Descripción
At General Motors, we are building secure software and connected experiences at scale. The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback loops that help teams reduce risk before it becomes customer impact.
This team helps uncover exploitable weaknesses, verify how well controls are performing, and provide actionable insights that improve remediation and prevention. This role is ideal for a leader who can grow a high-performing team, turn strategy into execution, and raise the security bar across a complex engineering environment.
The Role
As Manager, Offensive Security, you will lead a distinct Cybersecurity function responsible for validating how well our products, platforms, and engineering controls stand up to real-world attacks. You will set direction for offensive security programs, translate enterprise priorities into team goals, and make operational decisions about talent, capacity, tooling, and delivery. You will partner closely with engineering, product, infrastructure, and Cybersecurity leaders to prioritize risk, improve remediation outcomes, and strengthen preventative controls. You will help shape scalable testing approaches that balance speed, depth, and business impact. This is a high-impact leadership role for someone who can build talent, influence across organizations, and lead change through measurable outcomes.
What You’ll Do
- Lead and develop a team responsible for penetration testing, adversary emulation, responsible disclosure triage, and verification of security controls across applications, platforms, and services.
- Own the function roadmap, operating model, and key performance indicators, including coverage, remediation velocity, validation quality, and risk reduction outcomes.
- Translate Cybersecurity strategy into quarterly priorities, staffing plans, resource allocation decisions, and clear execution goals for the team.
- Partner with engineering and platform teams to turn offensive security findings into remediation actions, prevention improvements, and stronger secure-by-design practices.
- Establish scalable testing approaches for web, API, cloud, identity, container, and software delivery environments, balancing depth, speed, and business risk.
- Drive stakeholder communication, cross-functional alignment, and change leadership, including escalation of significant risks and recommendations for action.
Your Skills & Abilities (Required Qualifications)
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
- 10+ years of cybersecurity experience, including 5+ years in offensive security, penetration testing, red teaming, application security testing, or closely related disciplines.
- 5+ years of people leadership experience, including hiring, performance management, coaching, workforce planning, and team development.
- 3+ years leading complex, cross-functional security programs with measurable outcomes across multiple product, software, or platform teams.
- Experience assessing or testing modern attack surfaces such as web applications, APIs, cloud services, identity systems, containers, developer tooling, or software delivery pipelines.
- Demonstrated ability to define key performance indicators, prioritize competing work, communicate risk to technical and business stakeholders, and drive remediation to closure.
What Will Give You A Competitive Edge (Preferred Qualifications)
- Experience building or leading offensive security programs in large-scale software, cloud, or product engineering environments.
- Familiarity with responsible disclosure, vulnerability intake, or bug bounty program operations.
- Experience partnering with development teams to improve secure design, detection, and resilience based on offensive testing results.
- Knowledge of security automation, findings workflows, and telemetry-driven reporting.
- Relevant industry certifications such as OSCP, OSWE, GPEN, GXPN, CISSP, or comparable credentials.
- Experience in highly regulated, safety-critical, or large enterprise environments.
GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc.)
Este puesto se clasifica como híbrido. Esto significa que se espera que el candidato seleccionado se presente en una ubicación específica al menos 3 veces por semana {o con otra frecuencia indicada por su líder}.
Este puesto podría ser elegible para beneficios de relocalización.
Información sobre diversidad
General Motors se compromete a ser un lugar de trabajo en el cual no solo no haya discriminación indebida, sino que fomente con sinceridad la inclusión y el sentido de pertenencia. Creemos firmemente que la diversidad del personal crea un entorno en el cual nuestros empleados pueden prosperar y desarrollar mejores productos para nuestros clientes. Instamos a los candidatos interesados a que revisen las responsabilidades y aptitudes clave para cada puesto y se postulen para los puestos que coincidan con sus habilidades y capacidades. Es posible que, cuando corresponda, se les pida a los solicitantes que están en el proceso de contratación que completen satisfactoriamente una o más evaluaciones relacionadas con su función y/o una evaluación previa al empleo antes de comenzar a trabajar. Para obtener más información, visite Cómo contratamos.
Declaración de igualdad de oportunidades en el empleo (EE.UU.)
General Motors se enorgullece de ser un empleador que ofrece igualdad de oportunidades. Todos los solicitantes calificados serán tenidos en cuenta para el empleo sin distinción de raza, color, religión, sexo, orientación sexual, identidad de género, nacionalidad, discapacidad o condición de veterano protegido.
Adecuaciones (EE.UU. y Canadá)
General Motors ofrece oportunidades a todos los solicitantes de empleo, incluyendo las personas con discapacidades. Si necesita una adecuación razonable para ayudarle con su búsqueda o solicitud de empleo, envíenos un correo electrónico a [email protected] o llámenos al 800-865-7580. En su correo electrónico, incluya una descripción del puesto específico que está solicitando, así como el título del empleo y el número de solicitud del puesto que está solicitando.




