Home › Companies › Fa Exvu Saasfaprod1 Fa Ocs Oraclecloud Com CX 1 › Cybersecurity Engineer
Cybersecurity Engineer
Fa Exvu Saasfaprod1 Fa Ocs Oraclecloud Com CX 1 · Arlington, TX, United States; US - Arlington AOC I, TX, Arlington, TX, US · Hybrid · Active · Oracle Recruiting Cloud / Fusion HCM
Job facts
| Field | Value |
|---|---|
| Company | Fa Exvu Saasfaprod1 Fa Ocs Oraclecloud Com CX 1 |
| Title | Cybersecurity Engineer |
| Normalized title | - |
| Department / team | Technology |
| Location | Arlington, TX, United States |
| Work model | Hybrid / Hybrid |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | Oracle Recruiting Cloud / Fusion HCM |
| Posted / first seen | 2026-05-18 / 2026-05-31 |
| Changed / last seen | 2026-06-03 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Fa Exvu Saasfaprod1 Fa Ocs Oraclecloud Com CX 1. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through Oracle Recruiting Cloud / Fusion HCM. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Arlington. | Open |
| Department jobs | Active postings in Technology. | Open |
| Work model jobs | Active Hybrid postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Fa Exvu Saasfaprod1 Fa Ocs Oraclecloud Com CX 1 |
| Source | f6d0cadf-249b-4136-83dc-06ed741e1fb3 |
| ATS provider | Oracle Recruiting Cloud / Fusion HCM |
Description
Description
Why GMF Cybersecurity?
Innovation isn’t just a talking point at GM Financial, it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.
Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.
Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.
This position will be posted until filled.
Responsibilities
About the role
The Cybersecurity Engineer – Incident Response Detection Engineer is responsible for designing proactive defenses that keep us ahead of evolving cyber threats. In this role, you’ll leverage SIEM analytics and detection engineering techniques to craft precise detection rules, optimize log analysis, and identify anomalous activity using a wide variety of tooling across on-prem and cloud environments. Security technologies may include but are not limited to: Data Loss Prevention (DLP), Security Incident Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Intrusion Detections System (IDS)/Intrusion Prevention System (IPS), Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR), Network Detection and Response (NDR), Security Orchestration, Automation and Response (SOAR), and Web and Email Security Tooling.
In this role you will:
Develop and maintain detection rules at source and within a SIEM to identify anomalous behaviors, suspicious activity, and emerging threats across on-prem and cloud environments Manage, filter, and correlate high-volume telemetry from multiple sources to produce actionable insights Align detection engineering efforts with CSIRT operational goals, ensuring seamless integration with incident response workflows and Detection as Code (DaC) Pipelines Continuously improve alert fidelity by tuning detection logic and reducing false positives Perform threat hunting and detection gap analysis to proactively identify coverage gaps and strengthen detection capabilities Investigate security incidents from detection to resolution, engaging in any containment, eradication and recovery actions as needed Conduct purple teaming exercises and analyze resulting log activity to validate detection coverage and identify gaps Collaborate with our threat intelligence team to incorporate emerging indicators and TTPs into detection strategies Document detection logic, tuning, playbooks and validation results for transparency, auditability, and knowledge sharing Stay current with evolving attack techniques and security technologies to adapt detection strategies accordingly Participate in an on ‑ call rotation as needed to support timely response to security incidents outside of standard business hours
Qualifications
What makes You an ideal candidate?
