Cloud Architect

Ford

Bengaluru

On-site

INR 15,238,000 - 20,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ford is seeking a Cloud-Native Security & AI Architect to lead security architectures for GCP-based workloads and guide migrations to a Zero-Trust model. You will shape AI-enabled SDLC practices with guardrails, logging, and governance while collaborating with enterprise teams on hybrid connectivity and identity integration.

The role requires deep cloud security expertise, strong communication, and the ability to translate policy into actionable architectures.

Qualifications

  • 10+ years of IT experience with 7+ years in cloud architecture/engineering with 4+ years focused on cloud security.
  • Hands-on experience with GCP security services: IAM & Workload Identity, VPC/SCC/Cloud Armor, Secrets Manager, Cloud Logging/Monitoring, GKE/Cloud Run, Artifact/Build, Pub/Sub, Apigee.
  • Proven experience designing Zero-Trust architectures (BeyondCorp principles; identity-centric access).
  • Strong understanding of OAuth/OIDC, service-to-service auth, token flows, and API security patterns.
  • Experience designing security for hybrid architectures that connect modern cloud platforms with traditional enterprise data centers through GCP Interconnect, including mainframe systems.
  • Experience with SaaS security frameworks and tools, such as CASB, SSPM, and DLP strategies.
  • Integrate security into the CI/CD pipeline (DevSecOps), ensuring automated guardrails and IaC scanning are part of the 'golden path.'
  • Experience producing reference architectures, standards, and golden paths for engineering teams.
  • Good knowledge of security.
  • Hands-on use of AI tools to improve productivity (e.g., coding, analysis, documentation).
  • Excellent communication and stakeholder enablement skills.

Responsibilities

  • Define and mature security architecture patterns and reference architectures for cloud-native workloads on GCP.
  • Provide day-to-day guidance to application teams migrating from legacy environments to a new Zero-Trust GCP segment.
  • Conduct gap analyses and recommend remediations to raise security maturity.
  • Translate Ford's Information Security Policies (ISP) into actionable architecture guidance and guardrails.
  • Establish golden paths for securing RPC endpoints, service-to-service auth, workload identity, runtime security, and logging.
  • Design secure patterns for hybrid connectivity, ensuring safe data exchange and identity federation between on-premise data centers and GCP.
  • Develop a holistic security strategy for critical third-party SaaS applications, focusing on identity integration, data governance, and unified visibility.
  • Partner with threat modeling, networking, and data architecture teams to ensure holistic, risk-balanced designs.
  • Create and maintain clear, consumable architecture documentation and standards from multiple sources.
  • Mentor teams; answer questions rapidly; help the org balance speed with security in a zero-trust context.
  • Contribute to a pragmatic roadmap to improve security maturity across the portfolio.

Skills

GCP security
Zero Trust
Apigee
Cloud architecture
CI/CD security
AI in SDLC
Mainframe connectivity
Identity & access management
OAuth/OIDC
Threat modeling

Tools

Terraform
Vault
GCP IAM

Job description

Job Title: Cloud-Native Security & AI Architect (GCP / Zero Trust) Location: Hybrid Dearborn, MI or Fully Remote (US based) Team: Ford Credit Enterprise Architecture

About the Role: Ford Credit is accelerating its transition to a Zero-Trust security model on Google Cloud Platform (GCP) and maturing their enterprise cloud security patterns. They are seeking a Cloud-Native Security & AI Architect to guide on-prem workload migrations into a secure, well-architected GCP environment, while also shaping their approach to safe and effective AI enablement (with a focus on agentic patterns in the SDLC). This role will help establish practical reference architectures, answering various How do I do X securelyquestions from internal teams, driving clarity where standards are still emerging.

What Success Looks Like (612 Months):
  • Documented, adopted reference architectures and patterns for Zero Trust on GCP.
  • Reduced critical security gaps across migrated workloads; measurable maturity lift (e.g., from 1/5 toward 3/5).
  • Repeatable Apigee patterns established; known gaps documented with remediation backlog and owners.
  • Teams self-serve with How to do X securelyguides; faster decision cycles and fewer escalations.
  • Safe, pragmatic AI enablement patterns integrated into SDLC with clear guardrails and logging.
  • Established security governance frameworks and stage-gates with both automation and human-in-the-loop processes.
Tools & Ecosystem:

GCP (IAM, Workload Identity, VPC, SCC, Cloud Armor, Secret Manager, Logging/Monitoring, GKE/Cloud Run, Build/Artifact), Apigee, GitHub, JIRA, Confluence, Vault (as applicable), Terraform (nice to have).

