描述
The Role:
We’re looking for a Security Software Engineer to join the Security Products Engineering team and drive the design and implementation of security-focused software and services across GM. You will lead and contribute to the engineering of platforms, services, and tooling that enable secure-by-default experiences for developers and end users, with a strong emphasis on high-quality software architecture, coding standards, and automation.
You will work as a hands-on engineer: designing systems, writing code, reviewing designs and implementations, and partnering with teams across GM to embed security into the software development lifecycle.
What You'll Do:
-
Design, build, and maintain security-focused software components, services, and tools used across GM’s application ecosystem.
-
Develop automation frameworks and internal platforms that make it easy for product teams to adopt secure patterns (e.g., identity, authorization, secrets management, logging).
-
Integrate security controls and checks into CI/CD pipelines, build systems, and cloud-native deployment workflows.
-
Architect and implement resilient, scalable security services and APIs (e.g., authentication, authorization, policy evaluation, event ingestion).
-
Collaborate with application, infrastructure, and platform engineering teams to embed security requirements into system and service designs.
-
Perform secure code reviews, threat modeling, and design reviews to identify and remediate vulnerabilities early in the SDLC.
-
Build and maintain systems for security telemetry: logging, metrics, and alerting that support detection, triage, and incident response.
-
Contribute to incident response and post-incident reviews as an engineering owner for security services and tooling.
-
Stay current with emerging security threats, vulnerabilities, and technologies, and translate them into concrete engineering requirements, patterns, and roadmaps.
-
Provide technical mentorship on secure coding, design patterns, and security architecture to other software engineers.
Your Skills & Abilities (Required Qualifications):
-
Bachelor’s degree or higher in Computer Science, Software Engineering, Cybersecurity, or a related technical field (or equivalent practical experience).
-
7+ years of experience as a software engineer building and owning production systems or in-house applications.
-
Advanced proficiency in at least one modern programming language (for example: Python, Go, Java, or C++) with a strong understanding of software engineering fundamentals (data structures, algorithms, design patterns).
-
Experience using AI-assisted development tools (for example, GitHub Copilot, Cursor, or similar) as part of day-to-day engineering workflows.
-
Experience designing, implementing, and operating services on a major cloud platform (AWS, Azure, or GCP), including use of managed services and infrastructure-as-code.
-
Hands-on experience with containerization and orchestration technologies (e.g., Docker, Kubernetes).
-
Solid understanding of core security concepts as applied to software engineering, including:
-
Authentication and authorization patterns (OAuth2/OIDC, SSO, RBAC/ABAC).
-
Encryption in transit and at rest, key/secrets management.
-
Secure coding practices, input validation, and common vulnerability classes (e.g., injection, XSS, CSRF, insecure direct object references).
-
Experience partnering with security and audit/compliance teams and translating security requirements into engineering work.
-
Proven ability to plan and manage work in an Agile environment, taking ownership of features and services from design through production.
-
Strong written and verbal communication skills, with the ability to explain identity and security concepts to both technical and non-technical audiences.
What Will Give You A Competitive Edge (Preferred Qualifications):
-
Experience designing or implementing identity and access management (IAM) solutions, including external/partner identity, contractor-heavy environments, or B2B/B2C identity patterns.
-
Project experience modeling and deploying external identity architectures (e.g., federation, multi-tenant identity, just-in-time provisioning).
-
Experience with data and analytics platforms (e.g., Databricks) or broader Microsoft/Google cloud product ecosystems.
-
Experience integrating cloud access security broker (CASB) or similar security technologies into applications or platforms.
-
Experience with modern front-end application development (e.g., React, TypeScript) and securing front-end/back-end interactions.
-
Track record of leading engineering initiatives that improved security posture through better design, automation, or developer experience.
Compensation: The compensation information is a good faith estimate only. It is based on what a successful applicant might be paid in accordance with applicable state laws. The actual base salary a successful candidate will be offered within this range will vary based on factors relevant to the position, as well as geography of the selected candidate.
• The salary range for this role is $160,200-$246,300. The actual base salary a successful candidate will be offered within this range will vary based on factors relevant to the position.
• Bonus Potential: An incentive pay program offers payouts based on company performance, job level, and individual performance.
Benefits:
Benefits: GM offers a variety of health and wellbeing benefit programs. Benefit options include medical, dental, vision, Health Savings Account, Flexible Spending Accounts, retirement savings plan, sickness and accident benefits, life insurance, paid vacation & holidays, tuition assistance programs, employee assistance program, GM vehicle discounts and more.
#LI-SB3
GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc.)
Renseignements sur la diversité
General Motors est résolue à être un lieu de travail qui est non seulement exempt de discrimination illégale, mais aussi un endroit qui favorise véritablement l'inclusion et l'appartenance. Nous sommes convaincus que la diversité de la main-d'œuvre permet de créer un environnement dans lequel nos employés peuvent s'épanouir et développer de meilleurs produits pour nos clients. Nous encourageons les candidats intéressés à consulter les principales responsabilités et compétences requises pour chaque rôle et à postuler à tout poste qui leur correspond. Dans le cadre du processus de recrutement, les candidats peuvent devoir, le cas échéant, réussir une évaluation liée au poste ou une présélection d'emploi avant d'être embauchés. Pour en savoir plus, consultez notre processus de recrutement.
Déclaration concernant l'égalité d'accès à l'emploi (É.-U.)
General Motors est fière d'être un employeur souscrivant au principe de l'égalité d'accès à l'emploi. Tous les candidats qualifiés seront pris en compte, sans égard à la race, à la couleur, à la religion, au sexe, à l'orientation sexuelle, à l'identité de genre, à l'origine ethnique, aux situations de handicap ou au statut protégé d'ancien combattant.
Aménagements (É.-U. et Canada)
General Motors offre des occasions à tous les chercheurs d'emploi, y compris les personnes handicapées. Si vous avez besoin d'un accommodement raisonnable pour vous aider dans votre recherche d'emploi ou la soumission de votre candidature, envoyez-nous un courriel à l'adresse [email protected] ou appelez-nous au 800 865-7580. Veuillez inclure dans votre courriel une description spécifique du type d'accommodement demandé, ainsi que le titre d'emploi et le numéro de demande du poste auquel vous postulez.
