> Markdown version of [/jobs/ext/2586859-senior-product-cybersecurity-engineer-product-security-incident-response-team-psirt](https://www.wearedevelopers.com/jobs/ext/2586859-senior-product-cybersecurity-engineer-product-security-incident-response-team-psirt). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT) - **Company:** General Motors - **Location:** Warren, MI, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Cyber Security, Firmware, Software Security, Backend - **Published:** August 14, 2026 - **Apply:** https://generalmotors.wd5.myworkdayjobs.com/Careers_GM/job/Warren-Michigan-United-States-of-America/Senior-Product-Cybersecurity-Engineer--Product-Security-Incident-Response-Team--PSIRT-_JR-202617421 ## About the Role * 6+ years of direct experience in product security, security engineering, and/or incident response * Hands-on experience analyzing software, firmware, or system vulnerabilities and exploitability * Familiarity with common vulnerability classes, CVEs/CVSS, and coordinated disclosure practices * Able to read and write software in multiple languages for analysis and remediation guidance * Experience working with engineering and product teams to drive timely, effective remediation * Strong written and verbal communication skills for technical and non-technical audiences What Will Give You A Competitive Edge (Preferred Qualifications) * Experience with automotive, embedded, or connected product environments * Prior experience in a PSIRT, PSOC, or similar product-focused security response function * Experience building or using tools and dashboards for vulnerability intake, tracking, and reporting * Experience contributing to internal / external security advisories and customer communications What You'll Bring * A calm, structured approach to handling security issues under time pressure * Strong judgment on risk, prioritization, and what is materially important to fix * A collaborative style that builds trust with engineers and cross-functional partners * A bias toward clear action, closure, and learning from each incident or vulnerability * A focus on improving PSIRT processes and tooling so security response gets better over time ## Description The Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT) role sits within the broader Product Cybersecurity organization at General Motors and focuses on responding to and managing product security vulnerabilities across GM's portfolio. Through rigorous investigation, technical risk analysis, and close collaboration with engineering and cross-functional partners, this engineer helps ensure that product security issues are triaged, remediated, and learned from in a consistent and defensible way. What You'll Do * Investigate and triage product security reports across vehicle, mobile, API, and backend software * Analyze exploitability, customer impact, and risk, and recommend severity and treatment * Partner with product and engineering teams on remediation plans, timelines, and validation * Validate fixes and mitigations to ensure vulnerabilities are resolved with sufficient quality * Contribute to PSIRT processes, playbooks, and tooling to improve consistency and response speed * Work as part of PSOC and closely with SOC, bug bounty, disclosure, and legal on product incidents, This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}. ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Agile work at CARIAD – Creating a customer web application for controlling the vehicle ](https://www.wearedevelopers.com/videos/200-agile-work-at-cariad-creating-a-customer-web-application-for-controlling-the-vehicle) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)