Overview
Cyber Monitoring Use Case Manager Jobs in Casablanca-Settat, Morocco at Stellantis
Title: Cyber Monitoring Use Case Manager
Company: Stellantis
Location: Casablanca-Settat, Morocco
Job Summary
The Cyber Monitoring Use Case Manager is responsible for defining, governing, and continuously improving cybersecurity detection use cases within the Cyber Defense Operations Center (CDOC). The role ensures that monitoring capabilities are aligned with the organization’s threat landscape, risk posture, and operational needs, delivering high‑value, actionable detections with measurable effectiveness.
In addition to detection use case management, the Cyber Monitoring Use Case Manager is responsible for defining and governing log collection requirements across on-premise infrastructure, cloud platforms, and SaaS services, ensuring that telemetry coverage is sufficient, reliable, and aligned with detection, threat hunting, and incident response needs. This includes working closely with Platform Engineering and MSSP partners to ensure logs are onboarded, normalized, and maintained according to monitoring standards.
Acting as a key interface between Cyber Monitoring Analysts, CSIRT, Threat Intelligence, Platform Engineering, and external MSSP partners, the Use Case Manager drives the end‑to‑end lifecycle of detection use cases—from ideation and design to validation, tuning, and operational handover.
Key Responsibilities
Use Case / Log collection Strategy & Governance
- Define and maintain the detection use case roadmap, aligned with business risks and cyber threat intelligence.
- Establish and enforce use case management frameworks, standards, and approval processes.
- Ensure alignment of use cases with industry frameworks such as MITRE ATT&CK and DeTTECT.
- Prioritize use cases based on risk, coverage gaps, and operational value.
Use Case Development & Lifecycle Management
- Oversee the creation, evolution, and retirement of cyber monitoring use cases.
- Coordinate use case development across SIEM, SOAR, and Threat Intelligence platforms.
- Ensure detections are tested, validated, and continuously tuned to reduce false positives and maintain effectiveness.
- Drive use case validation through threat hunting, red team exercises, and security validation tools.
Operational Coordination
- Supervise and guide Cyber Monitoring Analysts and Use Case Engineers on detection-related activities.
- Ensure smooth interaction between Cyber Monitoring, CSIRT, and MSSP teams to support incident detection and escalation flows.
- Act as a key point of contact for service delivery and operational performance related to monitoring use cases.
Performance Measurement & Reporting
- Define and track KPIs for detection effectiveness (coverage, false positives, detection rate, response time).
- Provide dashboards and reporting on use case performance and maturity to stakeholders and leadership.
- Ensure documentation and knowledge base updates are maintained throughout the use case lifecycle.
Continuous Improvement & Innovation
- Monitor emerging threats and integrate new attack techniques and indicators into detection logic.
- Identify opportunities for automation, playbook integration, and operational efficiency.
- Support the ongoing advancement and enhancement of the Cyber Monitoring capability.
Required Skills & Qualifications
Technical Skills
- Strong understanding of SOC/CDOC operations and cyber threat detection.
- Experience with SIEM platforms (Microsoft Sentinel) and detection engineering concepts (SIGMA detection rules, Security Copilot) and globally Microsoft products (Azure, MDE, MDI, XDR, …)
- Log collections methodologies for on-Premises, Cloud and SaaS sources
- Knowledge of MITRE ATT&CK, threat intelligence, and detection validation methodologies.
- Agile methodology to implement new use case factory in sprints, using Git to deploy the log source collection and the use cases (Terraform, SIGMA, KQL)
- Familiarity with SOAR, automation, and alert triage workflows.
Professional Skills
- Proven ability to coordinate cross‑functional teams in a complex security environment.
- Strong analytical and problem‑solving mindset with a focus on operational value.
- Excellent communication skills to engage both technical and non‑technical stakeholders.
- Capability to operate in a service‑oriented, performance‑driven environment.
Experience & Education
- Experience in Cyber Monitoring, SOC, Detection Engineering, or Incident Response roles.
- A background in use-case management, service delivery, or security product management is a strong advantage.
- Degree in Cybersecurity, Computer Science, or related field, or equivalent professional experience.
Key Interfaces
- Cyber Monitoring Analysts (L1/L2)
- CSIRT / Incident Response teams
- Threat Intelligence teams
- Platform Engineering teams
- MSSP partners and external vendors
At Stellantis, we assess candidates based on qualifications, merit and business needs. We welcome applications from people of all gender identities, age, ethnicity, nationality, religion, sexual orientation and disability. Diverse teams will allow us to better meet the evolving needs of our customers and care for our future.