Staff Product Cybersecurity Engineer - Secure Product Engineering
General Motors
- Location
- Milford Michigan United States of America
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 267 approvals (FY2023)
- Posted
- 1d ago
Skills
About this role
Job Description
The Role The Staff Product Cybersecurity Engineer, Secure Product Engineering is a senior individual contributor within the Secure Product Engineering pillar of General Motors’ Product Cybersecurity organization. This role helps make secure implementation an integrated, repeatable part of how GM builds products. Through close, hands-on partnership with product engineering teams, the Staff Engineer ensures that software and systems are implemented securely as products and features move through the build phase of development. The role supports GM’s broad product portfolio, including embedded vehicle software, vehicle platforms and operating systems, mobile experiences, cloud services, APIs, and other connected software and services. As a technical leader without direct reports, this engineer earns influence through technical credibility, direct execution, mentorship, and a practical approach to solving difficult security problems. They personally build and mature the tooling, reusable patterns, technical guidance, and secure-engineering workflows that enable product teams to deliver secure software efficiently and consistently. Secure Product Engineering provides high-touch, integrated support to product teams while improving automated security capabilities that allow engineers to move quickly and confidently. This role works closely with Product Threat Assessment, Secure Product Architecture, Product Security Validation, Offensive Product Security, Product Security Operations Center, Enterprise Application Security, and product engineering teams to ensure security intent is carried from design into implementation and sustained through delivery. What You’ll Do Serve as a hands-on technical leader for secure software and systems engineering, driving outcomes through direct execution, trusted partnership, and influence rather than people management. Establish embedded working relationships with product engineering teams and act as a technically credible security partner throughout development. Design, build, deploy, and mature scalable secure-engineering services and capabilities that help teams identify and remediate security issues early. Implement and improve application-security practices across product environments, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis, fuzzing, runtime security, secure code review, and operating-system hardening. Develop reusable secure coding patterns, reference implementations, guardrails, libraries, automation, and technical standards that make the secure path the easiest path for engineers. Perform in-depth code, configuration, architecture, and design reviews to identify material vulnerabilities, implementation gaps, insecure dependencies, and opportunities for preventive controls. Translate cybersecurity requirements, threat-model outputs, and secure architecture decisions into clear, actionable implementation guidance for engineering teams. Build or extend security tooling, integrations, dashboards, and workflows that improve developer experience, improve visibility into security risk, and enable consistent evidence of security execution. Partner with Enterprise Application Security and adjacent teams to align toolchains, reduce duplication, and extend enterprise capabilities where product-specific needs require additional depth. Work with Product Threat Assessment and Secure Product Architecture to ensure changes in product implementation are reflected in threat assumptions, architecture decisions, security requirements, and downstream validation activities. Partner with Product Security Validation and Offensive Product Security to address recurring findings, improve remediation quality, and feed lessons learned back into engineering patterns and automated controls. Help engineering teams prioritize vulnerabilities and technical debt based on exploitability, product context, customer