Application Security Cloud Engineer at Ford Global Career Site
Dearborn, Michigan, United States -
Full Time


Start Date

Immediate

Expiry Date

11 Feb, 26

Salary

0.0

Posted On

13 Nov, 25

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Application Security, Cloud Security, Google Cloud Platform, Vulnerability Management, Security Testing, Scripting, Containerization, Serverless Technologies, Communication, Collaboration, Problem Solving, Infrastructure as Code, Security Frameworks, Compliance Standards, Security Monitoring, Logging

Industry

Motor Vehicle Manufacturing

Description
Cloud Security Strategy & Oversight: Partner with Architecture, Developer Experience (DevX), and Site Reliability Engineering (SRE) teams to shape and implement our GCP Zero-Trust security architecture. Provide expert oversight and validation of security controls, acting as a critical second-line partner to ensure our cloud environment is fundamentally secure. Drive the operationalization of Google's Security Command Center Enterprise (SCCE), turning its powerful features into a proactive threat detection and compliance engine. Collaborate on best practices for the enforcement of security quality gates for Infrastructure as Code (IaC) and Policy as Code (PaC) implementations. Develop and automate vulnerability management processes, using a risk-based approach to prioritize and drive remediation. Collaborate effectively with cross-functional teams, including development, operations, compliance, and incident response. Established and active employee resource groups Bachelor's degree in computer science, information security, or a related technical field, or equivalent practical experience. 5+ years of progressive experience in application security, cloud security, or a similar security engineering role. Demonstrable expertise in securing applications and infrastructure within Google Cloud Platform (GCP). In-depth understanding of software development lifecycle (SDLC) principles and practices. Proven experience with vulnerability management, including scanning, analysis, prioritization, and remediation tracking. Strong knowledge of various security testing methodologies and tools Proficiency in at least one scripting language (e.g., Python, Go, Bash) for automation and tool development. Experience with containerization (Docker, Kubernetes) and serverless technologies. Excellent communication, collaboration, and problem-solving skills. Master's degree in a relevant technical field. Relevant industry certifications such as GCP Professional Cloud Security Engineer, CISSP, CCSP, CSSLP. Experience with Infrastructure as Code (IaC) security practices and tools (e.g., Terraform, Mondoo, Open Policy Agent). Knowledge of common security frameworks and compliance standards (e.g., NIST, ISO 27001, SOC 2, GDPR). Experience with security monitoring, logging, and alerting solutions in a cloud environment (e.g., GCP Security Command Center, Cloud Logging, Cloud Monitoring).
Responsibilities
Partner with various teams to implement GCP Zero-Trust security architecture and validate security controls. Drive the operationalization of security tools and collaborate on best practices for security implementations.
Loading...