Cyber Defense Analyst at Ford Global Career Site
Allen Park, Michigan, United States -
Full Time


Start Date

Immediate

Expiry Date

05 Mar, 26

Salary

0.0

Posted On

05 Dec, 25

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Cyber Security, Incident Handling, SIEM Tools, Data Correlation, Customer Service, Problem Solving, Analytical Thinking, Scripting, Cloud Technologies, AI, Machine Learning, Windows, Linux, Mac, Documentation, Collaboration

Industry

Motor Vehicle Manufacturing

Description
Perform initial triage of various security incidents to determine if a threat applies to Ford including phishing, malicious software, hostile probes, information theft, and misuse of computing facilities Conduct daily analysis on the aforementioned incidents using a range of tools such as SIEM, EDR, IDS/IPS, Cloud, and Sandbox analysis Collaborate with internal and customer teams to investigate and contain incidents Respond to cyber security queries received from Ford personnel Adhere to various playbooks/procedures to provide consistent and repeatable methods to resolve security incidents Effectively document investigation details for both technical and non-technical audiences Recognize attacker Tools, Techniques, and Procedures (TTPs) and Indicator of Compromises (IOCs) that apply to current and future investigations Support Shift Lead rotation at least once per calendar quarter Keeping up-to-date with emerging cybersecurity threats to proactively prevent potential attacks and improve Ford's cyber security posture Leverage AI-driven threat detection and analysis tools to enhance triage accuracy and accelerate identification of emerging attack patterns Established and active employee resource groups Bachelor's degree in a computer related field 2+ years of experience with SIEM tools and/or reviewing system log files, data correlation, and analysis (i.e. firewall, network flow, system logs, IDS) 2+ years of experience in customer service including the resolution of escalations, incident handling, and response In depth knowledge of servers, clients, various computer peripherals, network and/or storage technologies with various operating systems including Windows, Linux, and Mac Experience in a fast paced, high stress, support environment, able to work with a sense of urgency and attention to detail Must work well with others including peers and end-users Strong interest in cyber security with an eagerness and willingness to learn Strong deductive reasoning, critical and analytical thinking, problem solving, and prioritization skills Disciplined approach utilized when completing work and adhering to procedure Strong oral and written communications skills - able and willing to communicate technical items in non-technical terms Demonstrate high level of independent initiative, drive for results and commitment to integrity Ability to concurrently work on multiple assignments/projects and complete on schedule with high quality 2+ years of Cyber Security experience 2+ years Cloud experience in Google Cloud Platform (GCP) or Microsoft Azure Experience applying Artificial Intelligence (AI) and Machine Learning (ML) to improve processes, decision-making, or analysis within your current job responsibilities Familiar with Ford Computing Infrastructure and application development life cycle (SDM) Scripting abilities (Python, PowerShell, Bash/Shell, SQL) GIAC, CEH, CISSP or other security credentials
Responsibilities
Perform initial triage of security incidents and conduct daily analysis using various tools. Collaborate with teams to investigate incidents and respond to cybersecurity queries.
Loading...