Ford Motor Company

DevSecOps Security Engineer

Ford Motor Company Chennai, Tamil Nadu, India

Motor Vehicle Manufacturing · 10,001+ employees

5 h ago Closes in 2d
security Mid (2-5 yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The DevSecOps Security Engineer ensures security best practices are integrated throughout the software development lifecycle. They are responsible for implementing security testing, triaging vulnerabilities, and providing guidance on secure coding practices to development teams.

What they look for

DevSecOps Application Security Cloud Security Vulnerability Management CI/CD SAST DAST SCA Container Scanning IaC Golang Python Shell Script OWASP Top 10 Agile AI Tools

Requirements

Candidates must hold a bachelor's degree in a relevant field and possess at least 3 years of professional experience in security disciplines. Proficiency in scripting languages, CI/CD pipeline integration, and security testing tools is required.

Full description

The DevSecOps Security engineer ensures that every step of the software development lifecycle (SDLC) follows security best practices. They are also responsible for guiding the teams to adhere to secure coding principles and aid in testing the application against security risks/parameters before release.

Responsibilities

  • Drive the implementation of security testing (Secrets Scanning/ SAST / DAST / SCA/IAC/Container Scanning/ AI Security)
  • Assist teams in triaging and addressing application security vulnerabilities.
  • Support integration of security tools into CI / CD pipelines. (Tekton, Cloud Build, Github actions etc.)
  • Define and publish security requirements from a DevSecOps perspective.
  • Prioritizing vulnerabilities discovered along with recommending remediation timeline.
  • Collaborate with cross-functional teams to ensure security best practices are followed throughout the software development lifecycle.
  • Monitoring and analyzing vulnerability trends to identify focused actions like training, bulk fix, etc.
  • Stay up to date with the latest security trends and technologies to continuously improve security processes
  • Provide security training and guidance to development teams on secure coding practices and security awareness

Qualifications

Qualifications required:

  • Bachelor (undergraduate) degree in a relevant field (Computer Science, Cybersecurity, Software Engineering, or others) OR an equivalent combination of education, training, and experience.
  • Minimum of 3 years of professional experience with any combination of at least 2 technical disciplines, including the following: application security, cloud security, vulnerability management, secure development methodologies, identity management.
  • Preferred - Cybersecurity / DevSecOps certifications
  • Willingness to work in flexible timings to support global customers / collaboration.

Skillset required:

  • Experience in security testing (SCA, SAST, DAST, Container Scanning, IaC, etc), and their integration into CI/CD.
  • Provide technical expertise in fixing the vulnerabilities. (e.g. Knowledge of OWASP Top 10).
  • Excellent communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner.
  • Experience in integrating, monitoring and improving DevSecOps tools and processes, automate routine tasks and improve system reliability.
  • Experience in writing scripts in languages such as Golang, Shell Script, Python, YAML etc.
  • Experience in DevOps related tools, pipelines, platforms, registries and version control systems.
  • Power-user of AI tools to boost productivity and quality of DevSecOps processes.
  • Basic understanding of network and web related protocols (such as TCP/IP, UDP, HTTP, HTTPS, protocols)
  • Good knowledge of Agile processes (planning/standups/retros etc.) and interact with cross functional teams.

Similar roles