Summary
Toyota Boshoku America is seeking a Cybersecurity Engineer to support and enhance its cybersecurity program across North and South American operations. The role implements and maintains security controls, monitors and investigates cybersecurity events, supports vulnerability management and incident response, and strengthens identity, endpoint, cloud, data protection, and manufacturing security. The engineer also collaborates with internal teams and third-party providers to reduce security risks and improve operational resilience.
Responsibilities
- Implement, administer, and maintain cybersecurity controls across cloud, hybrid, on-premises, and manufacturing environments
- Support the deployment and configuration of security technologies related to identity, endpoint, network, cloud, and data protection
- Assist with maintaining security baselines, standards, and technical documentation
- Participate in security reviews of new technologies, applications, and infrastructure deployments to help identify and mitigate security risks
- Assist with vulnerability management activities, including reviewing scan results, validating remediation efforts, and tracking corrective actions
- Support cybersecurity projects and initiatives designed to improve TBA's overall security posture
- Monitor, investigate, and respond to cybersecurity alerts, incidents, and suspicious activity
- Assist with the investigation and remediation of malware, phishing, unauthorized access attempts, ransomware, and other cybersecurity threats
- Analyze security logs, endpoint telemetry, network activity, and threat intelligence to identify potential security risks and indicators of compromise
- Work with internal teams, third-party vendors, and security service providers to support incident response and remediation efforts
- Assist in maintaining and testing incident response procedures, playbooks, and recovery processes
- Support security monitoring platforms, alert tuning activities, and continuous improvement of detection capabilities
- Participate in after-hours support and escalation activities during significant cybersecurity incidents when required
- Administer and support identity security technologies including Microsoft Entra ID, Multi-Factor Authentication (MFA), Conditional Access, access reviews, and Privileged Identity Management (PIM)
- Support data protection initiatives including:
- Data Classification
- Sensitivity Labeling
- Data Loss Prevention (DLP)
- Insider Risk Management
- Information Protection Controls
- Assist with securing Microsoft Azure, Microsoft 365, and other cloud-based services utilized by the organization
- Support implementation and monitoring of security controls for approved AI technologies and emerging business applications
- Collaborate with Plant IT teams to support cybersecurity controls within manufacturing and operational technology (OT) environments
- Assist with implementing and maintaining network segmentation, secure remote access, and monitoring controls for manufacturing systems
- Participate in assessments of cybersecurity risks associated with plant operations, industrial systems, and connected manufacturing technologies
- Support cybersecurity initiatives that balance security requirements with manufacturing uptime, safety, and operational reliability
- Assist with implementing cybersecurity controls aligned with industry frameworks and organizational standards
- Support cybersecurity policies, standards, procedures, and compliance initiatives
- Maintain accurate cybersecurity documentation including:
- Security Configurations
- System Documentation
- Network Diagrams
- Incident Records
- Operational Procedures
- Security Baselines
- Track vulnerability remediation activities and assist with risk reduction efforts
- Support software security reviews, vendor assessments, and third-party risk management activities
- Assist with internal audits, compliance reviews, and cybersecurity assessments
- Work collaboratively with infrastructure, networking, application, operations, and manufacturing teams to support cybersecurity objectives
- Communicate cybersecurity risks, issues, and recommendations effectively to technical and non-technical stakeholders
- Maintain awareness of emerging cybersecurity threats, vulnerabilities, and industry best practices
- Participate in ongoing training and professional development to enhance cybersecurity knowledge and technical skills
- Support continuous improvement efforts that strengthen TBA's cybersecurity capabilities and operational resilience
Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related technical field, or an equivalent combination of education and relevant experience
- Minimum of 4–6 years of experience in cybersecurity, information security, systems administration, infrastructure support, or security engineering roles
