Cyber Defense Analyst
Ford MotorJob Description
Cyber Defense Analyst
The Ford AI-Enhanced Cyber Defense team comprises highly technical security experts dedicated to defending Ford Motor Company against sophisticated cybersecurity attacks. This role moves beyond traditional L1/L2 segregation, providing an end-to-end service that leverages cutting-edge Artificial Intelligence (AI) and Machine Learning (ML) capabilities to identify, analyze, communicate, and proactively contain cyber threats. The primary goal is to protect the organization from advanced threat actors, minimize the impact of incidents through AI-accelerated response, and continuously enhance our defensive posture using intelligent systems. This position is central to evolving Ford's cyber defense into an adaptive, predictive, and autonomous capability.
AI-Driven Detection and Automated Response:
Harness AI/ML-powered platforms and solutions to identify, defend against, and mitigate a wide spectrum of attacks, including sophisticated web application attacks, reconnaissance, advanced network intrusions (e.g., Windows Active Directory, cloud environments), credential attacks, post-exploitation techniques, drive-by attacks, and endpoint compromises.
Manage AI-driven anomaly detection systems to proactively identify the use of covert tools, exploitation techniques, and evasive methods employed by threat actors, ensuring rapid detection of stealthy activities.
Command and orchestrate defensive AI agents to engage directly against adversarial agents within the network, leading defensive 'swarms' to hunt malicious code, stop attack sequences, and initiate automated system repair at machine speed, far outpacing human capabilities.
Orchestrate AI agents and automated playbooks to accelerate incident containment and remediation processes, significantly reducing dwell time and minimizing impact.
Conduct deep-dive investigations on critical security incidents, leveraging AI-assisted forensic analysis, AI-powered malware analysis, and AI-enhanced network investigation tools to understand attack vectors, scope, and impact, ensuring comprehensive containment and remediation.
- Utilize AI/ML for proactive threat identification through advanced malware analysis, reverse engineering, and behavioral profiling, anticipating emerging threats before they materialize.
AI-Powered Threat Hunting:
Lead and execute AI-driven threat hunting operations, transforming raw threat intelligence into immediate, actionable hunting queries and patterns of activity for deployment across enterprise networks.
Develop and refine AI/ML models to identify and observe subtle malware indicators and sophisticated adversary Tactics, Techniques, and Procedures (TTPs), generating highly accurate and predictive threat intelligence.
Proactively hunt down, identify, counter, and recover from a wide range of advanced threats, including APT nation-state adversaries, organized crime syndicates, and AI-enhanced ransomware operators, leveraging AI to predict their movements and adapt defensive strategies.
- Design, develop, and implement AI-powered tools, techniques, and procedures (TTPs) for automated hunting, detection, and containment, enhancing the efficiency and effectiveness of our cyber defense operations.
- Collaborate with AI Threat Intelligence Analysts to integrate AI-generated insights into defensive strategies and automated response mechanisms.
AI-Driven Prompt Orchestration:
- Contribute to the development and optimization of AI models for security applications, including threat prediction, anomaly detection, and automated response.
- AI-powered Security Orchestration, Automation, and Response (SOAR) platforms, enabling autonomous detection, investigation, correlation, and response to threats.
- Utilize Prompt Engineering techniques to optimize AI model interactions for security analysis, threat hunting, and incident response, developing prompt libraries for various security AI tools.
Basic Qualifications:
Bachelor’s Degree in Computer Science, Cybersecurity, Data Science, or a related field.
3+ Years of Information Technology (IT) experience, with at least 1 year demonstrating practical application of AI/ML concepts in a security context.
Industry Certifications:
GCIH (GIAC Certified Incident Handler)
GREM (GIAC Reverse Engineering Malware)
GCFA (GIAC Certified Forensic Analyst)
Recommended AI/ML Security Certifications Relevant such as SANS, GCP, Azure certifications focused on AI/ML in cybersecurity or other advanced AI/ML security accreditations.
Core Knowledge: SIEM (e.g., QRadar, Splunk, Chronicle), EDR, IDS/IPS, Windows, Linux, Firewall, Cloud Security, OSINT, Sandbox, Phishing analysis, Malware analysis.
AI Focus: Understanding of AI/ML concepts in cybersecurity, ability to interpret AI-generated alerts and insights, foundational knowledge of prompt engineering for security tools.
Scripting knowledge: Well versed in atleast one scripting language (Powershell/Python/Shell etc)
Skill matrix required as below (0-5, 5 being the highest)
Detection & Monitoring
- SIEM Tools (QRadar, Splunk, Chronicle) – Skill Rating Required: 4
- AI-Driven Detection & Defense (Windows, Linux, Industrial Systems) – Skill Rating Required: 3–4
- EDR/XDR and AI-Enhanced SOAR – Skill Rating Required: 3–4
- AI-Enhanced Email Analysis (Proofpoint, OSINT) – Skill Rating Required: 3–4
Network & Threat Analysis
- Network Protocols & AI-Accelerated Packet Analysis (Wireshark, tcpdump) – Skill Rating Required: 3–4
- RegEx (AI-Assisted Searches, Log Parsing) – Skill Rating Required: 3–4
Digital Forensics & Investigation
- AI-Assisted Digital Forensics (EnCase, FTK, Autopsy) – Skill Rating Required: 2–3
- AI-Driven Memory Investigation (Volatility, ResponderPro, Axiom) – Skill Rating Required: 3–4
Malware & Threat Research
- AI-Powered Malware Analysis (Static, Dynamic, Reverse Engineering) – Skill Rating Required: 2–3
AI/ML & Automation
- AI/ML Automation and Scripting (Python, PowerShell, Shell) – Skill Rating Required: 3–4
- Prompt Engineering for Security Applications – Skill Rating Required: 2
- AI/ML Model Understanding & Application (Security Context) – Skill Rating Required: 2
Cloud Security
- Cloud AI Security Simulation (GCP, Azure) – Skill Rating Required: 2–3
Experience Level
Senior LevelJob role
Job requirements
About company
Similar jobs you can apply for
Manufacturing / Production
Network Engineer
Careerlink HR Solution LLPAirtel WIFI Installation
Quess Corp LimitedGraduate Engineer Trainee
Suba solutions pvt ltdLaptop Technician
Iat NetworksAssest Management
Radiant Cash Management Services LimitedInstallation Engineer
AirtelYou can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.
The candidate should have completed the required education and people who have 5 to 31 years are eligible to apply for this job. You can apply for more jobs in Chennai to get hired quickly.
The candidate should have sound communication skills and sound communication skills for this job.
Both Male and Female candidates can apply for this job.
No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Chennai at apna.
No work-related deposit needs to be made during your employment with the company.
Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.
The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Chennai . Through apna, you can find jobs in 64 cities across India. Join NOW!