Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT)

General Motors
Warren, MI, United States
23 days ago
Apply on generalmotors.wd5.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Cyber Security Firmware Software Security Backend

Job description

The Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT) role sits within the broader Product Cybersecurity organization at General Motors and focuses on responding to and managing product security vulnerabilities across GM’s portfolio. Through rigorous investigation, technical risk analysis, and close collaboration with engineering and cross-functional partners, this engineer helps ensure that product security issues are triaged, remediated, and learned from in a consistent and defensible way.

What You’ll Do

  • Investigate and triage product security reports across vehicle, mobile, API, and backend software
  • Analyze exploitability, customer impact, and risk, and recommend severity and treatment
  • Partner with product and engineering teams on remediation plans, timelines, and validation
  • Validate fixes and mitigations to ensure vulnerabilities are resolved with sufficient quality
  • Contribute to PSIRT processes, playbooks, and tooling to improve consistency and response speed
  • Work as part of PSOC and closely with SOC, bug bounty, disclosure, and legal on product incidents, This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.

Requirements

  • 6+ years of direct experience in product security, security engineering, and/or incident response
  • Hands-on experience analyzing software, firmware, or system vulnerabilities and exploitability
  • Familiarity with common vulnerability classes, CVEs/CVSS, and coordinated disclosure practices
  • Able to read and write software in multiple languages for analysis and remediation guidance
  • Experience working with engineering and product teams to drive timely, effective remediation
  • Strong written and verbal communication skills for technical and non-technical audiences

What Will Give You A Competitive Edge (Preferred Qualifications)

  • Experience with automotive, embedded, or connected product environments
  • Prior experience in a PSIRT, PSOC, or similar product-focused security response function
  • Experience building or using tools and dashboards for vulnerability intake, tracking, and reporting
  • Experience contributing to internal / external security advisories and customer communications

What You’ll Bring

  • A calm, structured approach to handling security issues under time pressure
  • Strong judgment on risk, prioritization, and what is materially important to fix
  • A collaborative style that builds trust with engineers and cross-functional partners
  • A bias toward clear action, closure, and learning from each incident or vulnerability
  • A focus on improving PSIRT processes and tooling so security response gets better over time

About the company

We believe we all must make a choice every day - individually and collectively - to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team., General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on generalmotors.wd5.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

11:26 min

Identifying system risks and collaborative ecosystem legal challenges

Hans-Jürgen Eidler · LIVE

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

1:57 min

Following security research and continuous developer education

Martin Schmiedecker · LIVE

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

Videos

See all

Related articles

See all