> Markdown version of [/jobs/ext/1410514-manager-offensive-product-cybersecurity-psoc](https://www.wearedevelopers.com/jobs/ext/1410514-manager-offensive-product-cybersecurity-psoc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Offensive Product Cybersecurity & PSOC - **Company:** General Motors - **Location:** Milford Charter Township, MI, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Red Team (Cyber Security), Software Security - **Published:** July 23, 2026 - **Apply:** https://jobs.mitalent.org/job-seeker/job-details/JobCode/396785933 ## About the Role * 8+ years of security experience in product security teams or similar security functions. * 4+ years of leadership experience in penetration testing, security research, product security, or closely related roles. * Expertise in embedded security, including operating system, application, and hardware contexts. * Experience defining a team calendar of work that incorporates stakeholder and business-wide priorities. * Ability to read and write software in multiple languages to support investigation and remediation efforts. * Proven leadership of incident response activities involving time-sensitive and confidential workflows. What Will Give You a Competitive Edge (Preferred Qualifications) * Prior experience in the automotive industry or a similarly complex, deadline-driven, and regulated environment. * Published cybersecurity research (e.g., conference talks, blog posts, or public code repositories). * Experience architecting security operations platforms and leading security analysts in triaging risk-based findings. * Experience building custom security tooling and/or extending functionality in related technologies. * A detailed, high-ownership leadership style that connects vision to clearly articulated strategy. * Ability to manage multiple complex projects simultaneously with defined milestones and success criteria. * Strong commitment to internal customer relationships that drive high-quality security outcomes. * Deep technical expertise that supports confident, opinionated work planning and team mentorship. * Ability to communicate technical content effectively to various levels of leadership and external audiences, including media. Company Vehicle: Upon successful completion of a motor vehicle report review, you will be eligible to participate in a company vehicle evaluation program, through which you will be assigned a General Motors vehicle to drive and evaluate. Note: program participants are required to purchase/lease a qualifying GM vehicle every four years unless one of a limited number of exceptions applies. GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc). This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}. ## Description The Manager, Offensive Product Cybersecurity & PSOC leads two key areas within GM's Product Cybersecurity organization: offensive product security services and the Product Security Operations Center (PSOC). This leader oversees penetration testing, red team operations, and security research to strengthen confidence in the security of GM's products, while also owning product security operations, including security-readiness visibility, detection and response, bug bounty management, and product security incident response (PSIRT). What You'll Do * Lead a team of 10+ product cybersecurity engineers across offensive security and security operations. * Define a comprehensive set of offensive security services and capabilities to ensure a secure product portfolio. * Establish and manage a product security assessment schedule in partnership with product management teams. * Develop and formalize a security research plan focused on forward-looking technology investments. * Own product cybersecurity operations strategy and data sources to enable effective detection and response. * Coordinate with third-party security researchers through the bug bounty program and lead PSIRT activities. ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Introduction to Responsible AI: Balancing Value and Risk](https://www.wearedevelopers.com/videos/1972-introduction-to-responsible-ai-balancing-value-and-risk) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Prompt Engineer ✍️](https://www.wearedevelopers.com/magazine/216-the-prompt-engineer) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)