About the role

  • DevSecOps engineer ensuring security practices in software development lifecycle at Ford. Collaborating with teams and implementing secure coding practices.

Responsibilities

  • Perform security-focused code reviews.
  • Assist teams in reproducing, triaging, and addressing application security vulnerabilities.
  • Knowledge of Risk mitigation techniques and fixing the code bugs.
  • Monitoring the processes during the entire lifecycle for its adherence and updating or creating new processes for improvement.
  • Support and consult with product and development teams in the area of application security. Identifying and deploying cybersecurity measures by continuously performing vulnerability assessment and risk management.
  • Providing security training and outreach to internal development teams.
  • Mentoring, guiding team members and customers.
  • Monitoring, measuring customer experience and KPIs.
  • Use security tools for identifying and mitigating vulnerabilities.
  • Able to work well with software development teams.
  • Experience identifying security issues through code review.
  • Excellent and professional communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner.
  • Familiarity with some common security libraries and tools (e.g. static analysis tools).
  • Familiarity and ability to explain common security flaws and ways to address them (e.g. OWASP Top 10).
  • Experience in integrating, monitoring and improving DevSecOps tools and processes, automate routine tasks and improve system reliability.
  • Development or scripting experience and skills. (preferable Python knowledge).
  • Designing and implementing Zero Trust Security model, automated enforcement, and monitoring of security controls, vulnerability management, code-based compliance and gate reviews, platform-based security controls and guardrails.

Requirements

  • Bachelor (undergraduate) degree in a relevant field (Computer Science, Software Engineer, Security, or others) OR an equivalent combination of education, training, and experience.
  • Minimum of 5 years of professional experience with any combination of at least 2 technical disciplines, including the following: DevSecOps, cloud security, network security, application security, mobile security, secure development methodologies, software development and coding, identity management, authentication and authorization, network architecture, system administration, and systems engineering.
  • Desirable Certified DevSecOps Professional (CDP), Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security (CKS) and HashiCorp Certified: Terraform Associate.

Benefits

  • Health insurance
  • Professional development opportunities

Job title

Cyber Security

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job