Knowledge and Skills
Strong technical skills and hands on experience in Cybersecurity Defensive Operations as it relates to alert triage, on-going monitoring, detection, investigation, and incident response activities Understanding of Cybersecurity concepts such as SIEM analytics, Endpoint security, Network security, Cloud security, Data Loss Prevention/Data Privacy, and Web/Email security Practical understanding of the NIST Incident Response Life Cycle and the MITRE ATT&CK Framework Demonstrate familiarity with AI and large language models (LLMs) and their application in cybersecurity, including how they can support threat detection, analysis, and decision ‑ making Strong knowledge of the OSI model and security that is associated with each layer Strong knowledge of core Information Technology concepts such as TCP/IP networking, Windows & Active Directory, Unix/Linux/Mac, web/email traffic fundamentals, and using a command line interface (CLI) Practical understanding of cloud providers, technologies, and concepts Understanding of Agile, CI/CD, and DevOps environments Experience with scripting languages such as Python or PowerShell Demonstrated ability to communicate across multiple levels of stakeholders Ability to document and summarize technical evidence and findings Good interpersonal, verbal, and written communication skills across various mediums Detail oriented with good time and analytical skills Ability to exercise prudent judgment and offer knowledgeable recommendations Ability to work both independently and in a team environment Ability to manage multiple projects, tasks, and investigations Ability to work in sensitive situations Be a reputable representative of the department Attention to detail and ability to formulate decisions based on evidence gathering
Education & Work Experience
High School Diploma or equivalent required Bachelor’s Degree in related field or equivalent work experience strongly preferred 1-5 years of experience in large and complex business environments with a successful track record working directly with senior level management preferred 1-5 years of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering, or Network Operations, Information Technology, Application Development preferred
Licenses and Certifications
One or more security related certifications, such as CISSP, CCNP-Security, GIAC, CEH, or CPTS highly preferred
What We Offer : Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.
Our Culture: Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.
Compensation: Competitive pay and bonus eligibility.
Work Life Balance: Flexible hybrid work environment, 4-days a week in office.
NOTE: We are unable to consider candidates who require visa sponsorship for this position
This position is not open to agency submissions
#GMFJobs
#LI-ST1
#LI-Hybrid
Full job record
| Job ID | d21d49b53d2c21d8b99e57ece5bd83e15d9f71b2 |
| Org ID | 75949101-40bb-42f4-afdd-cf86ec16bd86 |
| Source ID | f6d0cadf-249b-4136-83dc-06ed741e1fb3 |
| Board ID | f6d0cadf-249b-4136-83dc-06ed741e1fb3 |
| Provider | oracle_hcm |
| Provider Job Key | 260063 |
| Title | Cybersecurity Engineer |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Arlington, TX, United States; US - Arlington AOC I, TX, Arlington, TX, US |
| Department | Technology |
| Team | — |
| Employment Type | full_time |
| Workplace Type | hybrid |
| Remote Policy | hybrid |
| Country | United States |
| Region | TX |
| City | Arlington |
| Salary Raw | Description Why GMF Cybersecurity? Innovation isn’t just a talking point at GM Financial, it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment. Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies. Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive. This position will be posted until filled. Responsibilities About the role The Cybersecurity Engineer – Incident Response Detection Engineer is responsible for designing proactive defenses that keep us ahead of evolving cyber threats. In this role, you’ll leverage SIEM analytics and detection engineering techniques to craft precise detection rules, optimize log analysis, and identify anomalous activity using a wide variety of tooling across on-prem and cloud environments. Security technologies may include but are not limited to: Data Loss Prevention (DLP), Security Incident Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Intrusion Detections System (IDS)/Intrusion