Cummins

Principal - Cybersecurity Asset Intelligence

Cummins  •  Columbus, IN (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Responsible for leading the organization’s cybersecurity operations team, with a primary focus on incident response, threat monitoring, and the execution of cybersecurity strategies, policies, and risk management practices to safeguard the organization’s systems, data, and infrastructure. The manager serves as a coach and mentor to security professionals, builds operational processes aligned with best practices and industry standards, and partners with engineering, IT, and business to protect critical systems, infrastructure, and data from evolving threats. Serves as an accountable leader for the people, processes, and technologies that prevent, detect, investigate, and contain cyber threats across enterprise, cloud, and OT environments. Owns SecOps outcomes (24×7 monitoring & incident response), the detection engineering program (use-case lifecycle, signal quality, automation), and the threat hunting program

Key Responsibilities:

Leads the execution of complex responses to computer security incidents in alignment with organizational policies and industry best practices. Coordinates and communicates with multiple business units during incidents, providing updates and actionable recommendations. Oversees root cause analysis and ensures that lessons learned are integrated into improved processes and protections. Leads teams in assessing severity, developing mitigation strategies, and prioritizing risk reduction activities. Monitors security-related intelligence sources (e.g., SANS, BugTraq) to maintain situational awareness of current attacks and trends. Collaborates with Cybersecurity Engineering teams and business to communicate risks and recommend security enhancements. Ensures that security technologies employed by the operations and incident response teams support and enhance operational processes. Identifies opportunities to improve operational efficiency, standard operating procedures, and incident response playbooks. Leads the application of recognized cybersecurity and IT frameworks (e.g., NIST, ISO, ITIL, COBIT) in alignment with organizational processes and controls. Manages, coaches, and mentors cybersecurity operations staff, fostering a culture of learning, accountability, and continuous improvement. Defines team objectives, evaluates performance, and supports professional growth through training and development. Participates in industry task forces and working groups to stay informed on evolving threats and best practices, and fosters a culture of continuous improvement in cybersecurity practices and awareness. Contributes to organizational situational awareness by managing and leveraging cybersecurity data sources.
Competencies: Process Management and Optimization - Designs, refines, and automates IT operations processes to improve efficiency, consistency, service quality, security, and cost effectiveness across diverse environments.
Service Quality and Reliability - Ensures IT services consistently meet performance, availability, and user satisfaction expectations by proactively maintaining service integrity, minimizing disruptions, and driving continuous improvement through collaboration, cost-effective practices, and operational excellence.
Risk Management - Proactively identifies, assesses, and mitigates risks to IT services, data, and operations by applying structured controls and communication strategies to strengthen resilience, ensure compliance, and reduce business impact through structured controls, cost-aware decision-making, and communication strategies.
Incident and Problem Management - Responds to disruptions and recurring issues by restoring service quickly, identifying root causes, and applying structured methods to reduce risk, improve reliability, and prevent recurrence.
Standardization and Documentation - Creates and maintains clear, accessible documentation and standardized procedures to ensure consistent practices, traceability, and knowledge sharing across IT environments.
Technical Passion and Drive - Models curiosity and excitement for technology by self-initiating continuous development, experimenting with emerging technologies, and identifying insertion opportunities that accelerate business performance.
Security and Compliance - Applies standards, tools, and best practices to embed security, privacy, and compliance into the design/build/test/operate lifecycle for products, services, apps, systems, software, and configurations—balancing protection, efficiency, and cost.
Driving Effective Outcomes - Takes ownership, acts with urgency, and initiates action to turn goals into clear plans, decisions, guardrails, and cadences while navigating ambiguity and change to drive momentum and deliver consistent results.
Engaging with Impact - Communicates with clarity and purpose to align stakeholders, foster collaboration, build trust, and influence coordinated action across teams and functions to accelerate outcomes.
Values Differences - Recognizing the value that different perspectives and cultures bring to an organization.
Ensuring Customer Success - Embraces a customer-first mindset to deliver outcomes by linking customer needs and business priorities to aligned solutions, delivery, adoption, satisfaction, and realized value through sustained engagement that builds partnership and trust.
Managing People and Teams - Builds inclusive teams that empower ownership, deepen capabilities, and ensure fair, timely performance accountability, creating an environment where people can deliver their best work and top performance.
Directs Work - Creates conditions for team success with clear goals, priorities, work plans, standards, effective processes, resourcing, and governance to enable fast, empowered, accountable, and quality execution.
