Manager, Offensive Product Cybersecurity & PSOC
Role details
Job location
Tech stack
Job description
The Manager, Offensive Product Cybersecurity & PSOC leads two key areas within GM's Product Cybersecurity organization: offensive product security services and the Product Security Operations Center (PSOC). This leader oversees penetration testing, red team operations, and security research to strengthen confidence in the security of GM's products, while also owning product security operations, including security-readiness visibility, detection and response, bug bounty management, and product security incident response (PSIRT)., * Lead a team of 10+ product cybersecurity engineers across offensive security and security operations.
- Define a comprehensive set of offensive security services and capabilities to ensure a secure product portfolio.
- Establish and manage a product security assessment schedule in partnership with product management teams.
- Develop and formalize a security research plan focused on forward-looking technology investments.
- Own product cybersecurity operations strategy and data sources to enable effective detection and response.
- Coordinate with third-party security researchers through the bug bounty program and lead PSIRT activities., This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.
Requirements
- 8+ years of security experience in product security teams or similar security functions.
- 4+ years of leadership experience in penetration testing, security research, product security, or closely related roles.
- Expertise in embedded security, including operating system, application, and hardware contexts.
- Experience defining a team calendar of work that incorporates stakeholder and business-wide priorities.
- Ability to read and write software in multiple languages to support investigation and remediation efforts.
- Proven leadership of incident response activities involving time-sensitive and confidential workflows.
What Will Give You a Competitive Edge (Preferred Qualifications)
- Prior experience in the automotive industry or a similarly complex, deadline-driven, and regulated environment.
- Published cybersecurity research (e.g., conference talks, blog posts, or public code repositories).
- Experience architecting security operations platforms and leading security analysts in triaging risk-based findings.
- Experience building custom security tooling and/or extending functionality in related technologies.
- A detailed, high-ownership leadership style that connects vision to clearly articulated strategy.
- Ability to manage multiple complex projects simultaneously with defined milestones and success criteria.
- Strong commitment to internal customer relationships that drive high-quality security outcomes.
- Deep technical expertise that supports confident, opinionated work planning and team mentorship.
- Ability to communicate technical content effectively to various levels of leadership and external audiences, including media.