Prevention System (IPS), Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR), Network Detection and Response (NDR), Security Orchestration, Automation and Response (SOAR), and Web and Email Security Tooling. In this role you will: Develop and maintain detection rules at source and within a SIEM to identify anomalous behaviors, suspicious activity, and emerging threats across on-prem and cloud environments Manage, filter, and correlate high-volume telemetry from multiple sources to produce actionable insights Align detection engineering efforts with CSIRT operational goals, ensuring seamless integration with incident response workflows and Detection as Code (DaC) Pipelines Continuously improve alert fidelity by tuning detection logic and reducing false positives Perform threat hunting and detection gap analysis to proactively identify coverage gaps and strengthen detection capabilities Investigate security incidents from detection to resolution, engaging in any containment, eradication and recovery actions as needed Conduct purple teaming exercises and analyze resulting log activity to validate detection coverage and identify gaps Collaborate with our threat intelligence team to incorporate emerging indicators and TTPs into detection strategies Document detection logic, tuning, playbooks and validation results for transparency, auditability, and knowledge sharing Stay current with evolving attack techniques and security technologies to adapt detection strategies accordingly Participate in an on ‑ call rotation as needed to support timely response to security incidents outside of standard business hours Qualifications What makes You an ideal candidate? Knowledge and Skills Strong technical skills and hands on experience in Cybersecurity Defensive Operations as it relates to alert triage, on-going monitoring, detection, investigation, and incident response activities Understanding of Cybersecurity concepts such as SIEM analytics, Endpoint security, Network security, Cloud security, Data Loss Prevention/Data Privacy, and Web/Email security Practical understanding of the NIST Incident Response Life Cycle and the MITRE ATT&CK Framework Demonstrate familiarity with AI and large language models (LLMs) and their application in cybersecurity, including how they can support threat detection, analysis, and decision ‑ making Strong knowledge of the OSI model and security that is associated with each layer Strong knowledge of core Information Technology concepts such as TCP/IP networking, Windows & Active Directory, Unix/Linux/Mac, web/email traffic fundamentals, and using a command line interface (CLI) Practical understanding of cloud providers, technologies, and concepts Understanding of Agile, CI/CD, and DevOps environments Experience with scripting languages such as Python or PowerShell Demonstrated ability to communicate across multiple levels of stakeholders Ability to document and summarize technical evidence and findings Good interpersonal, verbal, and written communication skills across various mediums Detail oriented with good time and analytical skills Ability to exercise prudent judgment and offer knowledgeable recommendations Ability to work both independently and in a team environment Ability to manage multiple projects, tasks, and investigations Ability to work in sensitive situations Be a reputable representative of the department Attention to detail and ability to formulate decisions based on evidence gathering Education & Work Experience High School Diploma or equivalent required Bachelor’s Degree in related field or equivalent work experience strongly preferred 1-5 years of experience in large and complex business environments with a successful track record working directly with senior level management preferred 1-5 years of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering, or Network Operations, Information Technology, Application Development preferred Licenses and Certifications One or more security related certifications, such as CISSP, CCNP-Security, GIAC, CEH, or CPTS highly preferred What We Offer : Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays. Our Culture: Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive. Compensation: Competitive pay and bonus eligibility. Work Life Balance: Flexible hybrid work environment, 4-days a week in office. NOTE: We are unable to consider candidates who require visa sponsorship for this position This position is not open to agency submissions #GMFJobs #LI-ST1 #LI-Hybrid |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | day |
