Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Principal Cybersecurity Engineer, Threat and Vulnerability

AT GM Financial
GM Financial

Principal Cybersecurity Engineer, Threat and Vulnerability

Fort Worth, TX

JOB DESCRIPTION

Hybrid work environment: 4 days onsite and 1 day remote

Why GM Financial Cybersecurity?

The GMF Cybersecurity team is tasked with the security engineering, regulatory response, third party risk, and incident response capabilities necessary to secure GM Financial, the captive auto finance subsidiary of General Motors. Reporting directly to the CEO, our Cybersecurity team enjoys unprecedented support to deliver the highest level of security capabilities using cutting edge technologies and automating mundane tasks, allowing our teams to focus on interesting and rewarding security work. As a part of GM, you'll have the opportunity to work on Cybersecurity projects across financial services, automotive, manufacturing, high-tech, and military industries. We are looking for team players who want the freedom to innovate leading edge capabilities to join our growing Cybersecurity team.

Want more jobs like this?

Get jobs delivered to your inbox every week.

Select a location
By signing up, you agree to our Terms of Service & Privacy Policy.


RESPONSIBILITIES

About the Role:

The Principal of Vulnerability Management is highly skilled and detail-oriented in the art of Cybersecurity Vulnerability Management. This role is responsible for identifying, assessing, analyzing, prioritizing, and coordinating security vulnerabilities across our IT infrastructure, business applications, and cloud environments. The ideal candidate must have a strong technical background in information technology, cybersecurity, vulnerability scanning tools, and risk assessment methodologies. The ideal candidate must be able to assess all vulnerability risks and accurately articulate and document for both technical and non-technical team members the risk level, impacts, and options for remediation and or mitigation of the risk.

In this role, you will:

  • Support technical direction for vulnerability and scanning supporting technology
  • Build and maintain scalable vulnerability detection rules, alerts, scripts, and triage pipelines
  • Monitor and assess the company's cybersecurity risks and implement mitigation strategies to address vulnerabilities
  • Conduct continuous discovery and vulnerability assessment of enterprise-wide assets, including vulnerability scans in support of operational matters (non-scheduled)
  • Serve as a technical escalation point for vulnerability management and remediation efforts
    Build and apply protective mitigations teams to integrate fixes upstream, and to support remediation efforts to close vulnerability exposure to new threats
  • Interpret complex data from vulnerability scans to pinpoint potential security risks and weaknesses
  • Examine disclosed vulnerabilities, threat scenarios, and mitigating controls
  • Implement technical recommendations for addressing and mitigating identified vulnerabilities
  • Perform technical analysis of all scan results and provide a report of analysis as required


QUALIFICATIONS

What Makes You A Dream Candidate?

  • Experience with leading initiatives from start to finish
  • Strong knowledge of business acumen and a deep understanding of business implications of decisions
  • Strong understanding of company values, mission, vision and strategic direction
  • Thorough knowledge of GM Financials' business operations
  • Recognized as a subject matter expert in area(s) of specialty
  • Experience in threat modeling, secure design, and code review processes
  • Demonstrated knowledge of Windows, Linux, Unix, and other operating system's vulnerabilities and ways to remediate and/or mitigate
  • Demonstrated knowledge in methods to protect against ransomware threats
  • Experience building and utilizing highly scalable platforms and tools (e.g., Vulnerability scanners, detection pipelines, analytics systems)
  • Ability to aggregate and report on data, utilizing data visualization techniques
  • Experience securing hybrid/multi cloud environments (Azure, AWS)
    Experience building vulnerability tooling and automations integrated into workflows
  • Understanding of the vulnerability risk landscape and its impact on cyber threats
  • Working experience prioritizing vulnerability remediation
    Experience performing risk assessments of vulnerabilities and evaluating compensating and mitigating controls
  • Experience building and operating Vulnerability Management, Threat Intelligence, or other security programs
  • Knowledge of secure coding practices and application security testing (SAST, DAST, SCA, IaC, etc).
  • Experience with Python, REST, Node, SWL, and other popular coding languages
  • Familiarity of computer networking operations, TCP/IP networking, network fabrics, OSI layers, and corporate networking devices and their operating systems.
  • Comfortability with DevSecOps and CI/CD methodologies
  • Familiarity with securing container-based systems (Docker, Kuberntes, etc)
  • Understanding of CVE, CVSS scoring, CWE, MitRE ATT&CK Framework, threat intelligence, and CISA
  • Possess strong analytical, written, and verbal communication and documentation skills.

Experience:

  • Related certifications and/or licenses required
  • Member of and recommendation by accredited association in related field preferred
  • Greater than 10 years in related function required
  • 3-5 years leading through mentorship in related field required
  • 3-5 years leading projects and initiatives through influence required
  • High School Diploma or equivalent required
  • Associate Degree or High School Equivalent plus 2 additional years of related experience required

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), training, GM employee auto discount, community service pay and nine company holidays.

Our Culture: Our team members define and shape our culture. We have an environment that welcomes new ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work - we thrive.

Compensation: Competitive salary and bonus eligibility; this role is eligible for company vehicle program

Work Life Balance: Flexible hybrid work environment, 4-days a week in office

#LI-hybrid

#GMFjobs

#LI-KC1

Client-provided location(s): Fort Worth, TX, USA; Arlington, TX, USA
Job ID: GM_Financial-498
Employment Type: Full Time

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • Short-Term Disability
    • Long-Term Disability
    • FSA
    • FSA With Employer Contribution
    • HSA
    • HSA With Employer Contribution
    • Mental Health Benefits
    • Fitness Subsidies
  • Parental Benefits

    • Birth Parent or Maternity Leave
    • Non-Birth Parent or Paternity Leave
    • Adoption Leave
  • Work Flexibility

    • Remote Work Opportunities
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Happy Hours
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
    • Volunteer Time Off
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Profit Sharing
  • Professional Development

    • Tuition Reimbursement
    • Promote From Within
    • Mentor Program
    • Shadowing Opportunities
    • Access to Online Courses
    • Lunch and Learns
    • Internship Program
    • Leadership Training Program
  • Diversity and Inclusion

    • Unconscious Bias Training
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at GM Financial.