Staff Product Cybersecurity Engineer - Secure Product Engineering

General Motors
Milford Charter Township, MI, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Systems Engineering Code Review Cyber Security Embedded Software Fuzz Testing Mobile Application Software Systems Development Life Cycle Secure Coding Security Support Provider Interface Software Security Backend Operating System Security
+3 more
Static Application Security Testing Programming Languages Dynamic Application Security Testing

Job description

The Staff Product Cybersecurity Engineer, Secure Product Engineering is a senior individual contributor within the Secure Product Engineering pillar of the broader Product Cybersecurity organization at General Motors. Through close, hands-on partnership with product engineering teams, this engineer helps ensure that software and systems are implemented securely as products move through the build phase of development. As a technical leader without direct reports, this role personally builds the tooling, patterns, and secure-engineering capabilities-and provides the technical guidance and workflows-that allow secure software and systems engineering to scale across GM’s product portfolio, spanning embedded vehicle software, mobile experiences, and other key software & services. This is a deep-expertise, execution-focused role. Influence is earned through technical credibility, mentorship, and leading by example rather than through people management.

What You’ll Do

  • Serve as a hands-on technical leader across secure software and systems engineering, driving outcomes through direct execution and influence rather than direct reports
  • Personally design, build, and mature a robust set of secure engineering services and capabilities for GM products
  • Establish close, embedded partnerships with product engineering teams to support and directly contribute to secure implementation
  • Implement and mature SAST, DAST, fuzzing, runtime security, and OS security hardening of core code bases
  • Author technical guidance, reusable patterns, and guardrails, and roll them out across product environments
  • Perform in-depth secure code review and partner with adjacent teams to improve tooling and carry security requirements into engineering
  • Mentor and uplevel engineers across the pillar, setting a high technical bar through example and pairing, This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.

Requirements

  • 8+ years of cybersecurity experience with roles in application security, product security, or similar
  • Demonstrated technical leadership and influence in relevant security or engineering-focused roles-leading initiatives without formal authority, mentoring engineers, and setting technical direction
  • Expertise with application security, secure software engineering, and practical technical guidance
  • Experience with SAST, DAST, fuzzing, code review, and secure SDLC workflows across platforms
  • Able to read and write software in multiple programming languages to personally build tooling and support the team’s execution
  • Works closely with engineering teams to materially improve security without unnecessary friction

What Will Give You A Competitive Edge (Preferred Qualifications)

  • Prior role(s) in the automotive industry or a similarly complex, deadline-driven, and regulated field
  • Published cybersecurity research projects (e.g. conference talks, blog posts, code repositories)
  • Familiarity with embedded software/OS security, mobile applications, and backend development
  • Have previously built custom security tooling and/or extended functionality in related technologies

What You’ll Bring

  • A high-ownership, hands-on style with strong product instincts and a pragmatic security mindset
  • A commitment to internal customer partnership and technically credible security support
  • Deep technical expertise that enables clear guidance, strong mentorship, and opinionated technical planning
  • The ability to manage multiple complex priorities with clear milestones and measurable outcomes
  • A bias toward scalable improvement that strengthens Secure Product Engineering over time

About the company

We believe we all must make a choice every day - individually and collectively - to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team., General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on generalmotors.wd5.myworkdayjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · WWC Europe 2026

3:40 min

Integrating mutation testing and fuzzing into software workflows

Michael Contento · WWC 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:12 min

Choosing TypeScript for complex backend applications

Maximilian Otto Maximilian Otto · WWC 2024

11:26 min

Identifying system risks and collaborative ecosystem legal challenges

Hans-Jürgen Eidler · LIVE

Videos

See all

Related articles

See all