| Source URL | https://fa-exvu-saasfaprod1.fa.ocs.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/260063 |
| Apply URL | https://fa-exvu-saasfaprod1.fa.ocs.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/260063 |
| First Seen At | 2026-05-31 18:15:50Z |
| Last Seen At | 2026-06-06 11:21:37Z |
| Last Checked At | 2026-06-06 11:21:37Z |
| Last Changed At | 2026-06-03 11:56:20Z |
| Inactive At | — |
| Source Posted At | 2026-05-18 11:52:11Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=oracle_hcm/board=fa-exvu-saasfaprod1.fa.ocs.oraclecloud.com|CX_1/date=2026-06-06/2026-06-06T11-21-30-248Z-a86cc81096cf82f57e899a35b68f6f29317e08f012856cb004f384fe00d05c0e.json |
Event Fields
{
"content_hash": "86b6630a3ac48aca071a8c73c33195995d496f0f77d2a9e8a8350517b7ebc912",
"source_hash": "d9ac51b45bf40655ce7fd11a214f6142b3e6f2ec548ab071132f706df2898099",
"last_changed_at": "2026-06-03T11:56:20.466Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Arlington, TX, United States",
"city": "Arlington",
"region": "TX",
"country": "United States",
"is_remote": false,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T11:21:37.455Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "Arlington, TX, United States",
"city": "Arlington",
"region": "TX",
"country": "United States",
"is_remote": false,
"confidence": 0.8
},
"countries": [
"United States"
]
},
"remote_policy": "hybrid",
"salary_period": "day",
"workplace_type": "hybrid",
"salary_currency": null
}Extensions
{}Native Structured
{
"detail": {
"Id": "260063",
"Title": "Cybersecurity Engineer",
"media": [],
"skills": [],
"JobType": null,
"Category": "Technology",
"JobGrade": null,
"JobLevel": null,
"JobShift": null,
"WorkDays": null,
"WorkHours": null,
"WorkYears": null,
"Department": null,
"HotJobFlag": false,
"StudyLevel": null,
"WorkMonths": null,
"WorkerType": null,
"GeographyId": 100000029509895,
"JobFamilyId": 300000008745193,
"JobFunction": "Individual Contributor",
"JobSchedule": "Full time",
"BusinessUnit": null,
"ContractType": null,
"Organization": null,
"TrendingFlag": false,
"workLocation": [
{
"Country": "US",
"Region1": "Tarrant",
"Region2": "TX",
"Region3": null,
"Building": null,
"Latitude": "32.69492",
"Longitude": "-97.08886",
"LocationId": 300000008728497,
"PostalCode": "76014",
"TownOrCity": "Arlington",
"AddressLine1": "4001 Embarcadero",
"AddressLine2": null,
"AddressLine3": null,
"AddressLine4": null,
"LocationName": "US - Arlington AOC I, TX"
}
],
"ContentLocale": "en",
"HiringManager": null,
"LegalEmployer": null,
"RequisitionId": 300000259293647,
"WorkplaceType": "Hybrid",
"BusinessUnitId": 300000008619124,
"OrganizationId": 300000008750581,
"GeographyNodeId": 100000221362191,
"JobFunctionCode": "IND_CONT",
"LegalEmployerId": 300000008558108,
"PrimaryLocation": "Arlington, TX, United States",
"RequisitionType": "Employee",
"NumberOfOpenings": null,
"WorkplaceTypeCode": "ORA_HYBRID",
"BeFirstToApplyFlag": false,
"otherWorkLocations": [],
"secondaryLocations": [
{
"Name": "Irving, TX, United States",
"Latitude": "32.81352",
"Longitude": "-96.95532",
"CountryCode": "US",
"GeographyId": 100000029509305,
"GeographyNodeId": 100000221362201,
"RequisitionLocationId": 300000259293652
},
{
"Name": "Fort Worth, TX, United States",
"Latitude": "33.0173",
"Longitude": "-97.31038",
"CountryCode": "US",
"GeographyId": 100000029509610,
"GeographyNodeId": 100000221362182,
"RequisitionLocationId": 300000259293653
}
],
"ExternalContactName": null,
"ShortDescriptionStr": "Designs, tunes, and maintains high‑fidelity cybersecurity detections across the incident response lifecycle, ensuring alerts are accurate, actionable, and aligned to investigation and response workflows. Leverages advanced analytics and AI‑assisted techniques to reduce noise, accelerate investigations, and improve detection quality at scale.\n\nThis opportunity is open to Mid and Senior Level engineers.",
"ExternalContactEmail": null,
"ExternalPostedEndDate": null,
"OtherRequisitionTitle": null,
"requisitionFlexFields": [],
"ApplyWhenNotPostedFlag": null,
"DomesticTravelRequired": null,
