Staff Cybersecurity Software Engineer

General Motors
Warren, MI, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services User Authentication Microsoft Azure C++ (Programming Language) Cloud Engineering Cyber Security Continuous Integration Data Validation Cursor (Graphical User Interface Elements) Software Design Patterns
+13 more
Python (Programming Language) Key Management Systems Development Life Cycle Secure Coding Security Software Software Engineering Data Logging GitHub Copilot Delivery Pipeline Information Technology Build Tools Docker Golang

Job description

Experteer Overview In this role, you will design and deliver security-focused software and services that enable secure-by-default experiences across GM’s application landscape. You’ll work hands-on with cross-functional teams to embed security into the software development lifecycle, shaping platforms and tooling that automate secure patterns. You’ll address threats, design resilient security services, and provide mentorship on secure architecture. This position offers impact through evolving security capabilities that support developers and end users at scale, aligned with GM’s technology and product goals. Compensation / Benefits * Design, build, and maintain security-focused software components, services, and tools across GM’s application ecosystem * Develop automation frameworks and internal platforms to promote secure patterns (identity, authorization, secrets management, logging) * Integrate security controls into CI/CD pipelines, build systems, and cloud-native deployment workflows * Architect and implement resilient, scalable security services and APIs (authentication, authorization, policy evaluation, event ingestion) * Collaborate with application, infrastructure, and platform engineering teams to embed security requirements into designs * Perform secure code reviews, threat modeling, and design reviews to remediate vulnerabilities early in the SDLC * Build and maintain systems for security telemetry: logging, metrics, and alerting for detection, triage, and incident response * Contribute to incident response and post-incident reviews as an engineering owner for security services and tooling * Stay current with emerging security threats and translate them into engineering requirements, patterns, and roadmaps * Provide technical mentorship on secure coding, design patterns, and security architecture Tasks * Bachelor’s degree or higher in Computer Science, Software Engineering, Cybersecurity, or related field (or equivalent practical experience) * 7+ years of software engineering experience building and owning production systems or in-house applications * Advanced proficiency in at least one modern language (Python, Go, Java, or C++) with solid fundamentals * Experience using AI-assisted development tools (GitHub Copilot, Cursor) * Experience designing, implementing, and operating services on major cloud platforms (AWS, Azure, or GCP) with IaC * Hands-on experience with Docker and Kubernetes * Strong understanding of core security concepts (authentication and authorization patterns, encryption, secure coding, input validation, common vulnerabilities) * Experience partnering with security/audit teams and translating requirements into engineering work * Proven ability to plan and manage work in an Agile environment * Strong written and verbal communication skills to explain security concepts to diverse audiences Key requirements * medical, dental, vision * Health Savings Account * Flexible Spending Accounts * retirement savings plan * life insurance * paid vacation and holidays

Requirements

_ * Architect and implement resilient, scalable security services and APIs (authentication, authorization, policy evaluation, event ingestion) * Collaborate with application, infrastructure, and platform engineering teams to embed security requirements into designs * Perform secure code reviews, threat modeling, and design reviews to remediate vulnerabilities early in the SDLC * Build and maintain systems for security telemetry: logging, metrics, and alerting for detection, triage, and incident response * Contribute to incident response and post-incident reviews as an engineering owner for security services and tooling * Stay current with emerging security threats and translate them into engineering requirements, patterns, and roadmaps * Provide technical mentorship on secure coding, design patterns, and security architecture Tasks * Bachelor’s degree or higher in Computer Science, Software Engineering, Cybersecurity, or related field (or equivalent practical experience) * 7+ years of aaaaa aX_ engineering experience building and owning production systems or in-house applications * Advanced proficiency in at least one modern language (Python, Go, Java, or C++) with solid fundamentals * Experience using AI-assisted development tools (GitHub Copilot, Cursor) * Experience designing, implementing, and operating services on major cloud platforms (AWS, Azure, or GCP) with IaC * Hands-on experience with Docker and Kubernetes * Strong understanding of core security concepts (authentication and authorization patterns, encryption, secure coding, input validation, common vulnerabilities) * Experience partnering with security/audit teams and translating requirements into engineering work * Proven ability to plan and manage work in an Agile environment * Strong written and verbal communication skills to explain security concepts to diverse audiences Key requirements * medical, dental, vision * Health Savings Account * Flexible Spending Accounts * retirement savings plan * life aaaaaaaz _ * paid vacation and holidays

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

48 sec

Exploring alternative build tools and experimental web components

Sasha Shynkevich · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · WWC Europe 2026

Videos

See all

Related articles

See all