, Roth, and Catch-Up plans
    • An employer contribution, even if you don't contribute

Income Protection & Insurance Options

Benefit from included and optional disability, life, and other insurance programs - because your peace of mind matters.

Company Vehicle Lease Program

Eligible employees and their immediate families can enjoy company vehicle lease options with included insurance, maintenance, and unlimited mileage. Plus, take advantage of exclusive discounts on Stellantis products.

Family Building Benefit

We proudly support all paths to parenthood- including fertility and infertility treatments, adoption services, and gestational surrogacy.

Support for Your Growth and Giving Back

We believe in investing in your future and your passions:

    • Tuition reimbursement
    • Student loan refinancing programs
    • 18 paid volunteer hours each year to make a difference in your community

And so much more!

When you join us, you're not just building a career - you're joining a company that supports you, inside and outside of work.

Applied = 0

(web-bd9584865-dffwj)