"ExternalDescriptionStr": "<div style=\"border-width: medium; border-style: none; border-color: currentcolor; border-image: initial; padding: 0cm 0cm 1pt;\"><p style=\"border-width: medium; border-style: none; border-color: currentcolor; border-image: initial; padding: 0cm;\"><span lang=\"EN-US\"><strong>Why GMF Cybersecurity?</strong></span></p><p style=\"border-width: medium; border-style: none; border-color: currentcolor; border-image: initial; padding: 0cm;\"><span lang=\"EN-US\">Innovation isn’t just a talking point at GM Financial, it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.</span></p><p style=\"border-width: medium; border-style: none; border-color: currentcolor; border-image: initial; padding: 0cm;\"><span lang=\"EN-US\">Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.</span></p><p style=\"border-width: medium; border-style: none; border-color: currentcolor; border-image: initial; padding: 0cm;\"><span lang=\"EN-US\">Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive. </span></p><p style=\"border-width: medium; border-style: none; border-color: currentcolor; border-image: initial; padding: 0cm;\"> </p><p style=\"border-width: medium; border-style: none; border-color: currentcolor; border-image: initial; padding: 0cm;\"><span lang=\"EN-US\">This position will be posted until filled.</span></p></div>",
"ObjectVerNumberProfile": "2",
"PrimaryLocationCountry": "US",
"CorporateDescriptionStr": "",
"ExternalPostedStartDate": "2026-05-18T11:52:11+00:00",
"ExternalQualificationsStr": "<p><strong>What makes You an ideal candidate?</strong></p><p><strong>Knowledge and Skills</strong></p><ul style=\"list-style-type: disc;\"><li>Strong technical skills and hands on experience in Cybersecurity Defensive Operations as it relates to alert triage, on-going monitoring, detection, investigation, and incident response activities</li><li>Understanding of Cybersecurity concepts such as SIEM analytics, Endpoint security, Network security, Cloud security, Data Loss Prevention/Data Privacy, and Web/Email security</li><li>Practical understanding of the NIST Incident Response Life Cycle and the MITRE ATT&CK Framework</li><li>Demonstrate familiarity with AI and large language models (LLMs) and their application in cybersecurity, including how they can support threat detection, analysis, and decision<span style=\"font-family: "Cambria Math", serif;\">‑</span>making</li><li>Strong knowledge of the OSI model and security that is associated with each layer</li><li>Strong knowledge of core Information Technology concepts such as TCP/IP networking, Windows & Active Directory, Unix/Linux/Mac, web/email traffic fundamentals, and using a command line interface (CLI)</li><li>Practical understanding of cloud providers, technologies, and concepts</li><li>Understanding of Agile, CI/CD, and DevOps environments</li><li>Experience with scripting languages such as Python or PowerShell</li><li>Demonstrated ability to communicate across multiple levels of stakeholders</li><li>Ability to document and summarize technical evidence and findings</li><li>Good interpersonal, verbal, and written communication skills across various mediums</li><li>Detail oriented with good time and analytical skills</li><li>Ability to exercise prudent judgment and offer knowledgeable recommendations</li><li>Ability to work both independently and in a team environment</li><li>Ability to manage multiple projects, tasks, and investigations</li><li>Ability to work in sensitive situations</li><li>Be a reputable representative of the department</li><li>Attention to detail and ability to formulate decisions based on evidence gathering</li></ul><p> </p><p><strong>Education & Work Experience</strong></p><ul><li>High School Diploma or equivalent required</li><li>Bachelor’s Degree in related field or equivalent work experience strongly preferred</li><li>1-5 years of experience in large and complex business environments with a successful track record working directly with senior level management preferred</li><li>1-5 years of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering, or Network Operations, Information Technology, Application Development preferred</li></ul><p> </p><p><strong>Licenses and Certifications</strong></p><ul><li>One or more security related certifications, such as CISSP, CCNP-Security, GIAC, CEH, or CPTS highly preferred</li></ul><p> </p><p><span lang=\"EN-US\"><strong>What We Offer</strong>: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.</span></p><p><span lang=\"EN-US\"><strong>Our Culture:</strong> Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.