Staff Cybersecurity Software Engineer

General Motors
Jackson, MS, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$160,200.0 - $246,300.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services User Authentication Microsoft Azure C++ (Programming Language) Cloud Engineering Cyber Security Continuous Integration Cross-Site Request Forgery Data Validation Data Structures
+32 more
Cursor (Graphical User Interface Elements) Software Design Patterns Identity and Access Management Python (Programming Language) Key Management OAuth OpenID Software Architecture Systems Development Life Cycle Role-Based Access Control Secure Coding Security Software Single Sign-On Software Engineering TypeScript Data Logging Google Cloud Cloud Platform System GitHub Copilot ReactJS Delivery Pipeline Cross-Site Scripting (XSS) Containerization Kubernetes Information Technology Data Analytics Build Tools Software Coding Docker Databricks Golang Programming Languages

Job description

We’re looking for a Security Software Engineer to join the Security Products Engineering team and drive the design and implementation of security-focused software and services across GM. You will lead and contribute to the engineering of platforms, services, and tooling that enable secure-by-default experiences for developers and end users, with a strong emphasis on high-quality software architecture, coding standards, and automation.

You will work as a hands-on engineer: designing systems, writing code, reviewing designs and implementations, and partnering with teams across GM to embed security into the software development lifecycle.

What You’ll Do:

  • Design, build, and maintain security-focused software components, services, and tools used across GM’s application ecosystem.
  • Develop automation frameworks and internal platforms that make it easy for product teams to adopt secure patterns (e.g., identity, authorization, secrets management, logging).
  • Integrate security controls and checks into CI/CD pipelines, build systems, and cloud-native deployment workflows.
  • Architect and implement resilient, scalable security services and APIs (e.g., authentication, authorization, policy evaluation, event ingestion).
  • Collaborate with application, infrastructure, and platform engineering teams to embed security requirements into system and service designs.
  • Perform secure code reviews, threat modeling, and design reviews to identify and remediate vulnerabilities early in the SDLC.
  • Build and maintain systems for security telemetry: logging, metrics, and alerting that support detection, triage, and incident response.
  • Contribute to incident response and post-incident reviews as an engineering owner for security services and tooling.
  • Stay current with emerging security threats, vulnerabilities, and technologies, and translate them into concrete engineering requirements, patterns, and roadmaps.
  • Provide technical mentorship on secure coding, design patterns, and security architecture to other software engineers., This role is based remotely, but if the selected candidate lives within a specific mile radius of a GM hub, they will be expected to report to the location three times a week {or other frequency dictated by your manager}.

Requirements

  • Bachelor’s degree or higher in Computer Science, Software Engineering, Cybersecurity, or a related technical field (or equivalent practical experience).
  • 7+ years of experience as a software engineer building and owning production systems or in-house applications.
  • Advanced proficiency in at least one modern programming language (for example: Python, Go, Java, or C++) with a strong understanding of software engineering fundamentals (data structures, algorithms, design patterns).
  • Experience using AI-assisted development tools (for example, GitHub Copilot, Cursor, or similar) as part of day-to-day engineering workflows.
  • Experience designing, implementing, and operating services on a major cloud platform (AWS, Azure, or GCP), including use of managed services and infrastructure-as-code.
  • Hands-on experience with containerization and orchestration technologies (e.g., Docker, Kubernetes).
  • Solid understanding of core security concepts as applied to software engineering, including:
  • Authentication and authorization patterns (OAuth2/OIDC, SSO, RBAC/ABAC).
  • Encryption in transit and at rest, key/secrets management.
  • Secure coding practices, input validation, and common vulnerability classes (e.g., injection, XSS, CSRF, insecure direct object references).
  • Experience partnering with security and audit/compliance teams and translating security requirements into engineering work.
  • Proven ability to plan and manage work in an Agile environment, taking ownership of features and services from design through production.
  • Strong written and verbal communication skills, with the ability to explain identity and security concepts to both technical and non-technical audiences.

What Will Give You A Competitive Edge (Preferred Qualifications):

  • Experience designing or implementing identity and access management (IAM) solutions, including external/partner identity, contractor-heavy environments, or B2B/B2C identity patterns.
  • Project experience modeling and deploying external identity architectures (e.g., federation, multi-tenant identity, just-in-time provisioning).
  • Experience with data and analytics platforms (e.g., Databricks) or broader Microsoft/Google cloud product ecosystems.
  • Experience integrating cloud access security broker (CASB) or similar security technologies into applications or platforms.
  • Experience with modern front-end application development (e.g., React, TypeScript) and securing front-end/back-end interactions.
  • Track record of leading engineering initiatives that improved security posture through better design, automation, or developer experience.

Benefits & conditions

Compensation: The compensation information is a good faith estimate only. It is based on what a successful applicant might be paid in accordance with applicable state laws. The actual base salary a successful candidate will be offered within this range will vary based on factors relevant to the position, as well as geography of the selected candidate.

  • The salary range for this role is $160,200-$246,300. The actual base salary a successful candidate will be offered within this range will vary based on factors relevant to the position.

  • Bonus Potential: An incentive pay program offers payouts based on company performance, job level, and individual performance.

Benefits:

Benefits: GM offers a variety of health and wellbeing benefit programs. Benefit options include medical, dental, vision, Health Savings Account, Flexible Spending Accounts, retirement savings plan, sickness and accident benefits, life insurance, paid vacation & holidays, tuition assistance programs, employee assistance program, GM vehicle discounts and more.

About the company

We believe we all must make a choice every day - individually and collectively - to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team., General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all