Cyber Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 10,001+Since 1903H1B SponsorCompany SiteLinkedIn

Location

Michigan

Posted

3 days ago

Salary

$99.6K - $166.6K / year

Seniority

Lead

Job Description

Cyber Security Engineer

Ford Motor Company

• Engineer technical vulnerability risk solutions that reduce operational, cyber, and resilience risk through architecture, automation, and control design. • Translate vulnerability risk requirements, policies, and standards into implementable technical patterns, guardrails, and reference architectures. • Prioritize and influence solution design decisions based on risk impact, blast radius, and recovery dependencies. • Partner with platform, cloud, security, and SRE teams to embed risk controls directly into infrastructure and pipelines. • Evaluate control effectiveness using technical signals and evidence, not just procedural compliance. • Support initiatives such as vulnerability discovery, exposure analysis, remediation workflow design, secure cloud architectures, isolated recovery environments, identity and access hardening, and infrastructure resilience. • Provide technical guidance on risk tradeoffs, recovery sequencing, and dependency-aware system design. • Work across broad vulnerability management capabilities, including scanners, asset and exposure data sources, prioritization models, remediation tracking platforms, exception workflows, and executive risk reporting.

Job Requirements

  • Bachelor's Degree in Computer Science, Cybersecurity, Information Systems, Software Engineering, or a related technical field
  • 7+ years in engineering, security engineering, platform engineering, SRE, vulnerability management, or technical risk roles
  • Proven ability to design and influence technical solutions across cross-functional teams
  • Hands-on experience with vulnerability management practices, including discovery, prioritization, remediation coordination, exception handling, and risk reporting
  • Demonstrated problem-solving skills, analytical thinking, and the ability to explain complex technical risk concepts to non-technical audiences without losing fidelity
  • Ability to work independently and as part of a team, operating comfortably between engineering teams and risk stakeholders
  • Strong understanding of how risk manifests in distributed systems, cloud platforms, and automation environments
  • Infrastructure as Code experience using Terraform
  • Configuration management and automation experience using Ansible
  • Programming and scripting proficiency in Python
  • Hands-on experience with cloud platforms, specifically Google Cloud Platform (GCP) and/or Azure.
  • Ability to design and implement scalable, automatable security controls and remediation workflows across enterprise technology stacks.
  • Familiarity with observability, logging, and evidence automation for control validation.

Benefits

  • Immediate medical, dental, and prescription drug coverage
  • Flexible family care, parental leave, new parent ramp-up programs, subsidized back-up child care and more
  • Vehicle discount program for employees and family members, and management leases
  • Tuition assistance
  • Established and active employee resource groups
  • Paid time off for individual and team community service
  • A generous schedule of paid holidays, including the week between Christmas and New Year’s Day
  • Paid time off and the option to purchase additional vacation time.

Related Categories

Related Job Pages

More Security Engineer Jobs

CorVel Corporation logo

Info Security Engineer II

CorVel Corporation

Raising the bar for care. Lowering risk for clients.

Full TimeRemoteTeam 1,001-5,000Since 1987H1B Sponsor

• Foster information security practices and procedures across the organization • Research, analyze, and formulate recommendations for technologies, products, and solutions to enable business • Provide technical inputs, system security controls, evaluate and recommend new and emerging security products and technologies • Work with engineering teams to threat model technical designs and implementation of solutions • Act as a subject matter expert and partner with other engineers to select appropriate security controls • Further mature and maintain vulnerability management processes and metrics • Assist with a variety of risk assessments • Assist with vendor risk assessments, and provide customer assurance • Other duties as assigned

United States
$87.2K - $134.6K / year
Secfix logo

Senior Information Security Specialist, German-speaking

Secfix

The fastest way to get ISO 27001 compliant | Compliance & Security Automation

Full TimeRemoteTeam 11-50H1B No Sponsor

• Own and drive the compliance roadmap inside the Secfix platform across different compliance frameworks (ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5, and more as we expand) • Implement ISO 27001 and adjacent frameworks end-to-end for customers • Mentor and upskill the compliance team: sharing expertise, reviewing work, and helping drive consistency in audits and customer deliverables • Conduct internal audits directly for strategic and complex customers, and review the internal audits performed by junior team members to drive quality and consistency • Act as a compliance partner to CSMs and sales reps: fast, reliable support for customer questions, and joining customer calls when deep expertise is needed • Own the quality of compliance content in the platform (including creating policies, evidence templates, Compliance enable playbooks for our CSMs, security awareness trainings and more) • Close framework gaps and incorporate auditor feedback into both team practice and platform improvements • Partner with product and engineering to translate compliance gaps into structured product work • Collaborate closely with CS, Product, and Founders to align compliance, customer, and roadmap priorities • Deepen relationships with our existing certification partners and train auditors on the Secfix platform so they can confidently use it during customer audits

Germany
GovCIO logo

Information Systems Security Officer

GovCIO

GovCIO is a service-disabled-veteran-owned small business (SDVOSB) that offers technology services to improve business performance for government organizations.