</span></p><p><span lang=\"EN-US\"><strong>Compensation:</strong> Competitive pay and bonus eligibility.</span></p><p><span lang=\"EN-US\"><strong>Work Life Balance:</strong> Flexible hybrid work environment, 4-days a week in office.</span></p><p><span lang=\"EN-US\"><strong>NOTE:</strong></span><i><span lang=\"EN-US\"> <strong>We are unable to consider candidates who require visa sponsorship for this position</strong></span></i></p><p><span lang=\"EN-US\"><strong>This position is not open to agency submissions</strong></span></p><p style=\"margin-left: 18pt;\"><span style=\"color: white;\"><span lang=\"EN-US\">#GMFJobs</span></span></p><p style=\"margin-left: 18pt;\"><span style=\"color: white;\"><span lang=\"EN-US\">#LI-ST1</span></span></p><p style=\"margin-left: 18pt;\"><span style=\"color: white;\"><span lang=\"EN-US\">#LI-Hybrid</span></span></p>",
"InternalQualificationsStr": "<p><strong>What makes You an ideal candidate?</strong></p><p><strong>Knowledge and Skills</strong></p><ul style=\"list-style-type: disc;\"><li>Strong technical skills and hands on experience in Cybersecurity Defensive Operations as it relates to alert triage, on-going monitoring, detection, investigation, and incident response activities</li><li>Understanding of Cybersecurity concepts such as SIEM analytics, Endpoint security, Network security, Cloud security, Data Loss Prevention/Data Privacy, and Web/Email security</li><li>Practical understanding of the NIST Incident Response Life Cycle and the MITRE ATT&CK Framework</li><li>Demonstrate familiarity with AI and large language models (LLMs) and their application in cybersecurity, including how they can support threat detection, analysis, and decision<span style=\"font-family: "Cambria Math", serif;\">‑</span>making</li><li>Strong knowledge of the OSI model and security that is associated with each layer</li><li>Strong knowledge of core Information Technology concepts such as TCP/IP networking, Windows & Active Directory, Unix/Linux/Mac, web/email traffic fundamentals, and using a command line interface (CLI)</li><li>Practical understanding of cloud providers, technologies, and concepts</li><li>Understanding of Agile, CI/CD, and DevOps environments</li><li>Experience with scripting languages such as Python or PowerShell</li><li>Demonstrated ability to communicate across multiple levels of stakeholders</li><li>Ability to document and summarize technical evidence and findings</li><li>Good interpersonal, verbal, and written communication skills across various mediums</li><li>Detail oriented with good time and analytical skills</li><li>Ability to exercise prudent judgment and offer knowledgeable recommendations</li><li>Ability to work both independently and in a team environment</li><li>Ability to manage multiple projects, tasks, and investigations</li><li>Ability to work in sensitive situations</li><li>Be a reputable representative of the department</li><li>Attention to detail and ability to formulate decisions based on evidence gathering</li></ul><p> </p><p><strong>Education & Work Experience</strong></p><ul><li>High School Diploma or equivalent required</li><li>Bachelor’s Degree in related field or equivalent work experience strongly preferred</li><li>1-5 years of experience in large and complex business environments with a successful track record working directly with senior level management preferred</li><li>1-5 years of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering, or Network Operations, Information Technology, Application Development preferred</li></ul><p> </p><p><strong>Licenses and Certifications</strong></p><ul><li>One or more security related certifications, such as CISSP, CCNP-Security, GIAC, CEH, or CPTS highly preferred</li></ul><p> </p><p><span lang=\"EN-US\"><strong>What We Offer</strong>: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.</span></p><p><span lang=\"EN-US\"><strong>Our Culture:</strong> Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.</span></p><p><span lang=\"EN-US\"><strong>Compensation:</strong> Competitive pay and bonus eligibility.</span></p><p><span lang=\"EN-US\"><strong>Work Life Balance:</strong> Flexible hybrid work environment, 4-days a week in office.</span></p><p><span lang=\"EN-US\"><strong>NOTE:</strong></span><i><span lang=\"EN-US\"> <strong>We are unable to consider candidates who require visa sponsorship for this position</strong></span></i></p><p><span lang=\"EN-US\"><strong>This position is not open to agency submissions</strong></span></p><p style=\"margin-left: 18pt;\"><span style=\"color: white;\"><span lang=\"EN-US\">#GMFJobs</span></span></p><p style=\"margin-left: 18pt;\"><span style=\"color: white;\"><span lang=\"EN-US\">#LI-ST1</span></span></p><p style=\"margin-left: 18pt;\"><span style=\"color: white;\"><span lang=\"EN-US\">#LI-Hybrid</span></span></p>",
