<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>94b27458-df7</externalid>
      <Title>Identity Security DevOps Engineer</Title>
      <Description><![CDATA[<p>As part of the Security Identity and Access Management team, we are hiring a DevSecOps Engineer with a primary technical focus on Privileged Access Management, including Cloud IAM. This role offers an exciting opportunity to apply your strong engineering skills to critical security challenges, helping secure our vital on-prem, cloud, and hybrid environments.</p>
<p>You will be a key contributor in our Privileged IAM platform, blending development, SRE/operations, and security practices to build and maintain our Privileged IAM products. This position requires a candidate capable of managing concurrent and complex development and operational tasks, implementing secure, scalable, automated, and resilient access controls, automating security tasks, and ensuring operational excellence across the platform. You&#39;ll work in a hybrid (cloud and prem) Privileged IAM environment, understanding how different PAM systems might coexist or integrate across our enterprise.</p>
<p>Due to the business-critical and global nature of the ePAM platform, this position provides an outstanding opportunity to engage with, deliver value and gain exposure to Global business units, JVs and Technology teams, including Ford Credit, Ford Pro and Model e, Ford Blue, Manufacturing, EPEO, Application Employee Experience, Enterprise Connectivity/Network teams and Cyber Defense.</p>
<p>Responsibilities:</p>
<p>Secure IAM/PAM Architecture &amp; Implementation</p>
<ul>
<li>Design &amp; Build: Design scalable Privileged IAM solutions, enforcing the principle of least privilege. You will specifically manage and configure Google PAM, Entra ID PIM, and Microsoft Intune PAM tools.</li>
</ul>
<ul>
<li>Hybrid Integration: Implement solutions for privileged accounts across hybrid environments (GCP, Entra, BeyondTrust PasswordSafe). Utilize cloud-native services (e.g., Secret Manager) while integrating enterprise PAM tools.</li>
</ul>
<ul>
<li>Risk Mitigation: Conduct technical security reviews to identify identity-related risks and single points of failure early in the architectural lifecycle.</li>
</ul>
<p>Automated Security &amp; DevSecOps (SRE Integration)</p>
<ul>
<li>Infrastructure as Code: Embed validation for IAM/PAM configurations directly into CI/CD pipelines using IaC tools (Terraform) to prevent insecure deployments.</li>
</ul>
<ul>
<li>Security Automation: Programmatically automate critical tasks,including credential rotation, access reviews, and compliance checks,championing &quot;Security as Code.&quot;</li>
</ul>
<ul>
<li>API Development: Utilize APIs to develop solutions and collect identity-related data to automate operations in a hybrid environment.</li>
</ul>
<p>Observability, Incident Response &amp; System Health</p>
<ul>
<li>Monitoring: Implement observability solutions (metrics, logs, traces) using tools like Dynatrace and Cloud Monitoring to analyze system health and detect malicious activity.</li>
</ul>
<ul>
<li>Incident Management: Lead the investigation and resolution of security and reliability incidents, applying SRE practices to minimize Mean Time To Detect (MTTD) and Recover (MTTR).</li>
</ul>
<ul>
<li>Maintenance: Maintain the operational health and performance of the PAM infrastructure, ensuring stability across integrated systems.</li>
</ul>
<p>Governance, Compliance &amp; Collaboration</p>
<ul>
<li>Strategy &amp; Compliance: Evolve the IAM/PAM posture to meet internal standards and external compliance requirements (SOC 2, ISO 27001).</li>
</ul>
<ul>
<li>Knowledge Sharing: Provide guidance on secure credential handling and application interaction to engineering and operations teams.</li>
</ul>
<ul>
<li>Documentation: Create high-quality documentation, including architecture diagrams, system runbooks, and risk assessments.</li>
</ul>
<p>Our preferred requirements:</p>
<ul>
<li>PAM Expertise: Experience with Privileged Access Management solutions from BeyondTrust or CyberArk, specifically workforce Privileged credential/password management.</li>
</ul>
<ul>
<li>Automation &amp; Scripting: Strong experience with scripting/programming languages (Python, Golang, BASH, PowerShell) and utilizing APIs (including Microsoft Graph API) for automation and solution development.</li>