- Experience supporting enterprise IT environments, preferably within manufacturing, automotive, or other industrial organizations
- Experience working with one or more cybersecurity technologies in the following areas:
+ Microsoft Defender
+ Microsoft Entra ID (Azure AD)
+ Microsoft Intune
+ Microsoft Sentinel or similar SIEM platform
+ Endpoint Detection and Response (EDR/XDR) solutions
+ Vulnerability Management tools
- Working knowledge of:
+ Networking fundamentals
+ TCP/IP
+ DNS
+ Firewalls
+ VPN technologies
+ Active Directory
+ Identity and Access Management (IAM)
+ Endpoint Security
+ Cloud Security Concepts
- Experience supporting security monitoring, vulnerability management, incident response, or security operations activities
- Ability to review and analyze security alerts, logs, and system events to assist with investigations and remediation efforts
- Familiarity with cybersecurity frameworks and best practices such as:
+ NIST Cybersecurity Framework (CSF)
+ CIS Controls
+ ISO 27001
- Strong analytical, troubleshooting, and problem-solving skills
- Ability to manage multiple tasks and priorities while working independently and collaboratively within a team environment
- Strong verbal and written communication skills with the ability to effectively interact with technical and non-technical stakeholders
- Strong analytical and problem-solving skills with the ability to identify and resolve technical security issues
- Ability to investigate security alerts, system events, and operational issues and assist with determining appropriate remediation actions
- Strong troubleshooting skills across security, infrastructure, endpoint, network, and cloud technologies
- Ability to prioritize tasks and manage multiple responsibilities in a fast-paced environment
- Effective verbal and written communication skills with technical and non-technical stakeholders
- Ability to work both independently and collaboratively within cross-functional teams
- Strong attention to detail and commitment to maintaining accurate documentation and operational procedures
- Understanding of cybersecurity principles, risk management concepts, and security best practices
- Ability to adapt to changing technologies, business requirements, and evolving cybersecurity threats
- Strong organizational and time management skills
- Commitment to continuous learning and professional development within the cybersecurity field
- Basic knowledge of computer programming or coding concepts, including the ability to understand scripts, automation logic, or code used to support cybersecurity analysis and operations
- High degree of integrity, professionalism, accountability, and customer service orientation
- Strong written and verbal communication skills
- Must be willing to travel up to 10% of the time between the U.S., Canada, Mexico, and South America
- The team member must be capable of walking, sitting, and standing for extended periods of time
- May be occasionally required to lift up to 30 pounds
- Ability to sit and work on a computer for extensive periods of time is required
- The ability to travel by automobile and airplane are both required
- Experience supporting Microsoft 365, Azure, or hybrid cloud environments preferred
- Experience supporting manufacturing, automotive, or industrial environments
- Exposure to Operational Technology (OT), manufacturing systems, or industrial control system (ICS) environments
- Experience with one or more of the following technologies:
+ Microsoft Defender
+ Microsoft Intune
+ Microsoft Sentinel
+ Microsoft Entra ID
+ Varonis
+ SolarWinds
+ Cisco security technologies
+ SCCM / Microsoft Configuration Manager
+ Commvault
- Familiarity with cybersecurity concepts such as:
+ Threat Intelligence
+ Security Monitoring
+ Vulnerability Management
+ Incident Response
+ Security Automation
+ Data Protection Technologies
- Experience participating in cybersecurity assessments, audits, or compliance activities
- Experience supporting cloud security initiatives within Microsoft Azure or Microsoft 365 environments
- Experience working with third-party vendors, managed security service providers, or cybersecurity consulting partners
- Understanding of cybersecurity frameworks such as NIST CSF, CIS Controls, or ISO 27001
- Relevant industry certifications are preferred, including:
+ CompTIA Security+
+ CompTIA CySA+
+ Microsoft SC-200
+ Microsoft SC-300
+ Microsoft AZ-500
+ Microsoft Security, Identity, or Compliance Certifications
- Bilingual or multilingual communication skills are a plus
- CISSP (preferred but not required)
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related technical field, or an equivalent combination of education and relevant experience
