Cybersecurity Risk Engineer Director
Ford Motor CompanyAbout the role
We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we’re all a part of something bigger than ourselves. Are you ready to change the way the world moves?
Enterprise Technology plays a critical part in shaping the future of mobility. If you’re looking for the chance to leverage advanced technology to redefine the transportation landscape, enhance the customer experience and improve people’s lives, this is the opportunity for you. Join us and challenge your IT expertise and analytical skills to help create vehicles that are as smart as you are.
This job is posted as REMOTE but designated as HYBRID with up to three days per week onsite may be required for candidates within commuting distance from our Dearborn, MI.,offices. (Eastern Time Zone, Central Time Zone preferred)
Visa sponsorship is NOT available for this position.
We are seeking a highly skilled and strategic Cyber Security Risk Engineer Director to lead our core cybersecurity risk engineering functions. This critical leadership role demands a deep technical understanding and a hands-on approach to designing, building, and owning the robust security capabilities that protect our enterprise. You will be instrumental in developing and implementing engineering strategies and solutions across Governance, Risk, and Compliance (GRC), Patch and Configuration Management, Business Impact Analysis (BIA) tooling (including its application to Business Continuity and Disaster Recovery), and Proactive Security Analysis responsibilities. A key aspect of this role is partnering closely with key security teams across the organization, ensuring they are equipped with the advanced tools and capabilities necessary to effectively protect the organization's assets and operations.
- Cyber Security Engineering Strategy, Ownership & Leadership:
- Define, develop, and execute a forward-thinking cybersecurity engineering strategy that directly reduces organizational risk and aligns with business objectives.
- Take direct ownership of the design, architecture, and implementation of innovative security solutions and controls, ensuring their effectiveness and scalability.
- Drive a culture of engineering excellence, continuous improvement, and automation across all security domains.
- Provide expert technical guidance and thought leadership on emerging cyber threats, vulnerabilities, and advanced risk mitigation engineering strategies to senior leadership and technical teams.
- Manage the engineering budget and technology roadmap for core security platforms, optimizing investments for maximum security posture improvement.
- Partner extensively with key stakeholders across the organization to understand their operational needs, provide them with the necessary engineering tools, platforms, and capabilities, and enable their success in protecting the enterprise.
- Governance, Risk, and Compliance (GRC) Engineering & Audit Compliance:
- Lead the engineering, development, and ongoing maintenance of GRC platforms and tools, ensuring they effectively support risk management, compliance, and audit requirements.
- Drive the automation of GRC processes, including continuous control monitoring, risk assessments, and compliance reporting, to enhance efficiency and accuracy.
- Engineer solutions that facilitate seamless risk audit compliance for the organization, proactively identifying and addressing control gaps.
- Collaborate with GRC, audit, and legal teams to translate regulatory requirements and internal policies into actionable, auditable engineering controls and solutions.
- Develop and maintain a risk-based cyber control program, focusing on the engineering aspects of control design, implementation, and effectiveness measurement across the enterprise.
- Patch and Configuration Management Engineering:
- Direct and own the engineering efforts for enterprise-wide patch and configuration management programs, ensuring the secure, compliant, and consistent state of all systems and applications.
- Lead the development and implementation of advanced, automated solutions for vulnerability remediation, patch deployment, and secure configuration enforcement across diverse IT and OT environments.
- Establish, engineer, and enforce methodologies and standards for secure configuration baselines, ensuring adherence to internal policies and industry best practices.
- Drive initiatives to proactively identify and mitigate configuration drift, unauthorized changes, and critical patch vulnerabilities, minimizing the attack surface.
- Oversee the engineering of robust monitoring and re
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s