Manager, Offensive Security

General Motors

Kentucky

Hybrid

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

General Motors is seeking a Manager, Offensive Security to lead a distinct cybersecurity function responsible for validating defenses through real-world attack simulation and controlled testing.

You will translate enterprise priorities into team goals, influence across engineering, product, and cybersecurity leadership, and drive talent decisions, capacity planning, tooling, and delivery on a fast-moving security program.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field, or equivalent practical experience.
  • 10+ years of cybersecurity experience, including 5+ years in offensive security, penetration testing, red teaming, application security testing, or closely related disciplines.
  • 5+ years of people leadership experience, including hiring, performance management, coaching, workforce planning, and team development.
  • 3+ years leading complex, cross-functional security programs with measurable outcomes across multiple product, software, or platform teams.
  • Experience assessing or testing modern attack surfaces such as web applications, APIs, cloud services, identity systems, containers, developer tooling, or software delivery pipelines.
  • Demonstrated ability to define key performance indicators, prioritize competing work, communicate risk to technical and business stakeholders, and drive remediation to closure.

Responsibilities

  • Lead and develop a team responsible for penetration testing, adversary emulation, responsible disclosure triage, and verification of security controls across applications, platforms, and services.
  • Own the function roadmap, operating model, and key performance indicators, including coverage, remediation velocity, validation quality, and risk reduction outcomes.
  • Translate Cybersecurity strategy into quarterly priorities, staffing plans, resource allocation decisions, and clear execution goals for the team.
  • Partner with engineering and platform teams to turn offensive security findings into remediation actions, prevention improvements, and stronger secure-by-design practices.
  • Establish scalable testing approaches for web, API, cloud, identity, container, and software delivery environments, balancing depth, speed, and business risk.
  • Drive stakeholder communication, cross-functional alignment, and change leadership, including escalation of significant risks and recommendations for action.

Skills

Leadership
Penetration testing
Red teaming
Application security testing
Offensive security
Strategic planning

Education

Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field

Job description

Job Description

At General Motors, we are building secure software and connected experiences at scale. The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback loops that help teams reduce risk before it becomes customer impact.

This team helps uncover exploitable weaknesses, verify how well controls are performing, and provide actionable insights that improve remediation and prevention. This role is ideal for a leader who can grow a high-performing team, turn strategy into execution, and raise the security bar across a complex engineering environment.

The Role

As Manager, Offensive Security, you will lead a distinct Cybersecurity function responsible for validating how well our products, platforms, and engineering controls stand up to real-world attacks. You will set direction for offensive security programs, translate enterprise priorities into team goals, and make operational decisions about talent, capacity, tooling, and delivery. You will partner closely with engineering, product, infrastructure, and Cybersecurity leaders to prioritize risk, improve remediation outcomes, and strengthen preventative controls. You will help shape scalable testing approaches that balance speed, depth, and business impact. This is a high-impact leadership role for someone who can build talent, influence across organizations, and lead change through measurable outcomes.

What You’ll Do
  • Lead and develop a team responsible for penetration testing, adversary emulation, responsible disclosure triage, and verification of security controls across applications, platforms, and services.
  • Own the function roadmap, operating model, and key performance indicators, including coverage, remediation velocity, validation quality, and risk reduction outcomes.
  • Translate Cybersecurity strategy into quarterly priorities, staffing plans, resource allocation decisions, and clear execution goals for the team.
  • Partner with engineering and platform teams to turn offensive security findings into remediation actions, prevention improvements, and stronger secure-by-design practices.
  • Establish scalable testing approaches for web, API, cloud, identity, container, and software delivery environments, balancing depth, speed, and business risk.
  • Drive stakeholder communication, cross-functional alignment, and change leadership, including escalation of significant risks and recommendations for action.
Your Skills & Abilities (Required Qualifications)
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
  • 10+ years of cybersecurity experience, including 5+ years in offensive security, penetration testing, red teaming, application security testing, or closely related disciplines.
  • 5+ years of people leadership experience, including hiring, performance management, coaching, workforce planning, and team development.
  • 3+ years leading complex, cross-functional security programs with measurable outcomes across multiple product, software, or platform teams.
  • Experience assessing or testing modern attack surfaces such as web applications, APIs, cloud services, identity systems, containers, developer tooling, or software delivery pipelines.
  • Demonstrated ability to define key performance indicators, prioritize competing work, communicate risk to technical and business stakeholders, and drive remediation to closure.
What Will Give You A Competitive Edge (Preferred Qualifications)
  • Experience building or leading offensive security programs in large-scale software, cloud, or product engineering environments.
  • Familiarity with responsible disclosure, vulnerability intake, or bug bounty program operations.
  • Experience partnering with development teams to improve secure design, detection, and resilience based on offensive testing results.
  • Knowledge of security automation, findings workflows, and telemetry-driven reporting.
  • Relevant industry certifications such as OSCP, OSWE, GPEN, GXPN, CISSP, or comparable credentials.
  • Experience in highly regulated, safety-critical, or large enterprise environments.
    GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc).This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.This job may be eligible for relocation benefits.
About GM

