[Skip To Content]

Cybersecurity Engineer – PKI & Secrets Management

  • Emplacement
    • Austin, Texas
    • Warren, Michigan
  • Type d'emploi Full time
  • Posté
  • Job Requisition JR-202615529

Description

The Role
The Cyber Security Engineer – PKI & Secrets Management acts as a senior domain expert for PKI and secrets, providing technical leadership, hands-on engineering, and cross-team guidance for certificate lifecycle management, key management, hardware security modules (HSMs), and enterprise secrets platforms. The role partners closely with Security Services, infrastructure, cloud, application, and product teams to ensure cryptographic services are reliable, scalable, and aligned with GM security standards and regulatory requirements.


What You’ll Do

  • Serve as the primary subject matter expert for at least one major PKI or secrets platform (e.g., enterprise CAs, HSM-backed key management, or central secrets management platform), including strategy, architecture, and day-to-day engineering

  • Design, implement, and maintain certificate lifecycle management solutions supporting servers, applications, devices, and services across on‑prem and cloud environments

  • Engineer, harden, and operate PKI components, including root and subordinate CAs, OCSP/CRL infrastructure, key storage, and associated monitoring and audit capabilities

  • Lead design and integration of secrets management patterns (e.g., application secrets, API keys, database credentials, service identities), driving standardization and automation for onboarding new use cases

  • Define and document PKI and secrets management standards, patterns, and reference architectures for use by application and infrastructure teams across GM

  • Provide technical leadership on Cyber Security projects related to identity, access, encryption, and secure connectivity, ensuring PKI and secrets requirements are captured, implemented, and validated

  • Collaborate with software, cloud, and infrastructure teams to embed secure-by-default cryptographic practices (e.g., TLS, mutual auth, certificate pinning, key rotation) in platforms and services

  • Lead root cause analysis and remediation for PKI/secrets-related incidents or outages, driving durable fixes, improved monitoring, and lessons-learned back into standards and runbooks

  • Develop automation and tooling (e.g., scripting, APIs, workflows) to reduce manual certificate and secrets operations, improve consistency, and increase coverage across fleets and environments

  • Participate in threat analysis and risk assessment activities where cryptography, keys, and certificates are central controls, translating findings into practical mitigation plans

  • Mentor and support other engineers on PKI, cryptography, and secrets management topics; provide clear guidance, design reviews, and hands-on assistance to project and platform teams

  • Represent the PKI & Secrets Management domain in internal forums, architecture reviews, and change control, ensuring changes that impact cryptographic services are well understood and properly evaluated

  • Contribute to and help own security metrics and KPIs related to certificate hygiene, secrets lifecycle health, coverage, and platform reliability; drive action plans when targets are not met

  • Lead development and execution of Cyber Security projects where PKI, certificate management, and secrets are primary enablers, from requirements definition through design, implementation, and operational transition

  • Exercise independent judgment on significant cryptographic and platform decisions, balancing security, reliability, and developer experience, and clearly articulating tradeoffs to stakeholders

  • Act as a recognized senior Cyber Security engineer with deep expertise in PKI & secrets and broad knowledge of adjacent areas (identity, network security, cloud security, compliance, and risk)

  • Break complex security and reliability problems into actionable initiatives, orchestrating work across Security Services, infrastructure, and application teams

  • Champion change management by driving adoption of updated PKI roots/intermediates, new secrets patterns, and improved lifecycle processes across legacy and modern platforms

  • Serve as a mentor and go‑to resource for junior and mid-level Cyber Security engineers, modeling GM’s behaviors and engineering best practices

Your Skills & Abilities (Required Qualifications):

  • Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, Information Technology, or a closely related field; or equivalent experience

  • Strong hands-on experience with enterprise PKI concepts and technologies, including: X.509 certificates, key pairs, certificate chains, and trust stores

  • Certificate issuance, renewal, revocation, CRLs/OCSP, and policy definition

  • Operating or integrating with certificate authorities and HSM-backed key storage

  • Practical experience designing or operating secrets management solutions (e.g., application secrets, service identities, API keys, credential rotation patterns) in large-scale environments

  • Solid understanding of network security and secure communications (TLS, mTLS, cipher suites, protocol hardening, certificate validation)

  • Demonstrated ability to own and deliver complex security engineering projects end-to-end with minimal direction, including planning, execution, and stakeholder communication

  • Strong problem-solving skills and experience troubleshooting PKI, certificate, and secrets-related failures in distributed systems

  • Ability to communicate complex technical concepts clearly to both engineers and non-technical partners, and to influence design decisions across teams

  • Demonstrated alignment with GM behaviors (Think Customer, Be Inclusive, It’s on All of Us, Innovate Now, Look Ahead, One Team, Be Bold, Win with Integrity) in day-to-day work

What Will Give You A Competitive Edge (Preferred Qualifications):

  • Experience operating PKI or secrets services in hybrid or multi-cloud environments

  • Familiarity with identity and access management (IAM) platforms, directory services, and authentication/authorization patterns that depend on PKI and secrets

  • Experience developing automation for certificate and secrets lifecycle (scripting, APIs, CI/CD integrations, or configuration management tools)

  • Prior experience in a large enterprise or regulated environment where cryptographic controls support audit, compliance, or regulatory requirements

  • Experience mentoring other engineers or informally leading technical workstreams within a security or infrastructure team

Renseignements sur la diversité

General Motors est résolue à être un lieu de travail qui est non seulement exempt de discrimination illégale, mais aussi un endroit qui favorise véritablement l'inclusion et l'appartenance. Nous sommes convaincus que la diversité de la main-d'œuvre permet de créer un environnement dans lequel nos employés peuvent s'épanouir et développer de meilleurs produits pour nos clients. Nous encourageons les candidats intéressés à consulter les principales responsabilités et compétences requises pour chaque rôle et à postuler à tout poste qui leur correspond. Dans le cadre du processus de recrutement, les candidats peuvent devoir, le cas échéant, réussir une évaluation liée au poste ou une présélection d'emploi avant d'être embauchés.  Pour en savoir plus, consultez notre processus de recrutement.

Déclaration concernant l'égalité d'accès à l'emploi (É.-U.)

General Motors est fière d'être un employeur souscrivant au principe de l'égalité d'accès à l'emploi.  Tous les candidats qualifiés seront pris en compte, sans égard à la race, à la couleur, à la religion, au sexe, à l'orientation sexuelle, à l'identité de genre, à l'origine ethnique, aux situations de handicap ou au statut protégé d'ancien combattant. 

Aménagements (É.-U. et Canada)

General Motors offre des occasions à tous les chercheurs d'emploi, y compris les personnes handicapées. Si vous avez besoin d'un accommodement raisonnable pour vous aider dans votre recherche d'emploi ou la soumission de votre candidature, envoyez-nous un courriel à l'adresse [email protected] ou appelez-nous au 800 865-7580. Veuillez inclure dans votre courriel une description spécifique du type d'accommodement demandé, ainsi que le titre d'emploi et le numéro de demande du poste auquel vous postulez.