A complete application in a minute — tailored resume and cover letter, ready to send.
General Motors seeks a Senior Cybersecurity Vulnerability Engineer to design, implement, and improve capabilities protecting people, products, partners, platforms, and production.
The role requires translating threat intelligence into actionable remediation, guiding priority decisions, and influencing across infrastructure, cloud, application, and manufacturing stakeholders. Mentors engineers and leads remediation efforts with a risk-based approach.
Job Description
As a Senior Cybersecurity Vulnerability Engineer, you will serve as a highly capable individual contributor responsible for designing, implementing, and improving cybersecurity capabilities that protect GM's risk domains of people, products, partners, platforms, and production.
The successful candidate is a senior experienced professional who can independently assess complex vulnerability and exposure risks, translate threat intelligence and technical findings into actionable remediation priorities, and influence outcomes across infrastructure, cloud, application, manufacturing, and security stakeholder groups. The senior engineer will have significant functional impact through risk-based decision-making, operational leadership, and mentorship of engineers and remediation partners.
You will solve diverse, non-standard security problems; translate broad challenges into implementable initiatives; and drive delivery across teams through technical leadership, sound judgment, and influence. This role has significant operational impact across the cybersecurity organization that serves as a mentor and resource for other team members.
Lead engineering, operational improvement, and continuous maturity of GM Vulnerability Management core services across enterprise infrastructure, client endpoints, multi-cloud, and AI security threat exposure domains.
Serve as a senior individual contributor for Enterprise Data Center Infrastructure vulnerability management, including server, endpoint, network, virtualization, patch coordination, exception handling, on-prem asset hygiene, and remediation prioritization for critical infrastructure.
Drive client endpoint vulnerability management by reducing endpoint risk through continuous detection, patching, browser and software update compliance, control enforcement, and remediation guidance across corporate and manufacturing endpoint environments.
Lead multi-cloud vulnerability management across Azure, AWS, and GCP, including workload exposure, misconfiguration correlation, cloud VM risk, container image and runtime exposure, and cloud-to-business criticality mapping to support risk-based remediation.
Build and mature AI security threat vulnerability management capabilities for AI workloads, model supply chain risk, prompt injection, data leakage, agent permissions, tool-use guardrails, model and runtime control validation, and secure rollout patterns for internal AI capabilities.
Correlate scanner findings with asset, business, network, telemetry, identity, threat-intelligence, and SBOM context to improve prioritization accuracy and focus remediation on exposures most likely to create business risk.
Apply threat intelligence and exploitability analytics, including exposure context, attack-path factors, and evidence of exploitation, to move prioritization beyond severity-only scoring.
Partner with infrastructure, endpoint, cloud platform, manufacturing, application, and Security Fitness stakeholders to convert findings into actionable remediation plans, drive accountability, and accelerate closure of urgent, critical, and high-risk issues.
Support and improve Vulnerability core functions including asset discovery and inventory, vulnerability scanning and assessment, threat intelligence and risk context, prioritization and risk scoring, remediation and patch coordination, exception management, reporting, dashboards, governance, integration, automation, and continuous improvement.
Contribute to workflow integration and automation across detection, security unification tools, automated patching orchestration, and related platforms, while maintaining appropriate guardrails and human approval for meaningful changes to critical environments.
Provide technical leadership, mentoring, and consultative support to less experienced engineers and aligned remediation owners.
Protect sensitive company, employee, and customer information and consistently operate in alignment with GM values, behaviors, and policies.
Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Technology, or a related field, or equivalent practical experience.
Significant professional experience in cybersecurity engineering, vulnerability management, security operations, cloud security, infrastructure security, or related domains.
Proven expertise in Enterprise Data Center Infrastructure vulnerability management, including servers, network-attached infrastructure, virtualization, patch coordination, exception handling, and remediation prioritization for enterprise environments.
Proven expertise in client endpoint vulnerability management, including endpoint controls, patching, software and browser update compliance, detection coverage, and remediation at scale.
Proven expertise in multi-cloud vulnerability management across Azure, AWS, and GCP, including cloud workload exposure, misconfigur