Skip to main content

Product Cybersecurity Penetration Tester

Description

This position involves performing security vulnerability assessments and penetration testing on GM products, including latest and next gen vehicles.

  • Simulate cyber attacks against vehicles and vehicle components to discover and exploit vulnerabilities
  • Reverse engineering on embedded devices firmware to identify and exploit vulnerabilities
  • Defining pen-test methodologies with a combination of automated and manual tools
  • Provide recommendation to mitigate security risks and fix security vulnerabilities
  • Demonstrate creative analysis techniques in distilling test results, eliminating false positives and providing actionable recommendations for mitigation
  • Serve as subject matter expert and resource on security exploits and containment approaches.
  • Research emerging vulnerabilities and develop proof-of-concept (POC) as needed
  • Develop custom tools to support penetration testing as required
  • Help guide 3rd party vendors with security assessments and provide coordination and support as needed

Additional Description

Required Skills

  • Penetration testing experience
  • Reverse engineering embedded systems and source code review
  • Proficiency in at least one of the following languages: C, C++, Java, or Python
  • Experience with real-time and POSIX oriented operating systems (Linux, Android, and QNX)
  • Security cryptography fundamentals - PKI, certificates, encryption, signatures, authentication, and authorization
  • Must have strong teamwork orientation and the ability to foster collaboration within and across teams

Preferred Skills

  • Experience with Vulnerability assessments and penetration testing
  • In-depth knowledge with wireless protocols, Wi-Fi, Bluetooth, and Zigbee
  • Reverse engineering Linux and/or Android based software
  • Experience with common automotive communication protocols (e.g., CAN/LIN, UDS/DoIP, Ethernet, immobilization etc.)
  • Security cryptography fundamentals - PKI, certificates, encryption, signatures, authentication, and authorization.
  • Experience with OS internals, virtualization, or container technologies
  • Experience with network protocols: TCP/IP, HTTP, (OSI model)
  • Certifications OSCP, OSEP, GPEN. 

This position may be filled with a mid-level professional, the median salary for that level is 97,980, OR this position may be filled with a Sr. level candidate, the median salary for that level is 126,756.

Bonus Potential: An incentive pay program offers payouts based on company performance, job level, and individual performance.

Benefits: GM offers a variety of health and wellbeing benefit programs. Benefit options include medical, dental, vision, Health Savings Account, Flexible Spending Accounts, retirement savings plan, sickness and accident benefits, life insurance, paid vacation & holidays, tuition assistance programs, employee assistance program, GM vehicle discounts and more.


About GM

Our vision is a world with Zero Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more equitable for all.

Why Join Us 

We aspire to be the most inclusive company in the world. We believe we all must make a choice every day – individually and collectively – to drive meaningful change through our words, our deeds and our culture. Our Work Appropriately philosophy supports our foundation of inclusion and provides employees the flexibility to work where they can have the greatest impact on achieving our goals, dependent on role needs. Every day, we want every employee, no matter their background, ethnicity, preferences, or location, to feel they belong to one General Motors team.

Benefits Overview

The goal of the General Motors total rewards program is to support the health and well-being of you and your family. Our comprehensive compensation plan incudes, the following benefits, in addition to many others:
• Paid time off including vacation days, holidays, and parental leave for mothers, fathers and adoptive parents;
• Healthcare (including a triple tax advantaged health savings account and wellness incentive), dental, vision and life insurance plans to cover you and your family;
• Company and matching contributions to 401K savings plan to help you save for retirement;
• Global recognition program for peers and leaders to recognize and be recognized for results and behaviors that reflect our company values; 
• Tuition assistance and student loan refinancing;
• Discount on GM vehicles for you, your family and friends.

Diversity Information

General Motors is committed to being a workplace that is not only free of discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that workforce diversity creates an environment in which our employees can thrive and develop better products for our customers.   We understand and embrace the variety through which people gain experiences whether through professional, personal, educational, or volunteer opportunities. GM is proud to be an equal opportunity employer.

We encourage interested candidates to review the key responsibilities and qualifications and apply for any positions that match your skills and capabilities.

Equal Employment Opportunity Statements

The policy of General Motors is to extend opportunities to qualified applicants and employees on an equal basis regardless of an individual's age, race, color, sex, religion, national origin, disability, sexual orientation, gender identity/expression or veteran status. Additionally, General Motors is committed to being an Equal Employment Opportunity (EEO) Employer and offers opportunities to all job seekers including individuals with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, email us at Careers.Accommodations@GM.com or call us at 800-865-7580. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.