Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT) role sits within the broader Product Cybersecurity organization at General Motors and focuses on responding to and managing product security vulnerabilities across GM’s portfolio. Through rigorous investigation, technical risk analysis, and close collaboration with engineering and cross-functional partners, this engineer helps ensure that product security issues are triaged, remediated, and learned from in a consistent and defensible way.
What You’ll Do
- Investigate and triage product security reports across vehicle, mobile, API, and backend software
- Analyze exploitability, customer impact, and risk, and recommend severity and treatment
- Partner with product and engineering teams on remediation plans, timelines, and validation
- Validate fixes and mitigations to ensure vulnerabilities are resolved with sufficient quality
- Contribute to PSIRT processes, playbooks, and tooling to improve consistency and response speed
- Work as part of PSOC and closely with SOC, bug bounty, disclosure, and legal on product incidents, This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.
Requirements
- 6+ years of direct experience in product security, security engineering, and/or incident response
- Hands-on experience analyzing software, firmware, or system vulnerabilities and exploitability
- Familiarity with common vulnerability classes, CVEs/CVSS, and coordinated disclosure practices
- Able to read and write software in multiple languages for analysis and remediation guidance
- Experience working with engineering and product teams to drive timely, effective remediation
- Strong written and verbal communication skills for technical and non-technical audiences
What Will Give You A Competitive Edge (Preferred Qualifications)
- Experience with automotive, embedded, or connected product environments
- Prior experience in a PSIRT, PSOC, or similar product-focused security response function
- Experience building or using tools and dashboards for vulnerability intake, tracking, and reporting
- Experience contributing to internal / external security advisories and customer communications
What You’ll Bring
- A calm, structured approach to handling security issues under time pressure
- Strong judgment on risk, prioritization, and what is materially important to fix
- A collaborative style that builds trust with engineers and cross-functional partners
- A bias toward clear action, closure, and learning from each incident or vulnerability
- A focus on improving PSIRT processes and tooling so security response gets better over time
About the company
We believe we all must make a choice every day - individually and collectively - to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team., General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Now is the time for industrialized software development
Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps
Dev Digest 134 - Where pixels sing?