Enterprise Cybersecurity Analyst joining Ford's Cybersecurity team focused on maintaining security posture and managing risks. Critical role ensuring compliance and enhancing internal customer experience.
Responsibilities
Serve as a subject matter expert, providing policy and risk-based consultation to enterprise customers, ensuring consistent adherence to regulatory requirements and best practices across all operations.
Manage and drive critical cybersecurity projects from inception to completion, focusing on initiatives that improve internal customer experience by delivering user-centric security solutions and streamlining security processes.
Act as a dedicated resource for Outside Service Provider (OSP) compliance, guiding business owners on company policy requirements and assisting in assessing the security posture of third-party vendors to minimize potential disruptions.
Conduct high-risk Application and Infrastructure Governance, Risk, and Compliance (GRC) component assessments, identifying potential vulnerabilities, ensuring control implementation, and recommending mitigation strategies across various technologies.
Support enterprise-level cybersecurity awareness initiatives, strengthening employee security awareness and empowering them as the first line of defense.
Manage the full lifecycle of security vulnerabilities, including assisting teams with triage and analysis, evaluating associated risks, and implementing effective remediation strategies to defend against threats to enterprise assets.
Collaborate with other cyber services to provide best-in-class consultation and support to enterprise customers.
Reporting cyber security metrics by tracking key performance indicators (KPIs).
Establishing robust engagement and communication channels to provide timely and quality response.
Requirements
Bachelor's degree in a relevant field (e.g., Computer Science, Cybersecurity, Software Engineering, Information Security) or an equivalent combination of education, training, and experience.
Minimum of 2-3 years of professional experience in IT (e.g., application development, infrastructure management), coupled with a strong desire and demonstrated aptitude for a career in cybersecurity.
Minimum of 2 years of professional experience in one or more of the following technical disciplines:
Third-party Risk Assessment
Vulnerabilities Assessments
Cybersecurity Consultation
Cybersecurity Auditing
Software Development and Coding (with a security focus)
Application Security
DevSecOps Methodologies
Identity and Access Management (IAM)
Cloud Security
Security Operations and Incident Response
Knowledge of cybersecurity frameworks and industry standards (e.g., NIST CSF, ISO 27001/2, OWASP).
Familiarity with Threat Modeling and IT Risk Assessment methodologies.
Knowledge of best practices for IAM flows, grant types, OAuth2, OIDC, and SAML standards.
Experience with API security best practices to protect sensitive data and services.
Knowledge of cryptographic algorithms and functions for building secure solutions.
Familiarity with common security flaws and effective remediation strategies (e.g., OWASP Top 10).
Understanding of DevSecOps principles, agile methodologies, and security policies.
IT Security Analyst for Bundesdruckerei GmbH monitoring security events in diverse infrastructures. Collaborating within the Blue Team and responding to security incidents.
Cyber Security Analyst within the Cyber Security Governance, Risk and Compliance team. Supporting effective management and oversight of cyber risk at Heathrow Airport.
Cyber Security Analyst focusing on security telemetry and metrics for Heathrow operations. Enhancing organizational cyber resilience through actionable intelligence and reporting.
Security Analyst monitoring systems and providing expertise for cybersecurity solutions at GoSecure. Engage in proactive analysis, incident response, and system oversight.
Security Analyst focusing on brand protection against online fraud and phishing attacks. Investigating threats, pursuing takedowns, and supporting sales evaluations in a hybrid work environment.
Jr. Vulnerability Management Analyst at OneDigital managing security vulnerabilities across infrastructure. Collaborating with IT teams to ensure timely remediation and effective reporting.
Offensive Security Analyst specializing in Red Team operations for AI/ML systems at Vanguard. Collaboration with data scientists and security teams to protect AI infrastructure.
IT Cybersecurity Analyst supporting vulnerability management and incident response for WEC Energy Group's cybersecurity infrastructure. Collaborating with teams to enhance security posture and mitigate risks.
IAM Security Engineer managing identity and access governance at WEC Energy Group. Collaborating on IAM solutions and troubleshooting access management issues.
Senior CyberSecurity Analyst focusing on identifying and responding to email borne threats at Proofpoint. Collaborating with a global team to develop detection signatures against phishing, malware, and spam attacks.