<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>41857894-7ab</externalid>
      <Title>DevSecOps Engineer – Identity &amp; Access Management</Title>
      <Description><![CDATA[<p>The DevSecOps Engineer will play a pivotal role in integrating robust security practices throughout the DevOps lifecycle, with a primary emphasis on identity and access management (IAM) using Microsoft Entra ID (formerly Azure AD).</p>
<p>This role is responsible for designing and implementing secure automation pipelines, enforcing least-privilege and Zero Trust access controls, and managing enterprise identity governance to meet both organisational and regulatory compliance requirements.</p>
<p>In addition to strong Entra ID expertise, the ideal candidate will bring hands-on experience with GCP pipeline deployment, infrastructure-as-code (IaC), and custom agent development to enhance cloud security observability, policy enforcement, and workload protection across cloud environments.</p>
<p>Responsibilities:</p>
<ul>
<li>Design and integrate security tooling into CI/CD pipelines using GitHub Actions and GCP Cloud Build to ensure automated code scanning, dependency security, secrets scanning, and policy enforcement.</li>
</ul>
<ul>
<li>Develop secure, automated pipelines on the GCP platform, enabling continuous compliance validation, vulnerability scanning, and policy-as-code deployment for cloud workloads and containerised environments.</li>
</ul>
<ul>
<li>Implement and manage emerging Microsoft Entra ID security controls, also including Conditional Access, Identity Protection, Privileged Identity Management (PIM), Identity Governance, and adaptive MFA policies across enterprise workloads.</li>
</ul>
<ul>
<li>Leverage emerging Entra technologies such as Entra Agent ID, Entra Workload ID, Identity Governance lifecycle workflows, and Zero-Trust deployments,to strengthen identity protection, automate governance, and modernise access strategies.</li>
</ul>
<ul>
<li>Continuously evaluate new features in Microsoft Entra ID and GCP IAM, providing architectural recommendations and integrating relevant capabilities into enterprise DevSecOps workflows.</li>
</ul>
<ul>
<li>Automate identity and security configuration using scripting and IaC tools such as Terraform, Ansible and ARM templates, with multi-cloud pipeline support for Azure and GCP.</li>
</ul>
<ul>
<li>Build and maintain custom security agents and automation workflows to enhance identity telemetry, enforce real-time access policies, and standardise cloud security controls across environments.</li>
</ul>
<ul>
<li>Conduct regular reviews of roles, permissions, service principals, workload identities, and application registration security, ensuring least-privilege access and Zero Trust alignment.</li>
</ul>
<ul>
<li>Collaborate with engineering teams to perform secure code reviews, threat modelling, vulnerability assessments, and provide remediation guidance during development and deployment cycles.</li>
</ul>
<ul>
<li>Develop dashboards, reports, and automation for identity compliance, audit readiness, and IAM security posture using tools like Azure Monitor, GCP Looker, Sentinel, and BigQuery.</li>
</ul>
<p>Qualifications:</p>
<ul>
<li>Strong technical, troubleshooting, and strategical skills to build emerging technology solutions at scale.</li>
</ul>
<ul>
<li>3–6+ years of experience in DevOps, SecOps, or Cloud Security Engineering roles.</li>
</ul>
<ul>
<li>Strong hands-on experience with Microsoft Entra ID (AuthN Protocols, Conditional Access, PIM, Identity Protection, Graph API and automation).</li>
</ul>
<ul>
<li>Lead GCP cloud deployments and build scalable, secure automation pipelines, leveraging Cloud Build, Cloud Deploy, Artifact Registry, and GCP-native IaC to support continuous delivery, compliance automation, and multi-cloud DevSecOps workflows.</li>
</ul>
<ul>
<li>Experience with IaC: Terraform, Bicep, or ARM templates.</li>
</ul>
<ul>
<li>Knowledge of container security, Kubernetes, and cloud-native security patterns.</li>
</ul>
<ul>
<li>Solid understanding of Zero Trust principles, IAM, and identity lifecycle management.</li>
</ul>
<ul>
<li>Familiarity with vulnerability management tools and SAST/DAST integrations (42Crunch, CheckmarX and FOSSA)</li>
</ul>
<ul>
<li>Microsoft Azure certifications (e.g., AZ-500, SC-300, AZ-104, AZ-305) are a strong plus.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Microsoft Entra ID, GCP pipeline deployment, Infrastructure-as-code (IaC), Custom agent development, Cloud security observability, Policy enforcement, Workload protection, CI/CD pipelines, GitHub Actions, GCP Cloud Build, Code scanning, Dependency security, Secrets scanning, Conditional Access, Identity Protection, Privileged Identity Management (PIM), Identity Governance, Adaptive MFA policies, Entra Agent ID, Entra Workload ID, Identity Governance lifecycle workflows, Zero-Trust deployments, Terraform, Ansible, ARM templates, Multi-cloud pipeline support, Azure, GCP, Cloud security controls, Least-privilege access, Zero Trust alignment, Secure code reviews, Threat modelling, Vulnerability assessments, Remediation guidance, Identity compliance, Audit readiness, IAM security posture, Azure Monitor, GCP Looker, Sentinel, BigQuery</Skills>
      <Category>Engineering</Category>
      <Industry>Automotive</Industry>
      <Employername>Ford Global Career Site Careers</Employername>
      <Employerlogo>https://logos.yubhub.co/careers.ford.com.png</Employerlogo>
      <Employerdescription>Ford is an American multinational automaker that designs, manufactures, markets, and services vehicles.</Employerdescription>
