Cybersecurity Defense Analyst - Senior
We are looking for a talented Cybersecurity Defense Analyst- Senior to join our team specializing in Systems/Information Technology for our Corporate organization in Columbus, IN.
In this role, you will make an impact in the following ways:
- Protect Cummins' technology environment by applying cybersecurity policies, data privacy principles, and security best practices to reduce organizational risk.
- Lead cybersecurity risk assessments and identify potential vulnerabilities, ensuring effective mitigation strategies are developed and implemented.
- Serve as a trusted advisor to business and technology stakeholders by providing expert guidance on secure technology solutions and risk-informed decision-making.
- Apply industry-leading frameworks and standards such as NIST, ISO, ITIL, and COBIT to strengthen security controls and support regulatory compliance.
- Partner with cross-functional teams to evaluate new and changing technology solutions, ensuring cybersecurity requirements are integrated from the start.
- Coach, mentor, and develop less experienced team members, helping build cybersecurity capabilities and fostering a culture of continuous learning.
- Build and maintain strong business relationships that enable collaboration, strengthen stakeholder trust, and deliver measurable business value.
- Drive proactive cybersecurity improvements by balancing business objectives with security requirements, helping the organization remain resilient against evolving threats.
To be successful in this role you will need the following:
- Action oriented - Taking on new opportunities and tough challenges with a sense of urgency, high energy, and enthusiasm.
- Balances stakeholders - Anticipating and balancing the needs of multiple stakeholders.
- Business insight - Applying knowledge of business and the marketplace to advance the organization’s goals.
- Ensures accountability - Holding self and others accountable to meet commitments.
- Manages complexity - Making sense of complex, high quantity, and sometimes contradictory information to effectively solve problems.
- Organizational savvy - Maneuvering comfortably through complex policy, process, and people-related organizational dynamics.
- Persuades - Using compelling arguments to gain the support and commitment of others.
- Resourcefulness - Securing and deploying resources effectively and efficiently.
- Tech savvy - Anticipating and adopting innovations in business-building digital and technology applications.
- Training Delivery - Instructs learners in a manner that engages and adjusts to individual and group needs resulting in knowledge, skills and abilities that can be applied on the job.
- Cybersecurity Risk Management - Identifies and assesses the potential impact of Cybersecurity risks against established Cybersecurity industry frameworks, regulations and organizational policies to develop and implement risk mitigation strategies in alignment with business objectives.
- Regulatory Risk Compliance Management - Evaluates the design and effectiveness of controls against established industry frameworks and regulations to assess adherence with legal/regulatory requirements.
- Values differences - Recognizing the value that different perspectives and cultures bring to an organization.
Education, Licenses, Certifications:
- College, university, or equivalent degree in Cybersecurity, Computer Science, or Information Technology, or related subject, or relevant equivalent experience required.
- This position may require licensing for compliance with export controls or sanctions regulations.
Experience:
- Intermediate level of relevant work experience required.
- 3-5 years of experience
Job Description / Responsibilities
• Support and execute adversary emulation, purple team, and security validation activities across enterprise environments.
• Operate and maintain Breach and Attack Simulation (BAS) and adversary emulation platforms to validate defensive controls and identify detection gaps.
• Conduct security testing of cloud, hybrid, and on-premises environments to identify exploitable weaknesses and security control deficiencies.
• Partner with Threat Intelligence and Threat Hunting teams to emulate relevant attacker behaviors, techniques, and procedures.
• Assist in developing repeatable attack scenarios aligned to MITRE ATT&CK techniques and organizational threat priorities.
• Validate detection and response capabilities by coordinating with defensive security teams during purple team exercises.
• Help automate offensive testing workflows, validation processes, and operational reporting through scripting and tooling enhancements.
• Document findings, attack paths, detection gaps, and remediation recommendations in a clear and actionable manner.
• Contribute to the continuous improvement of proactive security validation capabilities, processes, and operational maturity.
• Support offensive cyber operations initiatives including targeted assessments, adversary simulation activities, and security research efforts.
• Support the engineering and development of remedial workflows for findings generated by adversarial and offensive activities
Requirements / Qualifications
• Experience in cybersecurity operations, cloud security, security engineering, offensive security, or related technical security disciplines.
• OCSP or equivalent certification holder or the willingness to obtain such a certification.
• Familiarity with cloud platforms such as AWS, Azure, OCI and associated security concepts.
• Understanding of common attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK.
• Exposure to scripting or automation using languages such as Python, PowerShell, or Bash.
• Familiarity with security validation, BAS, detection engineering, purple teaming, penetration testing, or adversary emulation concepts is preferred.
• Strong analytical, troubleshooting, and collaboration skills with the ability to work across offensive and defensive security functions.