"OrganizationDescriptionStr": "",
"primaryLocationCoordinates": [
{
"Latitude": "32.7356",
"Longitude": "-97.10772",
"CountryCode": "US",
"GeographyId": 100000029509895,
"GeographyNodeId": 100000221362191
}
],
"ExternalResponsibilitiesStr": "<p><strong>About the role</strong></p><p>The Cybersecurity Engineer – Incident Response Detection Engineer is responsible for designing proactive defenses that keep us ahead of evolving cyber threats. In this role, you’ll leverage SIEM analytics and detection engineering techniques to craft precise detection rules, optimize log analysis, and identify anomalous activity using a wide variety of tooling across on-prem and cloud environments. Security technologies may include but are not limited to: Data Loss Prevention (DLP), Security Incident Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Intrusion Detections System (IDS)/Intrusion Prevention System (IPS), Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR), Network Detection and Response (NDR), Security Orchestration, Automation and Response (SOAR), and Web and Email Security Tooling.</p><p><strong>In this role you will:</strong></p><ul style=\"list-style-type: disc;\"><li>Develop and maintain detection rules at source and within a SIEM to identify anomalous behaviors, suspicious activity, and emerging threats across on-prem and cloud environments</li><li>Manage, filter, and correlate high-volume telemetry from multiple sources to produce actionable insights</li><li>Align detection engineering efforts with CSIRT operational goals, ensuring seamless integration with incident response workflows and Detection as Code (DaC) Pipelines</li><li>Continuously improve alert fidelity by tuning detection logic and reducing false positives</li><li>Perform threat hunting and detection gap analysis to proactively identify coverage gaps and strengthen detection capabilities</li><li>Investigate security incidents from detection to resolution, engaging in any containment, eradication and recovery actions as needed</li><li>Conduct purple teaming exercises and analyze resulting log activity to validate detection coverage and identify gaps</li><li>Collaborate with our threat intelligence team to incorporate emerging indicators and TTPs into detection strategies</li><li>Document detection logic, tuning, playbooks and validation results for transparency, auditability, and knowledge sharing</li><li>Stay current with evolving attack techniques and security technologies to adapt detection strategies accordingly</li><li>Participate in an on<span style=\"font-family: "Cambria Math", serif;\">‑</span>call rotation as needed to support timely response to security incidents outside of standard business hours</li></ul>",
"InternalResponsibilitiesStr": "<p><strong>About the role</strong></p><p>The Cybersecurity Engineer – Incident Response Detection Engineer is responsible for designing proactive defenses that keep us ahead of evolving cyber threats. In this role, you’ll leverage SIEM analytics and detection engineering techniques to craft precise detection rules, optimize log analysis, and identify anomalous activity using a wide variety of tooling across on-prem and cloud environments. Security technologies may include but are not limited to: Data Loss Prevention (DLP), Security Incident Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Intrusion Detections System (IDS)/Intrusion Prevention System (IPS), Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR), Network Detection and Response (NDR), Security Orchestration, Automation and Response (SOAR), and Web and Email Security Tooling.