      <Employerwebsite>https://careers.ford.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/60841?utm_source=yubhub.co&amp;utm_medium=jobs_feed&amp;utm_campaign=apply</Applyto>
      <Location>Chennai</Location>
      <Country></Country>
      <Postedate>2026-04-25</Postedate>
    </job>
    <job>
      <externalid>e1b04487-4c3</externalid>
      <Title>Security Engineer - Azure Government</Title>
      <Description><![CDATA[<p>We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security controls across our Azure Gov Cloud environment (including hybrid and multi-cloud scenarios). In this hands-on role, you will build, strengthen, and maintain our cloud security posture, protect critical workloads, and collaborate with engineering, DevOps, and compliance teams to embed security throughout the development lifecycle. You will develop, implement, and leverage Microsoft&#39;s native security tools to detect threats, respond to incidents, and ensure alignment with industry standards and regulations. Lastly, you will be required to both achieve and maintain compliance with government regulations such as FedRAMP and CMMC.</p>
<p>Responsibilities: Implement, design, and manage security architecture for Azure Government and Commercial deployments (with considerations for DoD IL5\IL6 and FedRAMP High controls) Configure and optimize Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, and related services for threat detection, vulnerability management, and automated response Design and enforce identity &amp; access management using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policies, RBAC, and just-in-time access Secure network architectures with Azure Firewall, Network Security Groups (NSGs), DDoS Protection, Web Application Firewall (WAF), Network Watcher, and private endpoints Protect data at rest and in transit via Azure Key Vault, encryption strategies, data classification, and information protection controls Develop and maintain security policies, initiatives, and blueprints using Azure Policy and Microsoft Purview for compliance (NIST, FedRAMP, CMMC, STIGs, etc.) Perform threat hunting, incident response, and forensics using Sentinel playbooks, Log Analytics, and KQL queries Conduct security reviews of Infrastructure as Code (IaC), containers, Kubernetes (AKS), and serverless workloads Collaborate with developers and architects to implement DevSecOps practices, including secure CI/CD pipelines, code scanning, and secure defaults Monitor and remediate security findings, reduce attack surface, and improve overall security posture per the Microsoft Cloud Security Benchmark (MCSB) Deploy configurations and compliance policies to Azure AVD endpoints using Intune and other Azure native services.</p>
<p>Basic Qualifications: Active U.S. security clearance (e.g., Secret, Top Secret) or eligibility to obtain one. 3+ years of experience in cloud security, cybersecurity engineering, or related roles (with strong Azure focus). Deep hands-on expertise with core Azure security services: Microsoft Defender suite, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, and Purview. Strong understanding of DLP implementation both in cloud and on endpoints utilizing Purview and other Microsoft native controls. Experience implementing security in hybrid/multi-cloud environments. Proficiency in scripting/automation (PowerShell, Azure CLI, Bicep/ARM templates, Terraform). Strong understanding of identity federation, zero-trust principles, encryption, network security, and vulnerability management. Familiarity with compliance frameworks (NIST, FedRAMP, CMMC, STIGs, etc.) and regulatory requirements. Excellent problem-solving, analytical, and communication skills. Strong verbal and written communication skills and the ability to stay composed under pressure.</p>
<p>Preferred Skills and Experience: Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100). Additional relevant certifications (e.g., CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD). Deep experience with detection and response engineering and SOC operations. Knowledge of container security (Docker, AKS), secure DevOps, or AI/ML workload protection. Prior experience in government regulations frameworks such as FedRAMP and CMMC.</p>
<p>ITAR Requirements: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.</p>
<p>Compensation and Benefits: $180,000 - $440,000 USD. Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$180,000 - $440,000 USD</Salaryrange>
      <Skills>Azure Security Engineer, Cloud Security, Cybersecurity Engineering, Microsoft Defender, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, Purview, DLP, Identity Federation, Zero Trust Principles, Encryption, Network Security, Vulnerability Management, Compliance Frameworks, Regulatory Requirements, Problem-Solving, Analytical Skills, Communication Skills</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>xAI</Employername>
      <Employerlogo>https://logos.yubhub.co/xai.io.png</Employerlogo>
      <Employerdescription>xAI creates AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. The organisation has a small, highly motivated team focused on engineering excellence.</Employerdescription>
      <Employerwebsite>https://www.xai.io/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/xai/jobs/5050657007?utm_source=yubhub.co&amp;utm_medium=jobs_feed&amp;utm_campaign=apply</Applyto>
      <Location>Palo Alto, CA; Washington, D.C.</Location>
      <Country></Country>
      <Postedate>2026-04-24</Postedate>
    </job>
  </jobs>
</source>