Description
Hybrid: This position does not require an employee to be onsite full-time, but the general expectation is that the employee will be onsite a minimum of 3 days each week.
The Role:
This is an exciting opportunity if you are looking to grow your security skillset and contribute in shaping the future of automotive security innovation. GM is undergoing a major transformation, both in how we operate and in how we will influence the future of transportation. The Senior Cybersecurity Engineer will lead in a progressive technical position responsible for continued execution of GM’s security design and its evolution through technological advancements to ensure GM remains ahead of the adversary. You will define end-to-end security solutions, feature requirements and guide the implementation across internal and external embedded software developers. You will engage with GM IT developers to drive application requirements necessary for enabling vehicle security strategies. In this role, you will be given the opportunity to engage in advanced technology work to evaluate various strategies for consideration in GM’s automotive security roadmap. You will also be given the opportunity to work cross-functionally with many GM business units to enable the success of vehicle development, manufacturing, and serviceability.
What You’ll Do:
-
Lead subject matter expert for end-to-end security for Digital Key System, remote vehicle access and biometrics sub-systems.
-
Lead subject matter expert for various fielded ECUs security strategy.
-
Conduct vulnerability Threat Analysis and Risk Assessment (TARA), and guide remediation strategy.
-
Define SDV (Software Defined Vehicle) ECUs security designs.
-
Develop and maintain detailed security requirements documentation for product specifications to support system design, development, and features evolution.
-
Lead design and implementation reviews of ECU security elements.
-
Review and approve the design of embedded systems from a cybersecurity perspective.
-
Work closely with development teams and penetration test engineers to risk assess and mitigate identified security vulnerabilities.
-
Perform risk assessments on penetration test findings and deviations from cybersecurity requirements.
-
Work with IT, product development teams, service engineering, and manufacturing engineering to gather requirements ensuring future changes are practical and non-disruptive.
-
Grow technical capability and knowledge on the latest cybersecurity features, tools and embedded technologies from a security perspective.
-
Conduct SW scans, lead their analysis, and guide remediation strategy.
-
Document vulnerabilities and mitigation action plans.
-
Occasional Local/Domestic/International travel to other GM facilities and supplier sites up to 5%.
[Additional Description]
Your Skills & Abilities (Required Qualifications):
-
Bachelor’s Degree in Electrical Engineering, Computer Engineering, Computer Science, Systems Engineering or equivalent majors.
-
5+ years of professional experience with proven technical and professional skills in job-related area required, including embedded controls/software development.
-
Knowledge and experience on working with Blue Tooth, BLE, and UWB technology.
-
General knowledge of microcontroller architectures.
-
Basic understanding of cryptography fundamentals (Encryption, Authentication, Symmetric Cryptography, Asymmetric Cryptography, PKI).
-
Ability to work independently, make decisions and recommendations while taking into account appropriate tradeoffs between conflicting objectives.
-
Strong interpersonal skills with demonstrated ability to participate in diverse/cross-functional teams, as well as educate/coach others on cybersecurity controls in the connected ecosystem ECU space.
-
Ability to handle ambiguity and make recommendations with limited data.
-
Technical writing competency.
What Will Give You A Competitive Edge (Preferred Qualifications):
-
2+ years of Cybersecurity experience.
-
Experience with bootloader, embedded security, controller communication, or diagnostics.
-
Knowledge of AUTOSAR standards and methodology.
-
Knowledge and experience with CAN, Ethernet or Bluetooth Low Energy (BLE) communications protocol.
-
Knowledge of microprocessor architectures deployed across the automotive industry.
-
Knowledge and experience with CCC (Car Connectivity Consortium) standards and specifications.
-
Understanding of methods leveraged for digital signature generation and verification.
-
Knowledge of diagnostic services (e.g., ISO 14229).
-
Understanding of automotive security peripherals (i.e., Secured Hardware Extension (SHE) and EVITA Hardware Security Module (HSM)).
-
Experience with Certificate Authorities and cryptography.
-
Experience with and/or knowledge of technologies used to secure embedded systems.
-
Understanding of various Cybersecurity elements deployed to embedded systems.
-
Experience with IT Back Office security.
#LI-SW1
Renseignements sur la diversité
General Motors est résolue à être un lieu de travail qui est non seulement exempt de discrimination illégale, mais aussi un endroit qui favorise véritablement l'inclusion et l'appartenance. Nous sommes convaincus que la diversité de la main-d'œuvre permet de créer un environnement dans lequel nos employés peuvent s'épanouir et développer de meilleurs produits pour nos clients. Nous encourageons les candidats intéressés à consulter les principales responsabilités et compétences requises pour chaque rôle et à postuler à tout poste qui leur correspond. Dans le cadre du processus de recrutement, les candidats peuvent devoir, le cas échéant, réussir une évaluation liée au poste ou une présélection d'emploi avant d'être embauchés. Pour en savoir plus, consultez notre processus de recrutement.
Déclaration concernant l'égalité d'accès à l'emploi (É.-U.)
General Motors est fière d'être un employeur souscrivant au principe de l'égalité d'accès à l'emploi. Tous les candidats qualifiés seront pris en compte, sans égard à la race, à la couleur, à la religion, au sexe, à l'orientation sexuelle, à l'identité de genre, à l'origine ethnique, aux situations de handicap ou au statut protégé d'ancien combattant.
Aménagements (É.-U. et Canada)
General Motors offre des occasions à tous les chercheurs d'emploi, y compris les personnes handicapées. Si vous avez besoin d'un accommodement raisonnable pour vous aider dans votre recherche d'emploi ou la soumission de votre candidature, envoyez-nous un courriel à l'adresse Careers.Accommodations@GM.com ou appelez-nous au 800 865-7580. Veuillez inclure dans votre courriel une description spécifique du type d'accommodement demandé, ainsi que le titre d'emploi et le numéro de demande du poste auquel vous postulez.