- Minimum of 4–6 years of experience in cybersecurity, information security, systems administration, infrastructure support, or security engineering roles
- Experience supporting enterprise IT environments, preferably within manufacturing, automotive, or other industrial organizations
- Experience working with one or more cybersecurity technologies in the following areas:
+ Microsoft Defender
+ Microsoft Entra ID (Azure AD)
+ Microsoft Intune
+ Microsoft Sentinel or similar SIEM platform
+ Endpoint Detection and Response (EDR/XDR) solutions
+ Vulnerability Management tools
- Working knowledge of:
+ Networking fundamentals
+ TCP/IP
+ DNS
+ Firewalls
+ VPN technologies
+ Active Directory
+ Identity and Access Management (IAM)
+ Endpoint Security
+ Cloud Security Concepts
- Experience supporting security monitoring, vulnerability management, incident response, or security operations activities
- Ability to review and analyze security alerts, logs, and system events to assist with investigations and remediation efforts
- Familiarity with cybersecurity frameworks and best practices such as:
+ NIST Cybersecurity Framework (CSF)
+ CIS Controls
+ ISO 27001
- Strong analytical, troubleshooting, and problem-solving skills
- Ability to manage multiple tasks and priorities while working independently and collaboratively within a team environment
- Strong verbal and written communication skills with the ability to effectively interact with technical and non-technical stakeholders
- Strong analytical and problem-solving skills with the ability to identify and resolve technical security issues
- Ability to investigate security alerts, system events, and operational issues and assist with determining appropriate remediation actions
- Strong troubleshooting skills across security, infrastructure, endpoint, network, and cloud technologies
- Ability to prioritize tasks and manage multiple responsibilities in a fast-paced environment
- Effective verbal and written communication skills with technical and non-technical stakeholders
- Ability to work both independently and collaboratively within cross-functional teams
- Strong attention to detail and commitment to maintaining accurate documentation and operational procedures
- Understanding of cybersecurity principles, risk management concepts, and security best practices
- Ability to adapt to changing technologies, business requirements, and evolving cybersecurity threats
- Strong organizational and time management skills
- Commitment to continuous learning and professional development within the cybersecurity field
- Basic knowledge of computer programming or coding concepts, including the ability to understand scripts, automation logic, or code used to support cybersecurity analysis and operations
- High degree of integrity, professionalism, accountability, and customer service orientation
- Strong written and verbal communication skills
- Must be willing to travel up to 10% of the time between the U.S., Canada, Mexico, and South America
- The team member must be capable of walking, sitting, and standing for extended periods of time
- May be occasionally required to lift up to 30 pounds
- Ability to sit and work on a computer for extensive periods of time is required
- The ability to travel by automobile and airplane are both required
Nice to Haves
- Experience supporting Microsoft 365, Azure, or hybrid cloud environments preferred
- Experience supporting manufacturing, automotive, or industrial environments
- Exposure to Operational Technology (OT), manufacturing systems, or industrial control system (ICS) environments
- Experience with one or more of the following technologies:
+ Microsoft Defender
+ Microsoft Intune
+ Microsoft Sentinel
+ Microsoft Entra ID
+ Varonis
+ SolarWinds
+ Cisco security technologies
+ SCCM / Microsoft Configuration Manager
+ Commvault
- Familiarity with cybersecurity concepts such as:
+ Threat Intelligence
+ Security Monitoring
+ Vulnerability Management
+ Incident Response
+ Security Automation
+ Data Protection Technologies
- Experience participating in cybersecurity assessments, audits, or compliance activities
- Experience supporting cloud security initiatives within Microsoft Azure or Microsoft 365 environments
- Experience working with third-party vendors, managed security service providers, or cybersecurity consulting partners
- Understanding of cybersecurity frameworks such as NIST CSF, CIS Controls, or ISO 27001
- Relevant industry certifications are preferred, including:
+ CompTIA Security+
+ CompTIA CySA+
+ Microsoft SC-200
+ Microsoft SC-300
+ Microsoft AZ-500
+ Microsoft Security, Identity, or Compliance Certifications
- Bilingual or multilingual communication skills are a plus
- CISSP (preferred but not required)
Benefits
- Participate in ongoing training and professional development to enhance cybersecurity knowledge and technical skills.