JOB DESCRIPTION
The Cloud Security team is responsible for identifying, evaluating, and recommending cloud security tools and functions to enhance security around Ford's public cloud. The team is also responsible for developing and managing the following Security Services in Ford's public cloud environments :
- GCP Security Command Center
- GCP / Azure Security Compliance
- GCP VPC Service Control
- GCP Cloud Armor / Azure WAF
RESPONSIBILITIES
Partner with other Cloud Security team members to identify and develop automation for security related workflows and audits (VPC SC, DLP, Exceptions, Org Policy, etc..).Lead evaluation and develop an understanding of tools needed to address security gaps.Lead / Collaborate with EPEO Services teams on security gap remediation.QUALIFICATIONS
Desired Skills
Experience working with CI / CD deployment pipelines & automated build and configuration tools such as Jenkins, Chef, OpenShift, Tekton, Cloud BuildExperienced in developing and releasing infrastructure-as-code (IaC) using configuration management tools such as Terraform.Experience with automation using scripting languages such as Python, Go, Node.js, Angular, JavaScript, React, TypeScript, etc.Strong understanding of Git and GitHub, GitHub Actions.Strong knowledge of security best practices and guidelines (at the enterprise-level) related to GCP and Azure Cloud deployments as well as common web application frameworksUnderstand the functionality and secure usage of various GCP services : VPCs, IAM, security groups, compute engine, cloud storage, Security Command Center, VPC Service Control, Cloud DLP and Cloud ArmorUnderstand the functionality and secure usage of various Azure services : Virtual Machines, Virtual Networks, Azure Active Directory, App Services, Azure SQL Databases, Storage Accounts, Kubernetes, Containers, Key vaults.Required Skills
Customer focused and strong team orientationSelf-starter and fast-learnerStrong communication and interpersonal skillsStrong problem solving and Analytical / Reasoning skillsStrong drive for results and ability to work independentlyDemonstrated commitment to quality and project timingFamiliarity with the agile project planning process and use of Rally.Document processes & procedures and developing other documentation.