</p><p><strong>In this role you will:</strong></p><ul style=\"list-style-type: disc;\"><li>Develop and maintain detection rules at source and within a SIEM to identify anomalous behaviors, suspicious activity, and emerging threats across on-prem and cloud environments</li><li>Manage, filter, and correlate high-volume telemetry from multiple sources to produce actionable insights</li><li>Align detection engineering efforts with CSIRT operational goals, ensuring seamless integration with incident response workflows and Detection as Code (DaC) Pipelines</li><li>Continuously improve alert fidelity by tuning detection logic and reducing false positives</li><li>Perform threat hunting and detection gap analysis to proactively identify coverage gaps and strengthen detection capabilities</li><li>Investigate security incidents from detection to resolution, engaging in any containment, eradication and recovery actions as needed</li><li>Conduct purple teaming exercises and analyze resulting log activity to validate detection coverage and identify gaps</li><li>Collaborate with our threat intelligence team to incorporate emerging indicators and TTPs into detection strategies</li><li>Document detection logic, tuning, playbooks and validation results for transparency, auditability, and knowledge sharing</li><li>Stay current with evolving attack techniques and security technologies to adapt detection strategies accordingly</li><li>Participate in an on<span style=\"font-family: "Cambria Math", serif;\">‑</span>call rotation as needed to support timely response to security incidents outside of standard business hours</li></ul>",
"InternationalTravelRequired": null
},
"list_job": {
"Id": "260063",
"Title": "Cybersecurity Engineer",
"JobType": null,
"Distance": 1779062400000,
"JobShift": null,
"Language": "US",
"WorkDays": null,
"JobFamily": null,
"Relevancy": 3,
"WorkHours": null,
"Department": null,
"HotJobFlag": false,
"PostedDate": "2026-05-18",
"StudyLevel": null,
"WorkerType": null,
"GeographyId": 100000029509895,
"JobFunction": null,
"JobSchedule": null,
"BusinessUnit": null,
"ContractType": null,
"ManagerLevel": null,
"Organization": null,
"TrendingFlag": false,
"workLocation": [
{
"Country": "US",
"Region1": "Tarrant",
"Region2": "TX",
"Region3": null,
"Building": null,
"Latitude": 32.69492,
"Longitude": -97.08886,
"LocationId": 300000008728497,
"PostalCode": "76014",
"TownOrCity": "Arlington",
"AddressLine1": "4001 Embarcadero",
"AddressLine2": null,
"AddressLine3": null,
"AddressLine4": null,
"LocationName": "US - Arlington AOC I, TX"
}
],
"LegalEmployer": null,
"MediaThumbURL": null,
"WorkplaceType": "Hybrid",
"BusinessUnitId": 300000008619124,
"OrganizationId": 300000008750581,
"PostingEndDate": null,
"LegalEmployerId": 300000008558108,
"PrimaryLocation": "Arlington, TX, United States",
"WorkDurationYears": null,
"WorkplaceTypeCode": "ORA_HYBRID",
"BeFirstToApplyFlag": false,
"WorkDurationMonths": null,
"otherWorkLocations": [],
"secondaryLocations": [
{
"Name": "Irving, TX, United States",
"Latitude": 32.81352,
"Longitude": -96.95532,
"CountryCode": "US",
"GeographyId": 100000029509305,
"GeographyNodeId": 100000221362201,
"RequisitionLocationId": 300000259293652
},
{
"Name": "Fort Worth, TX, United States",
"Latitude": 33.0173,
"Longitude": -97.31038,
"CountryCode": "US",
"GeographyId": 100000029509610,
"GeographyNodeId": 100000221362182,
"RequisitionLocationId": 300000259293653
}
],
"ShortDescriptionStr": "Designs, tunes, and maintains high‑fidelity cybersecurity detections across the incident response lifecycle, ensuring alerts are accurate, actionable, and aligned to investigation and response workflows. Leverages advanced analytics and AI‑assisted techniques to reduce noise, accelerate investigations, and improve detection quality at scale.\n\nThis opportunity is open to Mid and Senior Level engineers.",
"requisitionFlexFields": [],
"DomesticTravelRequired": null,
"PrimaryLocationCountry": "US",
"ExternalQualificationsStr": null,
"ExternalResponsibilitiesStr": null,
"InternationalTravelRequired": null
},
"detail_meta": {
"url": "https://fa-exvu-saasfaprod1.fa.ocs.oraclecloud.com/hcmRestApi/resources/latest/recruitingCEJobRequisitionDetails?expand=all&onlyData=true&finder=ById;Id=%22260063%22,siteNumber=CX_1",
"http_status": 200,
"content_type": "application/json",
"response_bytes": 19915
},
"detail_errors": []
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/d21d49b53d2c21d8b99e57ece5bd83e15d9f71b2?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/75949101-40bb-42f4-afdd-cf86ec16bd86JSONGET https://api.bluedoor.sh/job-postings/v1/sources/f6d0cadf-249b-4136-83dc-06ed741e1fb3JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/d21d49b53d2c21d8b99e57ece5bd83e15d9f71b2/eventsJSON