</ul>
<ul>
<li>Problem Solving: Proven ability to independently identify, analyze, and solve complex technical and operational problems with minimal oversight.</li>
</ul>
<ul>
<li>Communication: Strong written and verbal communication skills with a high degree of attention to detail.</li>
</ul>
<ul>
<li>SRE Principles: Solid understanding of Site Reliability Engineering practices (SLOs/SLIs, toil reduction, incident response).</li>
</ul>
<ul>
<li>Cloud IAM: Strong practical experience with Cloud Identity and Access Management (IAM) concepts (roles, policies, service accounts) and related security services.</li>
</ul>
<ul>
<li>CI/CD &amp; IaC: Experience with pipeline development, Infrastructure as Code, and Terraform.</li>
</ul>
<ul>
<li>Cloud Core Services: Hands-on experience with core cloud platform components across major providers (AWS, Azure, or GCP).</li>
</ul>
<ul>
<li>Containerization: Experience with Docker and Kubernetes/GKE.</li>
</ul>
<ul>
<li>Observability: Experience with monitoring tools (Dynatrace, Cloud Audit Logs).</li>
</ul>
<p>Nice to have:</p>
<ul>
<li>Understanding of Enterprise security domains with a strong emphasis on Identity and Access Management  and Cloud Security.</li>
</ul>
<ul>
<li>Familiarity with Microsoft Entra Privileged Access Management.</li>
</ul>
<ul>
<li>Experience with Perl programming/scripting.</li>
</ul>
<ul>
<li>Familiarity with security risk assessment methodologies and compliance frameworks (SOC 2, ISO 27001)</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Privileged Access Management, Cloud IAM, Google PAM, Entra ID PIM, Microsoft Intune PAM, Terraform, Infrastructure as Code, Security Automation, API Development, Dynatrace, Cloud Monitoring, Observability, Incident Response, System Health, Governance, Compliance, Collaboration, PAM Expertise, Automation &amp; Scripting, Problem Solving, Communication, SRE Principles, CI/CD &amp; IaC, Cloud Core Services, Containerization</Skills>
      <Category>Engineering</Category>
      <Industry>Automotive</Industry>
      <Employername>Ford Global</Employername>
      <Employerlogo>https://logos.yubhub.co/ford.com.png</Employerlogo>
      <Employerdescription>Ford Global is a multinational corporation that designs, manufactures, markets, and services a full line of Ford cars, trucks, vans, and SUVs, as well as Lincoln luxury vehicles.</Employerdescription>
      <Employerwebsite>https://www.ford.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/60935?utm_source=yubhub.co&amp;utm_medium=jobs_feed&amp;utm_campaign=apply</Applyto>
      <Location>Chennai</Location>
      <Country></Country>
      <Postedate>2026-04-30</Postedate>
    </job>
    <job>
      <externalid>791144c2-47c</externalid>
      <Title>Sr Staff Production Engineer- Public Sector</Title>
      <Description><![CDATA[<p>At Databricks, we are looking for a Sr Staff Production Engineer- Public Sector to join our team. In this role, you will own and evolve the secure infrastructure, access patterns, and guardrails that keep Databricks&#39; global platform safe and compliant in production. You will be responsible for the &#39;sovereign layer&#39; of our infrastructure, ensuring that our Data Intelligence Platform operates with 100% reliability and security in highly regulated, air-gapped, and sovereign environments.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Design, automate, and operate the IAM, account/subscription, and project lifecycle across AWS, Azure, and GCP, enforcing least-privilege and standardized access patterns at scale.</li>
</ul>
<ul>
<li>Review, implement, and continuously improve cloud identity and access policies (IAM, Okta, Opal) to align with Databricks security standards and audit requirements.</li>
</ul>
<ul>
<li>Build and maintain reliable, observable automation and tooling to apply cloud changes (roles, policies, accounts, networking) safely and repeatedly.</li>
</ul>
<ul>
<li>Treat operational and security issues as software problems: eliminate toil, drive root-cause analysis, and codify fixes into infrastructure and tooling.</li>
</ul>
<ul>
<li>Own and improve security and audit logging data pipelines from cloud providers into our internal systems, ensuring timely, accurate data for detection, investigations, and audits.</li>
