# Cloud-Native Security & AI Architect (GCP / Zero Trust)

**Company**: Ford Credit
**Location**: Dearborn, MI
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Automotive

**Apply**: https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/66434?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_de9cd915-f43

## Description

Ford Credit is seeking a Cloud-Native Security & AI Architect to guide on-prem workload migrations into a secure, well-architected GCP environment, while shaping their approach to safe and effective AI enablement.

**About the Role:** Ford Credit is accelerating its transition to a Zero-Trust security model on Google Cloud Platform (GCP) and maturing their enterprise cloud security patterns. This role will help establish practical reference architectures, answering various “How do I do X securely?” questions from internal teams, driving clarity where standards are still emerging.

**What Success Looks Like (6–12 Months):**

- Documented, adopted reference architectures and patterns for Zero Trust on GCP.

- Reduced critical security gaps across migrated workloads; measurable maturity lift.

- Repeatable Apigee patterns established; known gaps documented with remediation backlog and owners.

- Teams self-serve with “How to do X securely?” guides; faster decision cycles and fewer escalations.

- Safe, pragmatic AI enablement patterns integrated into SDLC with clear guardrails and logging.

- Established security governance frameworks and stage-gates with both automation and human-in-the-loop processes.

**Responsibilities:**

**Zero-Trust Cloud Security Architecture (GCP) – primary focus**

- Define and mature security architecture patterns and reference architectures for cloud-native workloads on GCP.

- Provide day-to-day guidance to application teams migrating from legacy environments to a new Zero-Trust GCP segment.

- Conduct gap analyses and recommend remediations to raise security maturity.

- Translate Ford’s Information Security Policies into actionable architecture guidance and guardrails.

- Establish “golden paths” for securing RPC endpoints, service-to-service auth, workload identity, runtime security, and logging.

- Design and document secure patterns for hybrid connectivity, ensuring safe data exchange and identity federation between on-premise data centers and GCP.

- Develop a holistic security strategy for critical third-party SaaS applications, focusing on identity integration, data governance, and unified visibility.

- Partner with threat modeling, networking, and data architecture teams to ensure holistic, risk-balanced designs.

**API & Apigee Security Enablement**

- Define patterns for securing APIs and RPC endpoints with Apigee.

- Identify platform gaps; collaborate with Ford’s Apigee owner to drive improvements and reusable examples.

**AI Architecture (Agentic SDLC) – secondary focus**

- Evaluate AI-enabled solutions for safety and security.

- Define secure agent patterns for SDLC use cases.

- Apply AI safety best practices.

- Design human-in-the-loop, decision traceability, and auditable logging for AI-assisted decision flows.

**Process & Enablement**

- Create and maintain clear, consumable architecture documentation and standards.

- Mentor teams; answer questions rapidly; help the org balance speed with security in a zero-trust context.

- Contribute to a pragmatic roadmap to improve security maturity across the portfolio.

**Qualifications:**

**Minimum Qualifications**

- 10+ years of IT experience with 7+ years in cloud architecture/engineering with 4+ years focused on cloud security.

- Deep hands-on experience with GCP services relevant to security.

- Proven experience designing or maturing Zero-Trust architectures.

- Strong understanding of OAuth/OIDC, service-to-service auth, token flows, and API security patterns.

- Experience designing security for hybrid architectures that connect modern cloud platforms with traditional enterprise data centers.

- Experience with SaaS security frameworks and tools.

- Integrate security seamlessly into the CI/CD pipeline.

- Experience producing reference architectures, standards, and “golden paths” for engineering teams.

- Good knowledge of security.

- Hands-on use of AI tools to improve productivity.

- Excellent communication and stakeholder enablement skills.

**Preferred Qualifications**

- GCP security certifications.

- Experience with Apigee at enterprise scale.

- Familiarity with LLM/agent attack vectors and mitigations.

- Exposure to spec-driven development and content-distributed architectures.

- Comfortable navigating ambiguity and building standards in-flight during large-scale migrations.

## Skills

### Required
- GCP
- Zero Trust
- cloud security
- Apigee
- AI
- SDLC
- OAuth/OIDC
- API security
- hybrid architectures
- SaaS security
- CI/CD pipeline
- reference architectures

### Nice to have
- GCP security certifications
- Apigee at enterprise scale
- LLM/agent attack vectors
- spec-driven development
- content-distributed architectures

---

Source: [Apply at efds.fa.em5.oraclecloud.com](https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/66434?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