Our vision is a world with Zero Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more equitable for all.

Why Join Us

We believe we all must make a choice every day – individually and collectively – to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team.

Benefits Overview

From day one, we’re looking out for your well-being–at work and at home–so you can focus on realizing your ambitions. Learn how GM supports a rewarding career that rewards you personally by visiting Total Rewards resources.

Non-Discrimination and Equal Employment Opportunities (U.S.)

General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.

All employment decisions are made on a non-discriminatory basis without regard to sex, race, color, national origin, citizenship status, religion, age, disability, pregnancy or maternity status, sexual orientation, gender identity, status as a veteran or protected veteran, or any other similarly protected status in accordance with federal, state and local laws.

Applicants in the recruitment process may be required, where applicable, to successfully complete a role-related assessment(s) and/or a pre-employment screening prior to beginning employment. To learn more, visit How we Hire.

Accommodations

General Motors offers opportunities to all job seekers including individuals with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, email us or call us at 1-800-865-7580. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Product Cybersecurity Engineer - Offensive Product Security
Staff Product Cybersecurity Engineer - Offensive Product Security

General Motors • Warren (MI)

Hybrid
USD 140,000 - 180,000
Senior Cybersecurity Engineer - Security Operations
Senior Cybersecurity Engineer - Security Operations

General Motors • Austin (TX)

Hybrid
USD 120,000 - 150,000
Relocation benefits
Comprehensive health benefits
Employee discounts
Senior Cybersecurity Platform Engineer — AI-Driven SecOps
Senior Cybersecurity Platform Engineer — AI-Driven SecOps

Dormont Manufacturing Co • Kentucky

Hybrid
USD 120,000 - 160,000
Staff Product Cybersecurity Engineer - Secure Product Engineering
Staff Product Cybersecurity Engineer - Secure Product Engineering

General Motors • Warren (MI)

Hybrid
USD 140,000 - 200,000
Senior Cybersecurity Incident Analyst
Senior Cybersecurity Incident Analyst

General Motors • Warren (MI)

Hybrid
USD 120,000 - 180,000
Cyber Detection Event Analyst
Cyber Detection Event Analyst

General Motors • Warren (MI)

Hybrid
USD 95,000 - 130,000
Senior Cybersecurity Engineer - Security Operations
Senior Cybersecurity Engineer - Security Operations

General Motors • Kentucky

Hybrid
USD 120,000 - 160,000
Senior Cybersecurity Incident Analyst
Senior Cybersecurity Incident Analyst

General Motors • United States

Hybrid
USD 150,000 - 190,000
Senior Cybersecurity Engineer – Adversary Operations, Innovation & Purple Team Operations
Senior Cybersecurity Engineer – Adversary Operations, Innovation & Purple Team Operations

General Motors • Austin Center (MI)

On-site
USD 140,000 - 190,000
Manager, Software Supply Chain Security
Manager, Software Supply Chain Security

General Motors • Warren (MI)

On-site
USD 170,000 - 250,000
Relocation benefits