</ul>
<ul>
<li>Partner with Security, Compliance, and Audit teams to provide evidence, clarifications, and policy updates that keep our environments aligned with evolving standards.</li>
</ul>
<ul>
<li>Operate and improve specialized, highly regulated environments (e.g., FedRAMP / GovCloud) including release management, patching cadences, and supporting secure access workflows (e.g., SAW).</li>
</ul>
<ul>
<li>Ensure high availability and resiliency for critical security and access infrastructure across these environments.</li>
</ul>
<ul>
<li>Participate in a 24x7 on-call rotation for high-severity incidents impacting cloud accounts, IAM, or security data pipelines.</li>
</ul>
<ul>
<li>Act as a key partner to product engineering, security engineering, and field teams during incidents to restore service and harden systems for the future.</li>
</ul>
<p>Requirements:</p>
<ul>
<li>Candidates must be eligible for a Top Secret / Sensitive Compartmented Information (TS/SCI) security clearance.</li>
</ul>
<ul>
<li>Possession of a current polygraph (Counterintelligence or Full Scope) is highly desired and considered a significant plus.</li>
</ul>
<ul>
<li>Education- BS, MS, or PhD in Computer Science, Engineering, or a related technical field, or equivalent practical experience.</li>
</ul>
<ul>
<li>Experience: 12+ years of experience, including leading the strategy for cloud IAM, account architecture, or security-critical infrastructure across multiple environments or business units.</li>
</ul>
<ul>
<li>Cloud &amp; Infrastructure Expertise</li>
</ul>
<ul>
<li>Deep hands-on experience with at least one major cloud provider (AWS, Azure, or GCP) in areas such as IAM, networking, accounts/subscriptions/projects, and audit logging.</li>
</ul>
<ul>
<li>Strong background in Infrastructure-as-Code and automation (e.g., Terraform, CloudFormation, or similar) and CI/CD for infrastructure changes.</li>
</ul>
<ul>
<li>Security &amp; Compliance Mindset</li>
</ul>
<ul>
<li>Proven experience working in or with security-sensitive or regulated environments (e.g., SOC2, FedRAMP, ISO 27001, financial services, public sector) and translating requirements into concrete technical controls.</li>
</ul>
<ul>
<li>Familiarity with access review processes, policy baselines, and audit evidence for cloud environments.</li>
</ul>
<ul>
<li>Operational Excellence</li>
</ul>
<ul>
<li>Demonstrated success running high-availability, security-critical services, including on-call responsibilities and incident management.</li>
</ul>
<ul>
<li>Strong debugging and problem-solving skills across distributed systems, with the ability to navigate ambiguous issues spanning multiple teams and platforms.</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Experience with Okta, Opal, or similar identity/access tooling.</li>
</ul>
<ul>
<li>Background operating secure admin workstations (SAW) or comparable hardened access patterns.</li>
</ul>
<ul>
<li>Experience migrating cloud accounts or subscriptions during M&amp;A or large-scale reorganizations.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$195,400-$268,600 USD</Salaryrange>
      <Skills>Cloud IAM, Cloud infrastructure, Infrastructure-as-Code, Automation, CI/CD, Security and compliance, Access review processes, Policy baselines, Audit evidence, High-availability services, Security-critical services, On-call responsibilities, Incident management, Debugging and problem-solving skills, Distributed systems, Okta, Opal, Identity/access tooling, Secure admin workstations, Hardened access patterns, Cloud account migration, Subscription migration</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Databricks</Employername>
      <Employerlogo>https://logos.yubhub.co/databricks.com.png</Employerlogo>
      <Employerdescription>Databricks is a data and AI company that provides a unified and democratized data, analytics, and AI platform to over 10,000 organizations worldwide.</Employerdescription>
      <Employerwebsite>https://databricks.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/databricks/jobs/8519396002?utm_source=yubhub.co&amp;utm_medium=jobs_feed&amp;utm_campaign=apply</Applyto>
      <Location>Virginia</Location>
      <Country></Country>
      <Postedate>2026-04-24</Postedate>
    </job>
  </jobs>
</source>