Role Description GovCIO is currently hiring for an Information Systems Security Officer (ISSO) to support our client’s contract needs. The ISSO ensures the confidentiality, integrity, and availability of HUD information systems by executing the NIST Risk Management Framework (RMF), supporting system authorization activities, conducting continuous monitoring, and coordinating remediation efforts with system owners and technical teams. Key responsibilities include: - Support and execute all phases of the NIST SP 800-37 RMF lifecycle including categorization, control selection, implementation, assessment, authorization, and continuous monitoring. - Develop, maintain, and update RMF documentation in JCAM including System Security Plans, Security Assessment Plans, Security Assessment Reports, POA&Ms, Configuration Management Plans, Contingency Plans, Incident Response Plans, Risk Assessment documentation, and interconnection documents. - Establish system impact levels following FIPS 199 for confidentiality, integrity, and availability. - Ensure systems comply with FISMA, NIST SP 800-53 Rev 5, OMB A-130, and applicable agency cybersecurity policies. - Prepare and maintain Body of Evidence materials and control traceability documentation in JCAM. - Support Authorization to Operate (ATO), Authority to Connect (ATC), and ongoing authorization activities; maintain associated documentation in JCAM. - Review and analyze vulnerability scan results using Tenable Security Center. - Validate asset inventories and correlate system information. - Validate secure configuration baselines and system hardening standards. - Track remediation activities and ensure POA&M items and milestones are created, updated, and closed on schedule. - Review endpoint security posture and support investigations by correlating endpoint findings with vulnerability, configuration, and CDM data. - Provide security reporting, dashboards, and status updates to system owners and leadership. - Support configuration management processes by reviewing and assessing change requests for security impact. - Ensure security controls are implemented correctly during system changes, upgrades, or new deployments. - Stay informed on emerging cybersecurity policies, standards, and threat landscapes; provide recommendations for improving security posture. - Collaborate with technical and non-technical personnel to review systems, gather evidence, and communicate security requirements. Qualifications - Bachelor’s degree in IT, Cybersecurity, Computer Science, or related field (or equivalent experience) with 5-8+ years or (commensurate experience). Requirements - 2–3 years in an ISSO or cybersecurity compliance role supporting RMF process. - Strong understanding of NIST 800-53 controls and assessment procedures. - Experience collecting, developing and maintaining RMF artifacts. - Experience managing POA&Ms and documenting remediation efforts. - Experience reviewing, interpreting, or validating vulnerability and configuration findings. - Clearance Required: Ability to obtain and maintain a HUD Public Trust clearance. Preferred Qualifications - CISSP, CISM, or similar advanced certification. - Experience supporting federal authorization packages. - Familiarity with CDM reporting and continuous monitoring processes. - Experience supporting secure development or cloud system reviews. Posted Salary Range USD $90,000.00 - USD $110,000.00 /Yr.

United States
$90K - $110K / year
Employment Hero logo

Security GRC Engineer

Employment Hero

Employment Hero is an HR-focused technology company on a mission to create a "better world at work" and change what people expect from employment. Beckoning qua

Role Description Employment Hero is seeking a Security GRC Engineer to join our Information Security department. In this build-centric and technical position, you will be responsible for engineering the integrations, tooling, and automation that power our GRC program. You will collaborate with our Audit Specialist to ensure our compliance is continuous, verifiable, and automated, reducing manual effort across the board. This role offers true ownership of our compliance automation from the start. You will transform control monitoring and evidence gathering into functional code while integrating the core systems that support our certifications. This is an ideal opportunity for an engineer with a compliance background, or a GRC expert who enjoys building, to scale automated security operations within a high-growth environment. As a GRC Analyst, you will be involved in: - Audit & Compliance Operations - Build and extend our in-house GRC automation platform (Python services on cloud infrastructure) that automates evidence collection, control checks, compliance letters and lost-device handling. - Build and run LLM-based tooling that reviews controls for evidence gaps and routes them to the right owners. - Own the day-to-day maintenance of Vanta: keep controls current, collect evidence from stakeholders, and manage control statuses across our certification portfolio. - Support audit preparation across our ISO and SOC 2 programs: prepare documentation, track auditor requests, and keep audit cycles on schedule. - Coordinate evidence collection and follow-ups with internal teams so that nothing is missed. - Maintain and report on compliance posture (control health, overdue evidence, vendor review status) to the security team. - Risk & Vendor Support - Assist with risk assessments: document, track, and follow up on identified risks in our GRC tooling. - Support third-party and vendor risk processes: coordinate vendor questionnaires, track review status, and maintain vendor registers. - Policy & BAU - Help maintain and review information security policies: flag outdated content, track review cycles, and support updates where needed. - Assist with broader GRC BAU tasks as the team’s needs evolve. Qualifications - A relevant degree or certification (e.g. CompTIA Security+, ISO 27001, ISO 27701, ISO 42001 Lead Auditor, Certified in Cybersecurity). - A background in constructing LLM-based solutions and the ability to execute end-to-end automation of manual workflows are highly valued assets. - 2 – 4 years in a GRC, compliance, or audit role (analyst, coordinator, or similar). - Experience working in a tech, SaaS, or scale-up environment. - Familiarity with Vanta or similar compliance automation tools (e.g. Drata, Tugboat Logic) is a strong plus. - A working understanding of frameworks like ISO 27001 or SOC 2. You do not need to be an expert, but you should know the basics. - Exposure to privacy or AI governance frameworks such as ISO 27701, 27018, or 42001. - Strong attention to detail and reliable follow-through. Organised and self-directed, able to manage multiple workstreams at once. - Clear communicator who is comfortable chasing stakeholders, asking questions, and keeping people accountable in a friendly but persistent way. - Eager to learn and open to feedback, with a genuine drive to grow in information security. The technical depth can be built, the mindset needs to be there. - A strong focus on continuous improvement, with a proven ability to challenge the status quo constructively. Benefits - You will work remotely, with the flexibility to own your time and impact. - You will access cutting-edge tools to amplify your work, knowledge and outputs. - You’ll surround yourself with ambitious, outcome-driven colleagues who challenge you to do the best work of your life. - You’ll own ESOP (employee share options) in one of the world’s fastest-growing tech companies. - You’ll also have access to a wide range of benefits that includes: - A very generous parental leave policy. - Subsidised egg freezing (so you can make the choice that’s right for you, on your terms). - A WFH office expense budget. - Outstanding learning & development opportunities.

Asia Pacific