Cybersecurity Key Provisioning Process Engineer
Job#: 3045779
About the role
We are seeking a Cybersecurity Key Provisioning Process Engineer to join our Vehicle Cybersecurity organization. This role sits at the intersection of automotive engineering, cryptographic security architecture, and manufacturing operations — owning the end-to-end process by which cryptographic key material is defined, provisioned, and secured across every Electronic Control Unit (ECU) and vehicle program. The ideal candidate is a systems thinker who can translate cryptographic and security requirements into concrete engineering specifications, drive supplier accountability through audit and integration, and operate our backend Public Key Infrastructure (PKI) and Key Management System (KMS) to deliver secure keys at scale. This is a highly cross-functional role requiring fluency in cybersecurity engineering, supplier quality/manufacturing processes, and product key management systems.
This role involves the development and governance of security policies and procedures, review of security controls and their efficiency, and monitoring processes for compliance risk and vulnerabilities. They also specialize in managing third party security risk programs.
Responsibilities
- Own and facilitate the process for defining, documenting, and approving cryptographic key requirements (algorithms, key lengths, key hierarchies, usage policies, rotation/expiry rules) for each ECU type and vehicle program.
- Serve as the central point of coordination between vehicle program teams, ECU feature owners, and cybersecurity architecture to ensure requirements are complete, consistent, and traceable across program timelines.
- Conduct technical audits of Tier-1 supplier manufacturing sites and processes to validate conformance to our cybersecurity requirements. Assess supplier readiness against cryptographic and secure manufacturing requirements; identify gaps and drive corrective action plans.
- Establish and monitor supplier compliance metrics, escalating non-conformances through appropriate governance channels.
- Partner with cybersecurity architects, ECU/software engineering teams, vehicle program management, procurement, and manufacturing to define cryptographic key requirements tailored to each ECU's function, threat model, and program constraints.
- Orchestrate the technical implementation of approved key requirements within Ford's backend PKI and KMS infrastructure, coordinating with platform/IT teams responsible for these systems. Define and manage key lifecycle workflows within the KMS in alignment with program and supplier timelines.
- Troubleshoot and resolve issues in the key delivery pipeline between backend systems and supplier manufacturing lines.
- Author clear, precise technical documentation, specifications, and work instructions covering cryptographic key requirements, provisioning processes, and PKI/KMS interfaces. Cascade approved requirements to relevant internal teams and external suppliers, ensuring proper acknowledgment and implementation.
- Enforce compliance with documented requirements through audits, design reviews, and program gate reviews; maintain version control and change management for all specifications.
Requirements
- Familiarity with automotive cybersecurity standards (ISO/SAE 21434, UNECE R155/R156).
- Hands-on experience with commercial or in-house PKI/KMS platforms (e.g., Thales, Entrust, HashiCorp Vault, AWS KMS, or automotive-specific secure provisioning platforms).
- Experience with ECU/embedded systems development lifecycle and vehicle program timing.
- Knowledge of secure manufacturing/provisioning protocols (e.g., SHE, HSM-based key injection, secure flashing).
- Project or process management experience (e.g., Agile, Six Sigma, or similar).
- Experience with relevant control frameworks (e.g., NIST 800-53/800-57, ISO 27001, PCI-HSM, or automotive-specific key management security standards) is a plus.
Qualifications
- Bachelor's Degree
Skills
- Embedded Systems
- Auditing
- Cyber Security
- Compliance
Preferred Skills:
- ISO 27001
- Supply Chain Operations
Schedule
Hybrid Position - 4 days a week onsite
Benefits
- Medical, dental, vision, life, and disability insurance plans
- Employee Stock Purchase Program (ESPP)
- 401K program with company match after 12 months of tenure
- Health Savings Account (HSA) on the HDHP plan
- SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions
- Corporate discount savings program and other discounts
- On-demand training program
- Access to certification prep and a library of technical and leadership courses/books/seminars after 6+ months of tenure
- Certification discounts and perks to associations that include CompTIA and IIBA
- Dedicated customer service team for consultants
- Access to a certified Career Coach