Application Security Analyst at Ford monitoring and validating cloud security implementations. Collaborating across teams to manage vulnerabilities and enhance secure coding practices.
Responsibilities
In this role, you will have the opportunity to support the oversight and security validation of our current technology platform and new Zero Trust environment within the Google Cloud Platform (GCP).
As a key member of our second line-of-defense (2LoD) security team, you will act as a collaborative partner to our development and operations teams. Your focus will be on providing independent technical review and vulnerability management expertise to ensure security is effectively embedded into the fabric of our applications.
You will play a vital role in identifying risks and ensuring our systems remain "secure by design" through proactive monitoring and reporting. If you are a detail-oriented professional who is passionate about cloud security and wants to make a tangible impact on a strategic, multi-year program, this is the role for you.
Requirements
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field (or equivalent experience/internships).
1–3 years of experience in an information security role (experience in application security or cloud security is a plus).
Foundational understanding of Google Cloud Platform (GCP) services and basic cloud security concepts.
Strong knowledge of common application vulnerabilities (e.g., OWASP Top 10).
Experience using vulnerability scanning or management tools (e.g., Cycode, Checkmarx, FOSSA)
Strong organizational skills with the ability to track multiple technical tasks and follow up on remediation.
Secure coding knowledge and techniques to provide developers with actionable guidance
Proactive self-starter with a passion for continuous learning in the evolving cloud security landscape and a demonstrated ability to identify and address security gaps independently
Good communication skills, with the ability to explain security risks to both technical and non-technical stakeholders.
**Even better, you may have...**
Relevant Cyber Security certifications (e.g., CompTIA Security+, Google Cloud Digital Leader, ISC2)
Familiarity with Infrastructure as Code (IaC) security practices and tools (e.g., Terraform, Mondoo, Open Policy Agent).
Knowledge of common security frameworks and compliance standards (e.g., NIST, ISO 27001, SOC 2, GDPR).
Experience with security monitoring, logging, and alerting solutions in a cloud environment (e.g., GCP Security Command Center, Cloud Logging, Cloud Monitoring).
Experience with containerization (Docker) or CI/CD tools.
Benefits
Immediate medical, dental, vision and prescription drug coverage
Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
Vehicle discount program for employees and family members and management leases
Tuition assistance
Established and active employee resource groups
Paid time off for individual and team community service
A generous schedule of paid holidays, including the week between Christmas and New Year’s Day
Paid time off and the option to purchase additional vacation time.
Cyber Security Analyst at Regions analyzing cyber threats and documenting security risks. Collaborating with teams on security posture and incident response efforts.
Global IT Security Analyst protecting Champion Petfoods' technology environment by monitoring security alerts and conducting hands - on investigations.
SOC Senior Analyst role overseeing 24/7 security operations, leading incident response and threat detection teams. Collaborating across teams to enhance organizational security posture and mentor junior analysts.
Cyber Security Analyst ensuring IT security and vulnerability management at Paysafe. Supporting compliance audits and collaborating with internal teams in Sofia.
Principal Cybersecurity Analyst managing SOX compliance activities and IT controls at Unisys. Responsible for ensuring the design, execution, and monitoring of ITGC processes.
Information Security Analyst role responsible for supporting security and privacy programs at Welocalize. Requires experience in information security and a strong desire for continuous learning.
Network Security Analyst focusing on designing and implementing secure network policies at Waste Management. Collaborating with teams to maintain robust security across all network layers.
Junior Cybersecurity Analyst at Minsait focusing on operational technology security and vulnerability management. Collaborating with engineering teams and ensuring security measures align with industrial process availability.
Cybersecurity Analyst supporting DISA's global IT enterprise security from Stuttgart, Germany. Monitoring, analyzing, and responding to cybersecurity threats and incidents with advanced technical skills.
Security Analyst responsible for ensuring compliance and security for sensitive health data in a healthcare AI platform. Collaborating with various teams to embed information security in organizational practices.