Education, Licenses, Certifications: College, university, or equivalent degree in Computer Science, Information Technology, Engineering, or related subject, or relevant equivalent experience required. Global Information Assurance Certification (GIAC) Security Essentials Certification, GIAC Security Leadership Certification, Information Systems Audit and Control Association (ISACA) Certified Information Security Manager, Microsoft Certified Systems Engineer: Security, or Certified Information Systems Security Professional (CISSP) certification preferred. This position may require licensing for compliance with export controls or sanctions regulations.
Experience: Understanding of the capabilities and configuration of industrial cybersecurity controls and solutions across multiple facets; for example: asset management, vulnerability management, anomaly detection, identity and access management, network security, endpoint security, application security, IDS/IPS, deep packet inspection, SIEM, data analytics, security and/or risk management and product development.
Demonstrated ability to lead teams, manage budgets, and build organizational capability.
Excellent communication and stakeholder management skills, with the ability to influence policy and advocate for cybersecurity best practices.
Proven experience in cybersecurity management or equivalent leadership role.
Competencies: Process Management and Optimization - Designs, refines, and automates IT operations processes to improve efficiency, consistency, service quality, security, and cost effectiveness across diverse environments.
Service Quality and Reliability - Ensures IT services consistently meet performance, availability, and user satisfaction expectations by proactively maintaining service integrity, minimizing disruptions, and driving continuous improvement through collaboration, cost-effective practices, and operational excellence.
Risk Management - Proactively identifies, assesses, and mitigates risks to IT services, data, and operations by applying structured controls and communication strategies to strengthen resilience, ensure compliance, and reduce business impact through structured controls, cost-aware decision-making, and communication strategies.
Incident and Problem Management - Responds to disruptions and recurring issues by restoring service quickly, identifying root causes, and applying structured methods to reduce risk, improve reliability, and prevent recurrence.
Standardization and Documentation - Creates and maintains clear, accessible documentation and standardized procedures to ensure consistent practices, traceability, and knowledge sharing across IT environments.
Technical Passion and Drive - Models curiosity and excitement for technology by self-initiating continuous development, experimenting with emerging technologies, and identifying insertion opportunities that accelerate business performance.
Security and Compliance - Applies standards, tools, and best practices to embed security, privacy, and compliance into the design/build/test/operate lifecycle for products, services, apps, systems, software, and configurations—balancing protection, efficiency, and cost.
Driving Effective Outcomes - Takes ownership, acts with urgency, and initiates action to turn goals into clear plans, decisions, guardrails, and cadences while navigating ambiguity and change to drive momentum and deliver consistent results.
Engaging with Impact - Communicates with clarity and purpose to align stakeholders, foster collaboration, build trust, and influence coordinated action across teams and functions to accelerate outcomes.
Values Differences - Recognizing the value that different perspectives and cultures bring to an organization.
Ensuring Customer Success - Embraces a customer-first mindset to deliver outcomes by linking customer needs and business priorities to aligned solutions, delivery, adoption, satisfaction, and realized value through sustained engagement that builds partnership and trust.
Managing People and Teams - Builds inclusive teams that empower ownership, deepen capabilities, and ensure fair, timely performance accountability, creating an environment where people can deliver their best work and top performance.
Directs Work - Creates conditions for team success with clear goals, priorities, work plans, standards, effective processes, resourcing, and governance to enable fast, empowered, accountable, and quality execution.
Education, Licenses, Certifications: College, university, or equivalent degree in Computer Science, Information Technology, Engineering, or related subject, or relevant equivalent experience required. Global Information Assurance Certification (GIAC) Security Essentials Certification, GIAC Security Leadership Certification, Information Systems Audit and Control Association (ISACA) Certified Information Security Manager, Microsoft Certified Systems Engineer: Security, or Certified Information Systems Security Professional (CISSP) certification preferred. This position may require licensing for compliance with export controls or sanctions regulations.
Experience: Understanding of the capabilities and configuration of industrial cybersecurity controls and solutions across multiple facets; for example: asset management, vulnerability management, anomaly detection, identity and access management, network security, endpoint security, application security, IDS/IPS, deep packet inspection, SIEM, data analytics, security and/or risk management and product development.
Demonstrated ability to lead teams, manage budgets, and build organizational capability.
Excellent communication and stakeholder management skills, with the ability to influence policy and advocate for cybersecurity best practices.
Proven experience in cybersecurity management or equivalent leadership role.
Cummins is an equal opportunity employer. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, sex, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity, or other status protected by law.

Cummins

About Cummins

Industry
Unknown
Company Size
Unknown
Headquarters
Unknown
Year Founded
Unknown
Social Media