Security Engineer
Overview
Who we are
Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow. with us.
An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota's vision to move people beyond what's possible. At TFS, you will help create best-in-class customer experience in an innovative, collaborative environment.
Toyota does not offer support or sponsorship of job applicants for employment-based visas or any other work authorization for this role now or in the future. You must have the right to work in the United States and not require Toyota support or sponsorship for immigration-related employment (e.g., H-1B, O-1, E-3, H-1B1, TN, F-1 OPT, F-1 STEM OPT, F-1 CPT, ‘job flexibility benefits’ [also known as I-140 or Adjustment of Status portability], etc.) now or in the future. You should not apply for this role if you will require Toyota to assist with immigration support or sponsorship now or in the future.
Who we’re looking for
Toyota Financial Services (TFS) Technology team is looking for a motivated and detail-oriented person to fill a role as a Security Engineer. In this role, you will support the engineering, maintenance, and improvement of the organization's vulnerability management and threat intelligence automation platforms. Working under the Information Security team, you will assist with Key Risk Indicator (KRI) reporting pipelines, CrowdStrike API/NG-SIEM integrations, Google Threat Intelligence (GTI) data pipelines, Qualys vulnerability data tuning, and CI/CD test automation that supports the Security Operations Center (SOC) and broader cyber defense teams.
We're looking for someone who is eager to learn, enjoys solving technical problems, and is interested in building a strong foundation in security engineering within a collaborative environment.
What you’ll be doing
KRI & Vulnerability Trend Reporting: Build and maintain automated pipelines that calculate Key Risk Indicator (KRI) scores, track newly introduced and remediate vulnerabilities and maintain historical snapshot/environment-change tables that feed executive dashboards.
Threat Intelligence Pipeline Development: Design, build, and maintain end-to-end data pipelines that pull Indicators of Compromise (IOCs), campaigns, threat reports, CVEs, and TTPs (Tactics, Techniques, and Procedures) from Google Threat Intelligence (GTI), including associating related threat objects (e.g., linking IOCs to campaigns and reports).
CrowdStrike Integration: Develop and maintain CrowdStrike API integrations, including API manager classes, Identity Protection scripts (e.g., account disablement tracking), and NG-SIEM worker/scheduler processes that support automated bulk searches of security event data.
Qualys Vulnerability Management: Assist with tuning Qualys API-based data pulls (e.g., posture/policy compliance filtering, host list detection) to improve data accuracy and reduce noise in vulnerability reporting.
Database Engineering: Design and maintain database models to store vulnerability and threat intelligence data (IOCs, campaigns, reports, TTPs, KRI history, and their associations), ensuring data is structured for efficient querying and reporting.
Concurrency & Performance Optimization: Build multi-threaded/concurrent data processing solutions to improve the speed and reliability of large-scale API data pulls and database writes, including batch-commit strategies for efficient performance.
CI/CD & Test Automation: Build and maintain GitHub Actions workflows for automated testing, code coverage reporting, and pre-commit hooks (linting, formatting) to improve code quality and reduce regressions across the security engineering codebase.
Scripting & Automation Development: Use Python to build automation scripts, API integrations, and export utilities that support threat intelligence operationalization and vulnerability tracking, reducing manual analyst workload.
Process Development & Documentation: Assist in creating and maintaining SOPs, runbooks, and documentation for platform support, pipeline configuration, data models, and troubleshooting workflows.
What you bring
0–3 years of experience in cyber security, information security, data engineering, or a related technical field.
Exposure to vulnerability management platforms (e.g., Qualys), threat intelligence sources (e.g., Google Threat Intelligence), and SIEM tools (e.g., CrowdStrike NG-SIEM).
Experience with Python, including scripting, concurrent/multi-threaded programming, and ORM frameworks such as SQL Alchemy.
Familiarity with relational databases (e.g., PostgreSQL) and designing/maintaining structured data pipelines.
Basic understanding of threat intelligence concepts such as Indicators of Compromise (IOCs), TTPs, and threat campaigns/actors.
Exposure to CI/CD tools such as GitHub Actions, Pytest, and code quality tooling (pre-commit, Pylint).
Strong problem-solving skills, willingness to learn, and ability to work collaboratively in a team environment.
What we’ll bring
During your interview process, our team can fill you in on all the details of our industry-leading benefits and career
development opportunities. A few highlights include:
• A work environment built on teamwork, flexibility, and respect
• Professional growth and development programs to help advance your career, as well as tuition reimbursement
• Team Member Vehicle Purchase Discount
• Toyota Team Member Lease Vehicle Program (if applicable)
• Comprehensive health care and wellness plans for your entire family
• Toyota 401(k) Savings Plan featuring a company match, as well as an annual retirement contribution from Toyota
regardless of whether you contribute (if applicable)
• Paid holidays and paid time off
• Referral services related to prenatal services, adoption, childcare, schools and more
• Tax Advantaged Accounts (Health Savings Account, Health Care FSA, Dependent Care FSA)
• Relocation assistance (if applicable)
Belonging at Toyota
Our success begins and ends with our people. We embrace all perspectives and value unique human experiences. Respect for all is our North Star.
Applicants for our positions are considered without regard to race, ethnicity, national origin, sex, sexual orientation, gender identity or expression, age, disability, religion, military or veteran status, or any other characteristics protected by law.
Have a question, need assistance with your application or do you require any special accommodations? Please send an email to talent.acquisition@toyota.com.