Manager, Offensive Product Cybersecurity & PSOC

General Motors
Milford Charter Township, MI, United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Red Team (Cyber Security) Software Security

Job description

The Manager, Offensive Product Cybersecurity & PSOC leads two key areas within GM’s Product Cybersecurity organization: offensive product security services and the Product Security Operations Center (PSOC). This leader oversees penetration testing, red team operations, and security research to strengthen confidence in the security of GM’s products, while also owning product security operations, including security-readiness visibility, detection and response, bug bounty management, and product security incident response (PSIRT).

What You’ll Do

  • Lead a team of 10+ product cybersecurity engineers across offensive security and security operations.
  • Define a comprehensive set of offensive security services and capabilities to ensure a secure product portfolio.
  • Establish and manage a product security assessment schedule in partnership with product management teams.
  • Develop and formalize a security research plan focused on forward-looking technology investments.
  • Own product cybersecurity operations strategy and data sources to enable effective detection and response.
  • Coordinate with third-party security researchers through the bug bounty program and lead PSIRT activities.

Requirements

  • 8+ years of security experience in product security teams or similar security functions.
  • 4+ years of leadership experience in penetration testing, security research, product security, or closely related roles.
  • Expertise in embedded security, including operating system, application, and hardware contexts.
  • Experience defining a team calendar of work that incorporates stakeholder and business-wide priorities.
  • Ability to read and write software in multiple languages to support investigation and remediation efforts.
  • Proven leadership of incident response activities involving time-sensitive and confidential workflows.

What Will Give You a Competitive Edge (Preferred Qualifications)

  • Prior experience in the automotive industry or a similarly complex, deadline-driven, and regulated environment.
  • Published cybersecurity research (e.g., conference talks, blog posts, or public code repositories).
  • Experience architecting security operations platforms and leading security analysts in triaging risk-based findings.
  • Experience building custom security tooling and/or extending functionality in related technologies.
  • A detailed, high-ownership leadership style that connects vision to clearly articulated strategy.
  • Ability to manage multiple complex projects simultaneously with defined milestones and success criteria.
  • Strong commitment to internal customer relationships that drive high-quality security outcomes.
  • Deep technical expertise that supports confident, opinionated work planning and team mentorship.
  • Ability to communicate technical content effectively to various levels of leadership and external audiences, including media.

Company Vehicle: Upon successful completion of a motor vehicle report review, you will be eligible to participate in a company vehicle evaluation program, through which you will be assigned a General Motors vehicle to drive and evaluate. Note: program participants are required to purchase/lease a qualifying GM vehicle every four years unless one of a limited number of exceptions applies.

GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc).

This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.

About the company

We believe we all must make a choice every day - individually and collectively - to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team., General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.mitalent.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all