> Markdown version of [/jobs/ext/1992470-staff-product-cybersecurity-engineer-offensive-product-security](https://www.wearedevelopers.com/jobs/ext/1992470-staff-product-cybersecurity-engineer-offensive-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Product Cybersecurity Engineer - Offensive Product Security - **Company:** General Motors - **Location:** Milford Charter Township, MI, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Software Security, Backend, Operating System Security, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://generalmotors.wd5.myworkdayjobs.com/Careers_GM/job/Milford-Michigan-United-States-of-America/Staff-Product-Cybersecurity-Engineer---Offensive-Product-Security_JR-202616758 ## About the Role * 8+ years of experience in penetration testing, product security, security research, or similar roles * Deep expertise in offensive security testing across applications, software, and systems * Experience with penetration testing, red-team activity, vulnerability research, and exploit validation * Familiarity with embedded security, operating system security, application security, and networking * Able to read-and-write software in a variety of languages to support investigation and tooling * Strong ability to communicate technical findings and work directly with engineers on remediation What Will Give You A Competitive Edge (Preferred Qualifications) * Prior role(s) in the automotive industry or a similarly complex, deadline driven, and regulated field * Direct experience working on automotive security in any relevant role across the secure SDLC * Published cybersecurity research projects (e.g. conference talks, blog posts, code repositories) * Experience building custom offensive tooling or extending existing security testing capabilities What You'll Bring * Deep technical curiosity and strong offensive security instincts across complex product focuses * A rigorous and detail-oriented approach to technical investigation and exploit validation * Clear judgment on risk, exploitability, and practical impact across software and systems * The ability to work independently on complex technical problems and ambiguous attack surfaces * A commitment to helping engineers improve security through detailed, risk-ranked findings ## Description The Staff Product Cybersecurity Engineer, Offensive Product Security role sits within the broader Product Cybersecurity organization at General Motors and focuses on offensive security services that help strengthen confidence in the security of our product portfolio. Through penetration testing, red-team activity, and security research, this engineer helps identify meaningful weaknesses in software, systems, and product implementations across embedded vehicle software, mobile experiences, and product-backed software and services. This role works closely with product teams to assess real-world attack paths, validate risk, and provide actionable findings that help find areas to mature in our secure SDLC. What You'll Do * Perform penetration testing across software, systems, and product environments * Conduct security research that targets meaningful product and technology risks * Execute offensive assessments across embedded, mobile, and backend environments * Identify vulnerabilities, validate impact, and provide clear remediation guidance * Partner with engineering teams to improve security through practical technical findings * Help strengthen offensive methods, tooling, and testing approaches across the portfolio, This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}. ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)