Sr SME Cyber Security Consultant (W2 Remote)
Sr SME Cyber Security Consultant (W2 Remote)
Megan Soft Inc
United States
See who Megan Soft Inc has hired for this role
Position: Sr SME Cyber Security Consultant (W2 Position) - 314121
Location: Dearborn MI (Remote)
Duration: 12+ Months
MOI: Phone & WebEx
Direct Client: FORD MOTORS
Note: 1. U.S. Citizens and those authorized to work in the U.S. are encouraged to apply. We are NOT able to sponsor H1-B at this time.
0
Education Required
Additional Safety Training/Licensing/Personal Protection Requirements:
Additional Information
Interested in Hybrid or Remote Candidates
Location: Dearborn MI (Remote)
Duration: 12+ Months
MOI: Phone & WebEx
Direct Client: FORD MOTORS
Note: 1. U.S. Citizens and those authorized to work in the U.S. are encouraged to apply. We are NOT able to sponsor H1-B at this time.
- H1B Consultant who are willing to WORK ON OUR W2 (H1B TRANSFER) are welcome
- Act as a senior subject matter expert for secure coding, evaluating, and implementing processes to mature application security.
- Provide consulting services to all Ford Pro product teams, providing guidance and education on code security related problems by leveraging enterprise services across product lifecycles, identifying vulnerabilities, and implementing secure solutions.
- Help define security standards around CI/CD pipelines, SAST/SCA/DAST testing processes, DevSecOps principles.
- Support ISO 27001 certification preparation of all Ford Pro software products and services.
- Support all teams dealing with Audit, ICC Control Review and OICs as they occur.
- Collaborate across Ford Pro Tech, Information Tech Operations (ITO), Enterprise Architecture, Model E and Enterprise Cyber Security organizations and so many more.
- Work with all regular security and compliance annual activities and education plan for all Ford Pro teams to ensure compliance with corporate policies to deliver Ford+ plan.
- Facilitate getting all known control gaps identified and develop control improvement plans in partnership with Internal Controls team as part of GRC processes.
- Partner with Cyber Defense during incident response for Ford Pro teams, as required.
- Support and develop automation solutions that enable our product teams to build and deploy code quickly.
- Leverage cloud technology to promote fast provisioning and scalability.
- Implement industry best practices for API configuration management.
- Cross between technology and business topics being able to explain security topics to any audience.
- Operate independently and adapt to dynamic needs of the organization and changing teams.
- Bachelor’s degree in business, Cyber Security, IT management, Risk Management, Computer Science, or Computer Engineering or any related field
- 5+ years’ experience in cybersecurity analysis, vulnerability management, security consulting, secure software engineering.
- Experience in security operations including delivery of security findings to software engineering teams and consulting on risk priorities for vulnerabilities.
- Ability to work collaboratively with others and navigate complex decision making.
- Familiarity with automation test scripts, test plans and configuration of test systems, security testing tools and their use in an SDLC.
- Experience working with GCP and particularly securing GCP assets and development pipelines.
- Experience working in incident Response teams to detect, contain, investigate, and recover from security incidents.
- Experience supporting cloud-based platforms in an enterprise environment such as: Google Cloud Platform (GCP), Microsoft Azure, and Amazon Web Services (AWS).
- Experience using 1 or more SAST/SCA tools like CheckMarx, FOSSA, 42Crunch or BlackDuck
- Strong working knowledge of Info Sec policy, global purchasing policies and process, GRC component assessment, controls testing, etc.
- Strong understanding of the OWASP Top 10 security vulnerabilities and remediation techniques
- Working knowledge of a variety of regulations, control frameworks, and requirements, such as SOX, NIST 800-53, NIST 800-171, ISO 27001
- Working knowledge of API Security
- Security coding experience with languages like Java, Java Script, Python, Ruby or equivalent
- Strong understanding of Security Engineering concepts around key management, authorization, Cloud Security etc.
- Experience working with GAO and/or Internal Control
- Certifications are highly valued (CISSP, CISA, CISM, etc.)
- Master’s degree in cyber security, Computer Science, Software Engineering, or a related field.
- Security architecture experience collaborating with software product teams.
- Experience with Git/GitHub or equivalent source control repositories.
- Experience using a centralized logging solution such as Splunk or Datadog for monitoring and reporting.
- IT operations, security, and/or infrastructure experience in an enterprise environment.
- Experience with vulnerability management with understanding of CVEs, CWEs and how to research and manage risks.
- Comfortable communicating with different levels and audiences effectively to gain attention collaboratively while not causing panic or animosity.
- A strong drive to keep learning new tools, ideas, techniques and methodologies to change culture to one based on building security and privacy into solutions from inception.
- Motivated to support compliance to standards and policies as foundational to security.
- 5+ years’ experience in cybersecurity analysis, vulnerability management, security consulting, secure software engineering.
- Experience in security operations including delivery of security findings to software engineering teams and consulting on risk priorities for vulnerabilities.
- Ability to work collaboratively with others and navigate complex decision making.
- Familiarity with automation test scripts, test plans and configuration of test systems, security testing tools and their use in an SDLC.
- Experience working with GCP and particularly securing GCP assets and development pipelines.
- Experience working in incident Response teams to detect, contain, investigate, and recover from security incidents.
0
Education Required
- Bachelor’s degree in business, Cyber Security, IT management, Risk Management, Computer Science, or Computer Engineering or any related field
Additional Safety Training/Licensing/Personal Protection Requirements:
Additional Information
Interested in Hybrid or Remote Candidates
-
Seniority level
Mid-Senior level -
Employment type
Contract -
Job function
Information Technology -
Industries
IT Services and IT Consulting
Referrals increase your chances of interviewing at Megan Soft Inc by 2x
See who you knowGet notified about new Cyber Security Consultant jobs in United States.
Sign in to create job alertSimilar jobs
People also viewed
-
VP of Cybersecurity
VP of Cybersecurity
-
Offensive Security Senior Consultant
Offensive Security Senior Consultant
-
Remote Work - Need Mainframe Security Consultant
Remote Work - Need Mainframe Security Consultant
-
Manager, Cyber Security Operations
Manager, Cyber Security Operations
-
Dir, Cyber Security (930804)
Dir, Cyber Security (930804)
-
Chief Information Security Officer Advisor
Chief Information Security Officer Advisor
-
Cyber Risk Assessor with Top Secret
Cyber Risk Assessor with Top Secret
-
Cyber Risk Consultant (FedRAMP) l REMOTE l - $95,000 - $125,000
Cyber Risk Consultant (FedRAMP) l REMOTE l - $95,000 - $125,000
-
Domain Consultant - Network Security Transformation, SASE
Domain Consultant - Network Security Transformation, SASE
-
Cyber Security Consultant
Cyber Security Consultant
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More