Zero-Trust Cloud Security Architecture (GCP) primary focus
  • Define and mature security architecture patterns and reference architectures for cloud-native workloads on GCP.
  • Provide day-to-day guidance to application teams migrating from legacy environments to a new Zero-Trust GCP segment.
  • Conduct gap analyses and recommend remediations to raise security maturity.
  • Translate Fords Information Security Policies (ISP) into actionable architecture guidance and guardrails.
  • Establish golden pathsfor securing RPC endpoints, service-to-service auth, workload identity, runtime security, and logging.
  • Design and document secure patterns for hybrid connectivity, ensuring safe data exchange and identity federation between on-premise data centers (including mainframe environments) and GCP.
  • Develop a holistic security strategy for critical third-party SaaS applications, focusing on identity integration (SSO), data governance, and unified visibility.
  • Partner with threat modeling, networking, and data architecture teams to ensure holistic, risk-balanced designs.
API & Apigee Security Enablement
  • Define patterns for securing APIs and RPC endpoints with Apigee (authN/Z, token flows, rate limiting, telemetry).
  • Identify platform gaps; collaborate with Fords Apigee owner (EPEO) to drive improvements and reusable examples.
AI Architecture (Agentic SDLC) secondary focus
  • Evaluate AI-enabled solutions for safety and security: Is this secureIs it safeAre we allowed to do this
  • Define secure agent patterns for SDLC use cases (e.g., agents drafting JIRAs, triaging issues).
  • Apply AI safety best practices (prompt injection defenses, tool/API misuse prevention, data leakage controls).
  • Design human-in-the-loop, decision traceability, and auditable logging for AI-assisted decision flows.
Process & Enablement
  • Create and maintain clear, consumable architecture documentation and standards from multiple sources.
  • Mentor teams; answer questions rapidly; help the org balance speed with security in a zero-trust context.
  • Contribute to a pragmatic roadmap to improve security maturity across the portfolio.
Minimum Qualifications
  • 10+ years of IT experience with 7+ years in cloud architecture/engineering with 4+ years focused on cloud security (enterprise scale).
  • Deep hands-on experience with GCP services relevant to security: IAM & Workload Identity, VPC/SCC/Cloud Armor, Secrets Manager, Cloud Logging/Monitoring, GKE/Cloud Run, Artifact/Build, Pub/Sub, Apigee.
  • Proven experience designing or maturing Zero-Trust architectures (BeyondCorp principles; identity-centric access).
  • Strong understanding of OAuth/OIDC, service-to-service auth, token flows, and API security patterns.
  • Experience designing security for hybrid architectures that connect modern cloud platforms with traditional enterprise data centers through GCP Interconnect, including mainframe systems.
  • Experience with SaaS security frameworks and tools, such as Cloud Access Security Brokers (CASB), SaaS Security Posture Management (SSPM), and advanced data loss prevention (DLP) strategies.
  • Integrate security seamlessly into the CI/CD pipeline (DevSecOps), ensuring automated guardrails and infrastructure-as-code (IaC) scanning are part of the "golden path."
  • Experience producing reference architectures, standards, and golden pathsfor engineering teams.
  • Good knowledge of security.
  • Hands-on use of AI tools to improve productivity (e.g., coding, analysis, documentation).
  • Excellent communication and stakeholder enablement skills.
Preferred Qualifications
  • GCP security certifications (e.g., Professional Cloud Security Engineer, Professional Cloud Architect).
  • Experience with Apigee at enterprise scale (API gateways, policies, auth patterns, observability).
  • Familiarity with LLM/agent attack vectors (prompt injection, jailbreaks, tool abuse, data exfiltration) and mitigations aligned to industry frameworks OWASP for LLM, NIST AI RMF etc.
  • Exposure to spec-driven development and content-distributed architectures.
  • Understanding of regulated environment and associated compliance frameworks PCI-DSS, SOC2, CCPA, GDPR and auditable human-in-the loop decisioning.
  • Comfortable navigating ambiguity and building standards in-flight during large-scale migrations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Architect
Cloud Architect

Jobtailor • Bengaluru

On-site
INR 3,200,000 - 5,200,000
Director, Enterprise Architect Enterprise API, AI Security & Governance
Director, Enterprise Architect Enterprise API, AI Security & Governance

Ford Motor Private Limited • Chennai District

On-site
INR 4,000,000 - 7,500,000
DDI Engineering & Automation Lead
DDI Engineering & Automation Lead

Ford • India

On-site
INR 3,500,000 - 7,000,000
Cloud Security Architect
Cloud Security Architect

Searce Inc • Pune District

On-site
INR 4,000,000 - 7,000,000
Senior Enterprise Security Architect
Senior Enterprise Security Architect

AlphaSense Oy • Delhi

On-site
INR 2,500,000 - 4,500,000
Senior Enterprise Security Architect
Senior Enterprise Security Architect

AlphaSense Oy • Pune District

On-site
INR 4,000,000 - 7,000,000
Security Architect - Data, Fabric & AI Security
Security Architect - Data, Fabric & AI Security

ProArch Company • Hyderabad

On-site
INR 2,500,000 - 4,200,000
Staff Security Architect
Staff Security Architect

KFC Corporation • Gurgaon

Hybrid
INR 1,800,000 - 2,500,000
Senior Enterprise Security Architect
Senior Enterprise Security Architect

AlphaSense Oy • Bengaluru

On-site
INR 4,000,000 - 7,500,000
Professional certifications encouraged
Senior Platform Engineer – Secure AI DevSecOps
Senior Platform Engineer – Secure AI DevSecOps

Ford Motor Company • Chennai District

On-site
INR 4,000,000 - 6,000,000