Security Operations Engineer
Fisher Dynamics St. Clair Shores, Michigan, United States
Motor Vehicle Manufacturing · 1,001-5,000 employees
About the role
The Security Operations Engineer is responsible for executing security controls, compliance frameworks, and infrastructure hardening for the company's custom ERP platform. They will manage firewall configurations, cloud security, identity access management, and support incident response and compliance audits.
What they look for
Requirements
Candidates must have a Bachelor's degree in a relevant field or equivalent experience, with 5-8 years of hands-on cybersecurity implementation. Proficiency in ISO 27001, TISAX, network infrastructure hardening, and cloud security platforms is required.
Full description
Fisher Dynamics is the automotive industry’s premier supplier of safety – critical seat structures and mechanisms. Steeped in a tradition of excellence, and rooted in automotive innovation, the Fisher story is filled with automotive manufacturing milestones. We bring design, engineering, and manufacturing vehicle seating systems to a new level with innovative thinking. We’re about cutting edge ideas. We have created an environment that encourages an uninterrupted flow of revolutionary concepts and unique ideas.
Fisher Dynamics is currently seeking a Security Operations Engineer to join our corporate IT department in Saint Clair Shores, MI. This posistion is responsible for executing security controls, compliance frameworks, and infrastructure hardening for Fisher Dynamics' custom ERP platform. They will translate security architecture into operational reality: configuring firewalls, implementing ISO 27001/TISAX controls, hardening switches, deploying GRC tooling, and ensuring compliance readiness. They will be the hands-on implementer who makes security work in production.
Essential Duties & Responsibilities
GRC Controls Implementation
- Implement ISO 27001 and TISAX controls across the ERP platform
- Deploy and configure GRC tooling for control tracking, evidence collection, audit documentation
- Map security requirements to technical controls (access control, encryption, logging, monitoring)
- Maintain control inventory and track implementation status
- Support compliance audits with evidence gathering and remediation tracking
Firewall & Network Infrastructure Hardening
- Configure and deploy firewalls (Palo Alto, Check Point, Fortinet, etc.) for ERP protection
- Implement firewall rules aligned with zero-trust architecture and network segmentation
- Harden network infrastructure: switches, routers, VPN endpoints
- Implement network access controls, rate limiting, DDoS protection
- Troubleshoot and optimize firewall performance without compromising security
Cloud Security Operations
- Implement cloud security controls on AWS/GCP/Azure (security groups, NACLs, WAF)
- Configure cloud IAM, MFA, logging, monitoring aligned with compliance requirements
- Implement secrets management, key rotation, encryption controls in cloud environment
- Perform cloud security configuration reviews and remediation
Access Control & IAM Implementation
- Deploy identity and access management systems (RBAC, ABAC)
- Configure multi-factor authentication (MFA), conditional access policies
- Implement privileged access management (PAM) for administrator accounts
- Maintain user access reviews and certification workflows
- Configure segregation of duties controls in ERP system
Logging, Monitoring & Incident Response
- Configure centralized logging and SIEM systems for security event monitoring
- Implement alerts for suspicious activity, policy violations, and anomalies
- Maintain audit trails for compliance and forensics
- Support incident response: investigation, containment, remediation
- Produce security monitoring dashboards and reports
Vulnerability Management & Patching
- Execute vulnerability scanning and assessment programs
- Coordinate patch management and security updates
- Remediate identified vulnerabilities with risk-based prioritization
- Track remediation status and compliance with SLAs
Documentation & Compliance Readiness
- Document security configurations, controls, and procedures
- Maintain compliance evidence (control matrices, test results, audit logs)
- Prepare for ISO 27001/TISAX audits with documentation and evidence
- Write control testing procedures and validation scripts
- Update risk registers and compliance status reports
MSP/Managed Services Mindset
- Treat security implementation like managed service: reliable, repeatable, documented
- Build runbooks and standard operating procedures for control execution
- Monitor control effectiveness and optimize over time
- Proactive identification of risks and recommendations for improvement
Qualifications
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education
Bachelor's degree in Computer Science, Cybersecurity, Information Security, Engineering, or related field
or equivalent professional experience (5+ years)
Experience
5-8 years hands-on cybersecurity implementation (not just planning/architecture)
ISO 27001 implementation experience — Led control implementation, not just audits
TISAX/manufacturing compliance strongly preferred
Firewall & network infrastructure hardening — Palo Alto, FortiGate, Check Point, Juniper
Cloud security implementation — AWS, GCP, or Azure IAM, logging, monitoring
MSP or managed services background — Comfortable with operational discipline, SLAs, documentation
GRC tooling experience — ServiceNow, Archer, Compliance.ai, or similar (preferred)
Skills
Infrastructure & Network:
Expert firewall configuration and hardening
Network segmentation, VLAN design, routing protocols
VPN, proxy, DMZ architecture
Switch/router configuration and hardening
Cloud infrastructure (AWS VPC, GCP VPC, Azure networking)
Access Control & IAM:
Identity management systems (Okta, Azure AD, Entra ID)
Multi-factor authentication (MFA) deployment
Privileged access management (PAM)
RBAC/ABAC design and implementation
Compliance & Audit:
ISO 27001 controls mapping and implementation
TISAX/manufacturing compliance requirements
Audit evidence collection and remediation tracking
Control testing and validation
Security Operations:
SIEM configuration and log management
Vulnerability scanning and remediation
Incident response procedures
Security monitoring and alerting
Tools & Platforms:
Firewall platforms (Palo Alto Networks, Fortinet, Check Point, Juniper)
Cloud security platforms (AWS Security Hub, GCP Security Command Center, Azure Security Center)
GRC/compliance tools (ServiceNow, Archer, Tenable, Qualys)
SIEM/logging (Splunk, ELK, Datadog)
Configuration management and IaC (Terraform, Ansible)
Certifications:
Security+, CISSP, or CCSK (preferred)
CompTIA Network+ or CCNA (for network depth)
Firewall certifications (Palo Alto, Fortinet) (preferred)
Work Environment
Working environment and physical requirements of this position are those typical of an office setting and manufacturing environment.
On-Call Support for security incidents (rotating schedule)
Physical Demands
Ability to lift 40lbs