Descrição
The Role
The Cyber Security Engineer – PKI & Secrets Management acts as a senior domain expert for PKI and secrets, providing technical leadership, hands-on engineering, and cross-team guidance for certificate lifecycle management, key management, hardware security modules (HSMs), and enterprise secrets platforms. The role partners closely with Security Services, infrastructure, cloud, application, and product teams to ensure cryptographic services are reliable, scalable, and aligned with GM security standards and regulatory requirements.
What You’ll Do
-
Serve as the primary subject matter expert for at least one major PKI or secrets platform (e.g., enterprise CAs, HSM-backed key management, or central secrets management platform), including strategy, architecture, and day-to-day engineering
-
Design, implement, and maintain certificate lifecycle management solutions supporting servers, applications, devices, and services across on‑prem and cloud environments
-
Engineer, harden, and operate PKI components, including root and subordinate CAs, OCSP/CRL infrastructure, key storage, and associated monitoring and audit capabilities
-
Lead design and integration of secrets management patterns (e.g., application secrets, API keys, database credentials, service identities), driving standardization and automation for onboarding new use cases
-
Define and document PKI and secrets management standards, patterns, and reference architectures for use by application and infrastructure teams across GM
-
Provide technical leadership on Cyber Security projects related to identity, access, encryption, and secure connectivity, ensuring PKI and secrets requirements are captured, implemented, and validated
-
Collaborate with software, cloud, and infrastructure teams to embed secure-by-default cryptographic practices (e.g., TLS, mutual auth, certificate pinning, key rotation) in platforms and services
-
Lead root cause analysis and remediation for PKI/secrets-related incidents or outages, driving durable fixes, improved monitoring, and lessons-learned back into standards and runbooks
-
Develop automation and tooling (e.g., scripting, APIs, workflows) to reduce manual certificate and secrets operations, improve consistency, and increase coverage across fleets and environments
-
Participate in threat analysis and risk assessment activities where cryptography, keys, and certificates are central controls, translating findings into practical mitigation plans
-
Mentor and support other engineers on PKI, cryptography, and secrets management topics; provide clear guidance, design reviews, and hands-on assistance to project and platform teams
-
Represent the PKI & Secrets Management domain in internal forums, architecture reviews, and change control, ensuring changes that impact cryptographic services are well understood and properly evaluated
-
Contribute to and help own security metrics and KPIs related to certificate hygiene, secrets lifecycle health, coverage, and platform reliability; drive action plans when targets are not met
-
Lead development and execution of Cyber Security projects where PKI, certificate management, and secrets are primary enablers, from requirements definition through design, implementation, and operational transition
-
Exercise independent judgment on significant cryptographic and platform decisions, balancing security, reliability, and developer experience, and clearly articulating tradeoffs to stakeholders
-
Act as a recognized senior Cyber Security engineer with deep expertise in PKI & secrets and broad knowledge of adjacent areas (identity, network security, cloud security, compliance, and risk)
-
Break complex security and reliability problems into actionable initiatives, orchestrating work across Security Services, infrastructure, and application teams
-
Champion change management by driving adoption of updated PKI roots/intermediates, new secrets patterns, and improved lifecycle processes across legacy and modern platforms
-
Serve as a mentor and go‑to resource for junior and mid-level Cyber Security engineers, modeling GM’s behaviors and engineering best practices
Your Skills & Abilities (Required Qualifications):
-
Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, Information Technology, or a closely related field; or equivalent experience
-
Strong hands-on experience with enterprise PKI concepts and technologies, including: X.509 certificates, key pairs, certificate chains, and trust stores
-
Certificate issuance, renewal, revocation, CRLs/OCSP, and policy definition
-
Operating or integrating with certificate authorities and HSM-backed key storage
-
Practical experience designing or operating secrets management solutions (e.g., application secrets, service identities, API keys, credential rotation patterns) in large-scale environments
-
Solid understanding of network security and secure communications (TLS, mTLS, cipher suites, protocol hardening, certificate validation)
-
Demonstrated ability to own and deliver complex security engineering projects end-to-end with minimal direction, including planning, execution, and stakeholder communication
-
Strong problem-solving skills and experience troubleshooting PKI, certificate, and secrets-related failures in distributed systems
-
Ability to communicate complex technical concepts clearly to both engineers and non-technical partners, and to influence design decisions across teams
-
Demonstrated alignment with GM behaviors (Think Customer, Be Inclusive, It’s on All of Us, Innovate Now, Look Ahead, One Team, Be Bold, Win with Integrity) in day-to-day work
What Will Give You A Competitive Edge (Preferred Qualifications):
-
Experience operating PKI or secrets services in hybrid or multi-cloud environments
-
Familiarity with identity and access management (IAM) platforms, directory services, and authentication/authorization patterns that depend on PKI and secrets
-
Experience developing automation for certificate and secrets lifecycle (scripting, APIs, CI/CD integrations, or configuration management tools)
-
Prior experience in a large enterprise or regulated environment where cryptographic controls support audit, compliance, or regulatory requirements
-
Experience mentoring other engineers or informally leading technical workstreams within a security or infrastructure team
Informações sobre diversidade
A General Motors está comprometida em ser um local de trabalho que não só é livre de discriminação ilegal, como estimula verdadeiramente a inclusão e integração. Acreditamos enfaticamente que a diversidade na força de trabalho cria um ambiente no qual nossos colaboradores podem crescer e desenvolver melhores produtos para nossos clientes. Incentivamos os candidatos interessados a analisar as principais responsabilidades e qualificações de cada função e a se candidatar a qualquer cargo que corresponda a suas habilidades e capacidades. Os candidatos no processo de recrutamento podem, quando aplicável, ser solicitados a concluir com sucesso uma ou mais avaliações relacionadas à função e/ou uma seleção pré-emprego antes de iniciar o emprego. Para saber mais, acesse Como contratamos.
Declaração de Igualdade de Oportunidades de Emprego (EUA)
A General Motors tem orgulho de ser um empregador que oferece oportunidades iguais. Todos os candidatos qualificados serão considerados para o emprego, independentemente de raça, cor, religião, sexo, orientação sexual, identidade de gênero, origem nacional, deficiência ou status como veterano protegido.
Adaptações (EUA e Canadá)
A General Motors oferece oportunidades a todos os candidatos a emprego, incluindo pessoas com deficiências. Se você precisa de uma adaptação razoável para ajudá-lo na sua pesquisa de cargos ou solicitação de emprego, fale conosco pelo e-mail [email protected] ou pelo telefone 800-865-7580. No seu e-mail, inclua uma descrição da adaptação específica que você está solicitando assim como o nome do cargo e o número de requisição do cargo ao qual está se candidatando.
