Security Risk Engineer
Ford Motor Company · 23 hours ago
We are looking for a Security Engineer with strong technical acumen who can immediately design, prioritize, and implement risk-reducing technical solutions across complex cloud and enterprise environments. This role emphasizes solution engineering over process engineering — using established information security frameworks, policies, and controls as direct inputs to build practical, automatable, and scalable technical safeguards.
The ideal candidate thinks like an engineer first and a security risk professional second: someone who already understands how systems fail, how controls are enforced through code and architecture, and how risk and compliance intent translate into resilient technical designs — without requiring extended ramp-up time on RAC fundamentals.
Responsibilities
Key Responsibilities
-
Engineer technical risk solutions that reduce operational, cyber, and resilience risk through architecture, automation, and control design — starting on day one with minimal onboarding.
-
Translate risk requirements, policies, and standards into implementable technical patterns, guardrails, and reference architectures.
-
Prioritize and influence solution design decisions based on risk impact, blast radius, and recovery dependencies.
-
Partner with platform, cloud, security, and SRE teams to embed risk controls directly into infrastructure and pipelines.
-
Evaluate control effectiveness using technical signals and evidence, not just procedural compliance checklists.
-
Independently support the requirements of internal control, internal audit, and external audit engagements, including evidence gathering, control testing, and remediation tracking.
-
Deploy and manage security software, assess and apply required security patches on Security Appliances (servers).
-
Support the Security Appliances 24x7 on-call rotation to enable continuous data collection.
-
Drive initiatives such as secure cloud architecture, isolated recovery environments, identity and access hardening, and infrastructure resilience.
-
Provide informed, immediate guidance on risk tradeoffs and compliance requirements to engineering and business stakeholders.
-
Contribute to lightweight process definition where needed, always in service of enabling better technical and audit outcomes.
Required Technical Skills
-
Risk, Audit & Compliance Frameworks: Direct working experience with frameworks such as NIST, ISO 27001, SOX, PCI-DSS, or similar, and demonstrated ability to map controls to technical implementations.
-
Data Analytics: Proficiency with GCP BigQuery, Power BI (or similar) for visualizing risk posture and audit evidence.
-
Configuration Management / Automation: Ansible, REST API, Terraform.
-
Programming / Scripting: Python, Linux Bash, Windows PowerShell, SQL.
-
Cloud Platforms: Google Cloud Platform (GCP), Azure, AWS.
-
Supporting Knowledge (nice to have):
-
Cloud IAM, networking, and control planes
-
CI/CD pipelines and policy-as-code
-
Familiarity with Agentic AI frameworks
-
Observability, logging, and evidence automation
-
Backup, recovery, and resilience architectures
-
Qualifications
Required Qualifications
-
7+ years of experience in security engineering, platform engineering, SRE, or technical risk roles, with a significant portion spent directly supporting risk, audit, or compliance functions.
-
Demonstrated, ready-to-apply experience with audit lifecycles, control testing, and compliance evidence collection — able to engage with auditors and risk stakeholders immediately without extensive training.
-
Proven ability to design and influence technical solutions across teams.
-
Strong understanding of how risk manifests in distributed systems, cloud platforms, and automation.
-
Comfortable operating at the intersection of engineering teams and risk/compliance stakeholders.
-
Ability to explain complex technical risk concepts to non-technical audiences without losing fidelity.
-
Experience in production support and troubleshooting.