Toyota's Cybersecurity & Risk Management (CSRM) group objective is to become a global cybersecurity leader in the mobility space - with the talent, scale, and services to enable our mission of securely bringing mobility for all.
Requirements
- 5+ years of hands-on experience securing and managing Unix/Linux systems in a large, diverse multi-national enterprise.
- Demonstrated ability to conduct thorough vulnerability assessments and risk analyses on complex applications and systems.
- Proven scripting experience with Bash and at least one of the following: Python, Perl or PowerShell.
- Experience in configuring intrusion detection/prevention systems, patch management, system hardening and intrusion detection systems.
- Experience with centralized configuration management, such as Ansible, Puppet, Chef, etc.
- Network segmentation or Zero-Trust experience.
- Any AI skills and/or knowledge of detecting AI misuse.
Responsibilities
- Conduct security assessments of complex Windows and Unix/Linux systems to help develop, enforce, and audit security standards and requirements.
- Collaborate with IT, Sales Field Offices, Parts Distribution Centers, Vehicle Distribution Centers, Manufacturing Facilities, R&D Engineering, Digital Engineering, and other engineering teams to integrate cybersecurity into the system lifecycles, from greenfield to brownfield.
- Provide subject matter expertise in areas such as Windows and Unix/Linux security architecture design.
- Identify and effectively communicate potential Windows and Unix/Linux risks and their associated impacts, and provide recommendations for effective risk mitigation.
- Design Windows and Unix/Linux Cybersecurity solutions for hardening, logging, monitoring, secure access, advanced threat detection, and intrusion detection systems.
- Support the tracking of and automated installation of TLS certificates.
- Drive integration and adoption of Cybersecurity standards and tools across multiple domains.
Other
- Bachelor’s Degree in Engineering or STEM or equivalent work experience.
- Familiarity with key regulations (e.g., PCI, HIPAA, CCPA, etc.) and how to apply them in practice.
- Relevant security certifications from CompTIA, ISC2, GAIC, etc. are highly valued as evidence of expertise.
- Certification for a Unix or Linux OS (e.g., Red Hat Enterprise Linux).
- Excellent communication skills to collaborate with cross-functional teams (IT, engineering, operations) and technically lead security initiatives.