CSIRT Manager

Reposted 5 Days Ago
Be an Early Applicant
Auburn Hills, MI
In-Office
Senior level
Automotive
The Role
The CSIRT Manager leads the Cyber Security Incident Response Team, managing incident response lifecycles, team development, and crisis command while ensuring compliance with security policies.
Summary Generated by Built In
Job Summary & Responsibilities

Description:

The CSIRT Manager leads the Cyber Security Incident Response Team (CSIRT), operating within Stellantis’ Cyber Defense Operations Center (CDOC) and in close partnership with several others cybersecurity teams, and regional stakeholders. You will own the incident response lifecycle, ensure adherence to Stellantis crisis procedures, drive operational excellence (MTTD/MTTR), and cultivate a high performing team in a follow the sun model

Stellantis is a global mobility leader with the ambition to deliver clean, safe, and affordable freedom of mobility for all, guided by the Dare Forward 2030 strategy and a commitment to carbon net zero by 2038 (Scopes 1–3) with interim 2030 decarbonization targets. Our portfolio of iconic brands and strong operational performance underpin this transformation into a sustainable mobility tech company.


Key responsibilities:

  • Own the IR Lifecycle & Escalation: Direct the end-to-end response across preparation, detection/analysis, containment, eradication, recovery, and post incident, following
  • Lead & Develop the Team: Manage, mentor, and schedule CSIRT analysts and leads across shifts and on call rotations within the distributed regional model; drive skills development and readiness.
  • Command During Crises: Serve as Incident Commander for high/critical events and integrate the right SMEs into the crisis cell, ensuring disciplined communications and handoffs as defined in the CSIR crisis process.
  • Metrics & Reporting: Establish, track, and improve KPIs/SLAs (e.g., MTTD, MTTR, containment time, PIR completion) and present status in monthly business reviews and dashboards.
  • Playbooks, Use Cases & Lessons Learned: Ensure playbooks/response procedures are current and threat informed; feed PIR insights back into detections, SOAR workflows, and control hardening in partnership with platform engineering and detection teams.
  • Cross Functional Orchestration: Coordinate with CDOC other products (CTI, Redteam, Monitoring) and Legal/Privacy, Comms, and business/IT/Cloud owners; align to the SOC Target Operating Model and service catalogue.
  • Threat Informed Response: Consume and task Cyber Threat Intelligence and threat hunting to guide scoping, IOCs, and hypotheses; ensure bidirectional feedback between CTI, Red Team, and CSIRT.
  • Tooling & Case Management: Ensure consistent use of the incident/case platform and evidence handling procedures; maintain audit ready documentation and artifacts.
  • Vendor & Retainer Oversight: Govern IR retainer(s) and MSSP engagements; validate service performance and integration with internal processes.
  • Compliance & Governance: Ensure incident handling aligns with Stellantis policy, applicable regulations, and internal governance boards; prepare materials for audits, PIRs, and leadership readouts (per SOC governance and crisis documentation).

Sample Duties:

  • Direct major incident bridges, integrate SMEs, and ensure timely executive updates per crisis process; confirm accurate status tracking and next actions.
  • Oversee investigations (host/network/cloud), evidence handling, and scoping; validate containment/eradication and business recovery while maintaining audit‑ready documentation.
  • Run post‑incident reviews and feed structured improvements into playbooks/use cases and control posture, track remediation to closure.
  • Report KPIs/SLAs and risk themes in monthly reviews; align resourcing and tooling roadmaps to findings. 
  • Coordinate with CTI for threat‑informed scoping and proactive hunts; ensure bi‑directional intel sharing and IOC packages. 

 

 

Preferred Qualifications

Basic Qualifications:

  • Bachelor’s degree (or equivalent experience) in Cybersecurity, Computer Science, or related field.
  • 5+ years in SOC/IR roles with 2+ years managing incident response teams or programs in large, distributed enterprises.
  • Demonstrated leadership during high/critical incidents and familiarity with crisis management communications per established escalation matrices.
  • Hands on knowledge of SIEM/SOAR, EDR, network security monitoring, IA detection & Response tools/ framework and cloud/identity telemetry; strong grasp of attacker TTPs and enterprise hardening.
  • Experience operating to structured IR frameworks (e.g., NIST style lifecycle) and running formal after action/lessons learned cycles integrated with use case/playbook updates.
  • Excellent written/oral communication, stakeholder management, and executive reporting skills; comfortable presenting in MBRs and steering forums.

Preferred Qualifications:

  • Prior leadership within a CSIRT/CSOC supporting multiple regions and product/OT security stakeholders. 
  • Certifications : GCIH, GCFA/GNFA, GCIA, CISSP, OSCP(or comparable).
  • Experience with threat‑informed defense (MITRE ATT&CK), KPI/SLA governance, and MSSP/retainer management.
  • Familiarity with worldwide privacy/security obligations and incident communication expectations in regulated, multi‑jurisdictional environments (in partnership with Legal/Privacy).

 

Essential Skills & Competences:

  • Crisis Leadership: Decisive command in high pressure situations, with disciplined adherence to escalation and executive comms playbooks.
  • Operational Excellence: KPI driven mindset; ability to translate PIR insights into upgraded detections, controls, and automations.
  • Collaboration & Influence: Build strong relationships across CSOC, PSOC, CTI, Red Team, platform engineering, and business/IT owners.
  • Communication: Clear incident narratives, timelines, and executive one pager; ability to brief senior leadership succinctly.

Top Skills

Edr
Nist Framework
SIEM
Soar
Threat Intelligence
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Amsterdam
104,031 Employees

What We Do

Our storied and iconic brands embody the passion of their visionary founders and today’s customers in their innovative products and services: they include Abarth, Alfa Romeo, Chrysler, Citroën, Dodge, DS Automobiles, Fiat, Jeep®, Lancia, Maserati, Opel, Peugeot, Ram, Vauxhall and mobility brands Free2move and Leasys. Powered by our diversity, we lead the way the world moves – aspiring to become the greatest sustainable mobility tech company, not the biggest, while creating added value for all stakeholders as well as the communities in which we operate.

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

Principal Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Sterling Heights, MI, USA
40000 Employees
130K-222K Annually

Deepgram Logo Deepgram

Research Staff, LLMs

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
2 Locations
150 Employees
150K-250K Annually

Magna International Logo Magna International

Environmental Health and Safety (EHS) Specialist

Automotive • Hardware • Robotics • Software • Transportation • Manufacturing
Hybrid
Troy, MI, USA
171000 Employees

Magna International Logo Magna International

Account Manager

Automotive • Hardware • Robotics • Software • Transportation • Manufacturing
Hybrid
Troy, MI, USA
171000 Employees

Similar Companies Hiring

Cox Enterprises Thumbnail
Software • Other • Information Technology • Greentech • Cybersecurity • Cloud • Automotive
Atlanta, GA
50000 Employees
UL Solutions Thumbnail
Software • Renewable Energy • Professional Services • Energy • Consulting • Chemical • Automotive
Chicago, IL
15000 Employees
HERE Technologies Thumbnail
Software • Logistics • Internet of Things • Information Technology • Computer Vision • Automotive • Artificial Intelligence
Amsterdam, NL
6000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account