Toyota's Cybersecurity & Risk Management (CSRM) group objective is to become a global cybersecurity leader in the mobility space - with the talent, scale, and services to enable our mission of securely bringing mobility for all.
Requirements
- 5+ years of experience in cybersecurity, with a focus on penetration testing activities.
- Strong understanding of security principles, attack methodologies, and vulnerability assessment techniques.
- Experience with common penetration tooling platforms, such as Kali, etc.
- Deep knowledge of common network protocols, operating systems, security tools, and how to exploit / circumvent them.
- Experience with application development and implementing or developing mitigating controls in a large environment.
- Exploitation experience with Active Directory / Azure Active Directory, containerization platforms (Docker, Kubernetes, etc.), and major cloud environments (AWS, Azure, GCP, etc.)
- Knowledge of industry-standard frameworks and best practices (e.g., NIST, ISO, OWASP).
Responsibilities
- Plan, coordinate, and execute application security assessments to identify vulnerabilities, control gaps, and potential attack vectors in Toyota's information systems.
- Collaborate with application teams and other cybersecurity teams to ensure effective and comprehensive engagements.
- Work closely with the application teams to share insights and knowledge from penetration tests to improve overall security posture.
- Analyze and prioritize findings from application security assessments, making data-driven recommendations to enhance the security of Toyota's systems.
- Produce high-quality reports detailing the results of exercises, including vulnerabilities, risks, and proposed mitigations, and highlighting larger thematic improvement opportunities.
- Provide guidance and support for the implementation of recommended security controls and improvements.
- Stay current with emerging threats, trends, and best practices in the cybersecurity landscape to ensure that Toyota's defenses remain effective and up-to-date.
Other
- Excellent analytical, problem-solving, and decision-making skills.
- Strong written and verbal communication skills, with the ability to effectively convey technical information to both technical and non-technical stakeholders.
- Bachelor’s degree in Computer Science or related discipline, or equivalent work experience.
- Master's degree in Computer Science or related discipline.
- Relevant certifications (e.g., OSCP, OSCE, CISSP) are highly desirable.