설명
At General Motors, we are building secure software and connected experiences at scale. The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback loops that help teams reduce risk before it becomes customer impact.
This team helps uncover exploitable weaknesses, verify how well controls are performing, and provide actionable insights that improve remediation and prevention. This role is ideal for a leader who can grow a high-performing team, turn strategy into execution, and raise the security bar across a complex engineering environment.
The Role
As Manager, Offensive Security, you will lead a distinct Cybersecurity function responsible for validating how well our products, platforms, and engineering controls stand up to real-world attacks. You will set direction for offensive security programs, translate enterprise priorities into team goals, and make operational decisions about talent, capacity, tooling, and delivery. You will partner closely with engineering, product, infrastructure, and Cybersecurity leaders to prioritize risk, improve remediation outcomes, and strengthen preventative controls. You will help shape scalable testing approaches that balance speed, depth, and business impact. This is a high-impact leadership role for someone who can build talent, influence across organizations, and lead change through measurable outcomes.
What You’ll Do
- Lead and develop a team responsible for penetration testing, adversary emulation, responsible disclosure triage, and verification of security controls across applications, platforms, and services.
- Own the function roadmap, operating model, and key performance indicators, including coverage, remediation velocity, validation quality, and risk reduction outcomes.
- Translate Cybersecurity strategy into quarterly priorities, staffing plans, resource allocation decisions, and clear execution goals for the team.
- Partner with engineering and platform teams to turn offensive security findings into remediation actions, prevention improvements, and stronger secure-by-design practices.
- Establish scalable testing approaches for web, API, cloud, identity, container, and software delivery environments, balancing depth, speed, and business risk.
- Drive stakeholder communication, cross-functional alignment, and change leadership, including escalation of significant risks and recommendations for action.
Your Skills & Abilities (Required Qualifications)
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
- 10+ years of cybersecurity experience, including 5+ years in offensive security, penetration testing, red teaming, application security testing, or closely related disciplines.
- 5+ years of people leadership experience, including hiring, performance management, coaching, workforce planning, and team development.
- 3+ years leading complex, cross-functional security programs with measurable outcomes across multiple product, software, or platform teams.
- Experience assessing or testing modern attack surfaces such as web applications, APIs, cloud services, identity systems, containers, developer tooling, or software delivery pipelines.
- Demonstrated ability to define key performance indicators, prioritize competing work, communicate risk to technical and business stakeholders, and drive remediation to closure.
What Will Give You A Competitive Edge (Preferred Qualifications)
- Experience building or leading offensive security programs in large-scale software, cloud, or product engineering environments.
- Familiarity with responsible disclosure, vulnerability intake, or bug bounty program operations.
- Experience partnering with development teams to improve secure design, detection, and resilience based on offensive testing results.
- Knowledge of security automation, findings workflows, and telemetry-driven reporting.
- Relevant industry certifications such as OSCP, OSWE, GPEN, GXPN, CISSP, or comparable credentials.
- Experience in highly regulated, safety-critical, or large enterprise environments.
GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc.)
이 직무는 하이브리드 직무로 분류됩니다. 즉, 선발된 지원자는 특정 근무지로 주 3일 이상(또는 관리자가 지정한 다른 빈도로) 특정 근무지로 출근해야 합니다.
이 직무는 리로케이션 혜택을 받을 수 있습니다.
다양성 정보
General Motors는 법적으로 금지된 차별을 배제하는 것은 물론 포용성과 소속감을 진정으로 장려하는 직장이 되기 위해 노력하고 있습니다. 당사는 다양성이 보장되는 환경에서 직원들이 역량을 발휘하고 우리 고객을 위한 더 좋은 제품을 개발할 수 있다고 믿습니다. 따라서 입사에 관심 있는 사람이 있다면 포지션별 주요 업무와 자격을 확인하고 본인이 보유한 기술과 능력에 부합하는 모든 포지션에 적극적으로 지원하기를 장려합니다. 지원자는 채용 과정에서 역할 관련 평가(해당하는 경우) 및/또는 채용 전 스크리닝을 통과해야 합니다. 자세한 정보는 GM 채용 과정 안내를 참고하십시오.
공평한 취업 기회 선언 (미국)
General Motors는 공평한 기회를 제공하는 고용주임을 자부합니다. 자격을 만족하는 지원자는 인종과 피부색, 성별, 성적 지향, 성별 정체성, 국적, 장애, 재향 군인 보호법 적용 여부와 상관없이 채용 후보로서 심사를 받습니다.
숙소 (미국 및 캐나다)
General Motors는 장애인을 포함한 모든 구직자들에게 취업 기회를 제공합니다. 구직이나 취업 지원에 도움이 되는 합리적인 숙소가 필요한 경우 [email protected]으로 이메일을 보내시거나 800-865-7580으로 전화주십시오. 이메일에, 귀하가 요청하는 특정한 숙소에 대한 설명과 귀하가 지원하는 직무와 채용 요청서 번호를 포함해주세요.
