Jobs and Careers
FO

DevOps Engineer-Security Identity & Access Management

Ford Motor Company
United Statesfull_timeVerifiedPosted 20 Aug 2025

About the role

We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we’re all a part of something bigger than ourselves. Are you ready to change the way the world moves? 

As part of the Security Identity and Access Management team, we are hiring a DevOps Engineer with a primary technical focus on Google Cloud Platform (GCP). This role offers an exciting opportunity to apply your strong cloud engineering skills to critical security challenges, helping secure our vital cloud, on-prem, and hybrid environments.

You will be a key contributor in a DevSecOps framework, blending development, operations, and security practices to build and maintain our Identity and Access Management (IAM) and Privileged Access Management (PAM) infrastructure. This position requires a candidate capable of managing concurrent and complex development and operational tasks, implementing secure, scalable, automated, and resilient access controls, automating security tasks, and ensuring operational excellence across the platform. You'll work primarily with GCP, understanding how different PAM/IAM systems might coexist or integrate across our enterprise.

Due to the business-critical and global nature of the ePAM platform, this position provides an outstanding opportunity to engage with, deliver value and gain exposure to Global business units, JVs and Technology teams, including Ford Credit, Ford Pro and Model e, Ford Blue, Manufacturing, EPEO, Application Employee Experience, Enterprise Connectivity/Network teams and Cyber Defense.

 

What you'll do...

1.    Secure, Reliable, and Scalable IAM/PAM Implementation in GCP:
•    You will contribute to the design and implement secure, reliable, and scalable GCP IAM/PAM policies and structures, rigorously applying the principle of least privilege across our GCP footprint (Organizations, Folders, Projects). This includes implementing and refining secure patterns for managing GCP IAM/PAM roles, service accounts, and their credentials, leveraging modern GCP security features like Workload Identity Federation and Access Context Manager, while also considering the availability and performance impact.
•    You will conduct technical security and reliability reviews of proposed GCP architectures to identify and mitigate potential identity and access-related risks and single points of failure early in the lifecycle.
2.    Implementing and Managing PAM Solutions with Reliability in Mind (Across Hybrid Environments):
•    You will implement and maintain solutions for managing privileged accounts and secrets across our environment, with a focus on assets within or interacting with GCP, Entra/InTune. This includes leveraging GCP-native services like Secret Manager where appropriate and understanding how to integrate with or manage credentials stored within other enterprise PAM tools.
•    You will define and enforce security policies around privileged session management, monitoring, and auditing, considering the operational stability and capabilities of the various PAM tools in use.
3.    Automated Security Enforcement & Operational Excellence (DevSecOps & SRE Integration):
•    You will embed automated security and operational checks, including validation for IAM/PAM configurations, directly into our CI/CD pipelines using Infrastructure as Code (IaC) tools like Terraform for GCP resources, to prevent insecure or unstable deployments.
•    You will automate security-critical tasks such as credential rotation, access reviews, and compliance checks programmatically, championing "Security as Code" and "Operations as Code" across the GCP environment and potential integrations with other systems.
•    You will utilize APIs to develop solutions, collect identity-related data and automate security & operational tasks in a hybrid environment.
4.    Observability, Monitoring, Threat Detection, and Incident Response:
•    You will implement and maintain observability solutions (metrics, logs, traces) and configure relevant logging sources (including security and PAM logs) to gain deep insights into system behavior, performance, and security events.
•    You will utilize detection and monitoring tools (like Dynatrace or similar platforms) to analyze system health, performance, and availability, proactively detect suspicious or malicious activity, and develop/maintain security, performance, and availability alerts, dashboards, and reporting.
•    With our team being Global,  you will provide support and be a key participant in the investigation and response to and resolution of security and reliability incidents, applying SRE practices and focusing on minimizing Mean Time To Detect (MTTD) and Mean Time To Recover (MTTR).
5.    Security,

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Ford Motor Company

View company profile →