Staff Cybersecurity Software Engineer
General Motors · United States · 2026-08-08
About this role
Job Description
The Role:
We’re looking for aSecurity Software Engineerto join the Security Products Engineering team and drive the design and implementation of security-focused software and services across GM. You will lead and contribute to the engineering of platforms, services, and tooling that enable secure-by-default experiences for developers and end users, with a strong emphasis on high-quality software architecture, coding standards, and automation.
You will work as a hands-on engineer: designing systems, writing code, reviewing designs and implementations, and partnering with teams across GM to embed security into the software development lifecycle.
What You'll Do:
• Design, build, and maintain security-focused software components, services, and tools used across GM’s application ecosystem.
• Develop automation frameworks and internal platforms that make it easy for product teams to adopt secure patterns (e.g., identity, authorization, secrets management, logging).
• Integrate security controls and checks into CI/CD pipelines, build systems, and cloud-native deployment workflows.
• Architect and implement resilient, scalable security services and APIs (e.g., authentication, authorization, policy evaluation, event ingestion).
• Collaborate with application, infrastructure, and platform engineering teams to embed security requirements into system and service designs.
• Perform secure code reviews, threat modeling, and design reviews to identify and remediate vulnerabilities early in the SDLC.
• Build and maintain systems for security telemetry: logging, metrics, and alerting that support detection, triage, and incident response.
• Contribute to incident response and post-incident reviews as an engineering owner for security services and tooling.
• Stay current with emerging security threats, vulnerabilities, and technologies, and translate them into concrete engineering requirements, patterns, and roadmaps.
• Provide technical mentorship on secure coding, design patterns, and security architecture to other software engineers.
Your Skills & Abilities (Required Qualifications):
• Bachelor’s degree or higher in Computer Science, Software Engineering, Cybersecurity, or a related technical field (or equivalent practical experience).
• 7+ years of experience as a software engineer building and owning production systems or in-house applications.
• Advanced proficiency in at least one modern programming language (for example: Python, Go, Java, or C++) with a strong understanding of software engineering fundamentals (data structures, algorithms, design patterns).
• Experience using AI-assisted development tools (for example, GitHub Copilot, Cursor, or similar) as part of day-to-day engineering workflows.
• Experience designing, implementing, and operating services on a major cloud platform (AWS, Azure, or GCP), including use of managed services and infrastructure-as-code.
• Hands-on experience with containerization and orchestration technologies (e.g., Docker, Kubernetes).
• Solid understanding of core security concepts as applied to software engineering, including:
• Authentication and authorization patterns (OAuth2/OIDC, SSO, RBAC/ABAC).
• Encryption in transit and at rest, key/secrets management.
• Secure coding practices, input validation, and common vulnerability classes (e.g., injection, XSS, CSRF, insecure direct object references).
• Experience partnering with security and audit/compliance teams and translating security requirements into engineering work.
• Proven ability to plan and manage work in an Agile environment, taking ownership of features and services from design through production.
• Strong written and verbal communication skills, with the ability to explain identity and security concepts to both technical and non-technical audiences.
What Will Give You A Competitive Edge (Preferred Qualifications):
• Experience designing or implementing identity and access management (IAM) solutions, including external/partner identity, contractor-heavy environments, or B2B/B2C identity patterns.
• Project experience modeling and deploying external identity architectures (e.g., federation, multi-tenant identity, just-in-time provisioning).
• Experience with data and analytics platforms (e.g., Databricks) or broader Microsoft/Google cloud product ecosystems.
• Experience integrating cloud access security broker (CASB) or similar security technologies into applications or platforms.
• Experience with modern front-end application development (e.g., React, TypeScript) and securing front-end/back-end interactions.
• Track record of leading engineering initiatives that improved security posture through better design, automation, or developer experience.
Compensation: The compensation information is a good faith estimate only. It is based on what a successful applicant might be paid in accordance with applicable state laws. The actual base salary a successful candidate will be offered within this range will vary based on factors relevant to the position, as well as geography of the selected candidate.
• The salary range for this role is $160,200-$246,300. The actual base salary a successful candidate will be offered within this range will vary based on factors relevant to the position.
• Bonus Potential: An incentive pay program offers payouts based on company performance, job level, and individual performance.
Benefits:
Benefits: GM offers a variety of health and wellbeing benefit programs. Benefit options include medical, dental, vision, Health Savings Account, Flexible Spending Accounts, retirement savings plan, sickness and accident benefits, life insurance, paid vacation & holidays, tuition assistance programs, employee assistance program, GM vehicle discounts and more.
GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes…
Skills asked for
- cybersecurity
- ci/cd
- python
- go
- java
- c++
- aws
- azure
Similar jobs
- Member of Technical Staff - Cybersecurity CapabilitiesPreference Model · San Francisco
- Staff Cybersecurity Specialist – Incident Response (f/m/x)Eye Security · The Hague - hybrid
- Staff Cybersecurity Evangelist - GTM, DACH (f/m/x)Eye Security · Berlin - remote
- Staff Cybersecurity Controls SpecialistSoFi · New York City
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.