Application Security Analyst at Ford monitoring and validating cloud security implementations. Collaborating across teams to manage vulnerabilities and enhance secure coding practices.
Responsibilities
In this role, you will have the opportunity to support the oversight and security validation of our current technology platform and new Zero Trust environment within the Google Cloud Platform (GCP).
As a key member of our second line-of-defense (2LoD) security team, you will act as a collaborative partner to our development and operations teams. Your focus will be on providing independent technical review and vulnerability management expertise to ensure security is effectively embedded into the fabric of our applications.
You will play a vital role in identifying risks and ensuring our systems remain "secure by design" through proactive monitoring and reporting. If you are a detail-oriented professional who is passionate about cloud security and wants to make a tangible impact on a strategic, multi-year program, this is the role for you.
Requirements
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field (or equivalent experience/internships).
1–3 years of experience in an information security role (experience in application security or cloud security is a plus).
Foundational understanding of Google Cloud Platform (GCP) services and basic cloud security concepts.
Strong knowledge of common application vulnerabilities (e.g., OWASP Top 10).
Experience using vulnerability scanning or management tools (e.g., Cycode, Checkmarx, FOSSA)
Strong organizational skills with the ability to track multiple technical tasks and follow up on remediation.
Secure coding knowledge and techniques to provide developers with actionable guidance
Proactive self-starter with a passion for continuous learning in the evolving cloud security landscape and a demonstrated ability to identify and address security gaps independently
Good communication skills, with the ability to explain security risks to both technical and non-technical stakeholders.
**Even better, you may have...**
Relevant Cyber Security certifications (e.g., CompTIA Security+, Google Cloud Digital Leader, ISC2)
Familiarity with Infrastructure as Code (IaC) security practices and tools (e.g., Terraform, Mondoo, Open Policy Agent).
Knowledge of common security frameworks and compliance standards (e.g., NIST, ISO 27001, SOC 2, GDPR).
Experience with security monitoring, logging, and alerting solutions in a cloud environment (e.g., GCP Security Command Center, Cloud Logging, Cloud Monitoring).
Experience with containerization (Docker) or CI/CD tools.
Benefits
Immediate medical, dental, vision and prescription drug coverage
Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
Vehicle discount program for employees and family members and management leases
Tuition assistance
Established and active employee resource groups
Paid time off for individual and team community service
A generous schedule of paid holidays, including the week between Christmas and New Year’s Day
Paid time off and the option to purchase additional vacation time.
Join is seeking a Senior Cybersecurity Analyst for a hybrid quality - focused squad. Responsible for incident response and digital forensics in cybersecurity.
Information Security Analyst developing documentation, managing security incidents, and maintaining information security practices. Engaging with internal teams and external suppliers while working in a hybrid environment.
Cybersecurity Analyst monitoring and responding to security threats in hybrid work environment. Collaborating across teams to enhance security and ensure compliance with standards.
Security Analyst at Aviso joining a cybersecurity team to mitigate threats across IT and Cloud. Responsible for investigations, implementing controls, and enhancing security posture.
IT Security Analyst responsible for monitoring and responding to security incidents. Collaborating with teams and ensuring effective incident response to maintain business continuity.
SOC Analyst Principal impacting national security in cyber at GDIT. Bring your cyber expertise and drive for innovation to a veteran - friendly workplace.
Information Security Analyst engaging in cyber security and governance risk compliance for Grupo BAUMINAS. Collaborating on security operations, incident response, and risk management processes.
Pleno Security Analyst protecting information assets by monitoring, incident management, and vulnerability oversight. Collaborating on compliance with internal policies and regulatory requirements.
Network and Security Analyst in Logicalis, aiding companies in digital transformation. Responsible for network monitoring and incident resolution, ensuring connectivity and security.