Description
At General Motors, software is central to how we build vehicles, platforms, and digital experiences. We are looking for a people leader to lead Secure Development & Application Security, a key Cybersecurity function focused on embedding preventative and detective security controls into engineering workflows before software reaches production.
This function includes areas such as static application security testing, dynamic application security testing, API security, AI security, and runtime resilience. This role is ideal for a leader who can help scale practical, developer-friendly security across modern software environments while improving risk reduction, coverage, and engineering partnership.
The Role
As Manager, Secure Development & Application Security, you will lead a distinct Cybersecurity function responsible for improving how secure software is designed, built, tested, and operated across GM. You will translate strategy into clear direction for teams, set priorities, allocate resources, and own the operational performance of the function. You will partner closely with engineering, platform, product, infrastructure, and other security teams to embed practical, developer-friendly controls that reduce risk without slowing delivery. You will help shape scalable security services and workflows that improve consistency across the software lifecycle. This is a high-impact leadership role for someone who can build strong teams, influence across organizations, and lead change through measurable outcomes.
What You’ll Do
- Lead the Secure Development & Application Security function, including team direction, operating model, workforce planning, and delivery against business priorities.
- Define and drive the roadmap for security controls embedded in engineering workflows, including static testing, dynamic testing, API security, AI security, and runtime resilience.
- Own functional performance through key metrics and service outcomes, using data to prioritize investments, improve coverage, and reduce application risk at scale.
- Partner with engineering and platform teams to integrate security controls into development pipelines and release processes in ways that are effective, reliable, and usable.
- Guide leaders and team members through complex technical and operational decisions, removing roadblocks and enabling consistent execution across multiple teams.
- Build strong cross-functional relationships to align policy, tooling, detection, remediation, and governance across the software development lifecycle.
- Develop talent, strengthen succession pipelines, and lead organizational change that improves team capability, accountability, and impact.
Your Skills & Abilities (Required Qualifications)
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
- 5+ years of experience in cybersecurity, application security, software engineering security, or secure software development.
- 3+ years of experience leading people, including hiring, coaching, performance management, and team development.
- 3+ years of experience leading or scaling one or more application security domains such as static testing, dynamic testing, API security, AI security, threat modeling, or runtime protection.
- Experience partnering with engineering and product organizations to embed security controls into software delivery workflows, developer tools, and release processes.
- Experience owning operational goals, metrics, or key performance indicators and using them to drive prioritization, execution, and continuous improvement.
- Working knowledge of modern software architectures and delivery environments, including cloud-native applications, APIs, containers, continuous integration and delivery pipelines, and developer tooling.
- Demonstrated ability to make independent decisions on significant matters, influence across functions, and lead teams through change in a complex enterprise environment.
What Will Give You A Competitive Edge (Preferred Qualifications)
- Master’s degree in a relevant field.
- 8+ years of experience in cybersecurity or software security, including enterprise-scale application security leadership.
- Experience building or maturing secure development programs in large, highly distributed engineering environments.
- Experience with developer-friendly security practices such as security automation, policy as code, self-service enablement, and risk-based remediation.
- Familiarity with regulated environments, third-party software risk, and secure-by-design approaches across the software lifecycle.
- Relevant industry certifications such as CISSP, CSSLP, GIAC, or cloud security certifications.
- Experience in automotive, mobility, manufacturing, or other large-scale product and technology organizations.
GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc.)
This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.
This job may be eligible for relocation benefits.
About GM
Our vision is a world with Zero Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more equitable for all.
Why Join Us
We believe we all must make a choice every day – individually and collectively – to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team.
Total Rewards | Benefits Overview
From day one, we're looking out for your well-being–at work and at home–so you can focus on realizing your ambitions. Learn how GM supports a rewarding career that rewards you personally by visiting Total Rewards resources.
Non-Discrimination and Equal Employment Opportunities (U.S.)
General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.
All employment decisions are made on a non-discriminatory basis without regard to sex, race, color, national origin, citizenship status, religion, age, disability, pregnancy or maternity status, sexual orientation, gender identity, status as a veteran or protected veteran, or any other similarly protected status in accordance with federal, state and local laws.
We encourage interested candidates to review the key responsibilities and qualifications for each role and apply for any positions that match their skills and capabilities. Applicants in the recruitment process may be required, where applicable, to successfully complete a role-related assessment(s) and/or a pre-employment screening prior to beginning employment. To learn more, visit How we Hire.
Accommodations
General Motors offers opportunities to all job seekers including individuals with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, email us [email protected] or call us at 1-800-865-7580. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.



