Job Description
The Role
The Staff Product Cybersecurity Engineer, Offensive Product Security role sits within the broader Product Cybersecurity organization at General Motors and focuses on offensive security services that help strengthen confidence in the security of our product portfolio. Through penetration testing, red-team activity, and security research, this engineer helps identify meaningful weaknesses in software, systems, and product implementations across embedded vehicle software, mobile experiences, and product-backed software and services. This role works closely with product teams to assess real-world attack paths, validate risk, and provide actionable findings that help find areas to mature in our secure SDLC.
What You'll Do
Perform penetration testing across software, systems, and product environments
Conduct security research that targets meaningful product and technology risks
Execute offensive assessments across embedded, mobile, and backend environments
Identify vulnerabilities, validate impact, and provide clear remediation guidance
Partner with engineering teams to improve security through practical technical findings
Help strengthen offensive methods, tooling, and testing approaches across the portfolio
Your Skills & Abilities (Required Qualifications)
8+ years of experience in penetration testing, product security, security research, or similar roles
Deep expertise in offensive security testing across applications, software, and systems
Experience with penetration testing, red-team activity, vulnerability research, and exploit validation
Familiarity with embedded security, operating system security, application security, and networking
Able to read-and-write software in a variety of languages to support investigation and tooling
Strong ability to communicate technical findings and work directly with engineers on remediation
What Will Give You A Competitive Edge (Preferred Qualifications)
Prior role(s) in the automotive industry or a similarly complex, deadline driven, and regulated field
Direct experience working on automotive security in any relevant role across the secure SDLC
Published cybersecurity research projects (e.g. conference talks, blog posts, code repositories)
Experience building custom offensive tooling or extending existing security testing capabilities
What You'll Bring
Deep technical curiosity and strong offensive security instincts across complex product focuses
A rigorous and detail-oriented approach to technical investigation and exploit validation
Clear judgment on risk, exploitability, and practical impact across software and systems
The ability to work independently on complex technical problems and ambiguous attack surfaces
A commitment to helping engineers improve security through detailed, risk-ranked findings
#LI-SB3


GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc).

This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}.

This job may be eligible for relocation benefits.

About GM
Our vision is a world with Zero Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more equitable for all.
Why Join Us
We believe we all must make a choice every day – individually and collectively – to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team.
Benefits Overview
From day one, we're looking out for your well-being–at work and at home–so you can focus on realizing your ambitions. Learn how GM supports a rewarding career that rewards you personally by visiting Total Rewards resources.
Non-Discrimination and Equal Employment Opportunities (U.S.)
General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.
All employment decisions are made on a non-discriminatory basis without regard to sex, race, color, national origin, citizenship status, religion, age, disability, pregnancy or maternity status, sexual orientation, gender identity, status as a veteran or protected veteran, or any other similarly protected status in accordance with federal, state and local laws.
We encourage interested candidates to review the key responsibilities and qualifications for each role and apply for any positions that match their skills and capabilities. Applicants in the recruitment process may be required, where applicable, to successfully complete a role-related assessment(s) and/or a pre-employment screening prior to beginning employment. To learn more, visit How we Hire.
Accommodations
General Motors offers opportunities to all job seekers including individuals with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, email us or call us at 1-800-865-7580. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.