Staff Product Cybersecurity Engineer - Offensive Product Security
General Motors
- Location
- Milford Michigan United States of America
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 267 approvals (FY2023)
- Posted
- 1d ago
Skills
About this role
Job Description
The Role The Staff Product Cybersecurity Engineer, Offensive Product Security is a senior individual contributor within General Motors’ broader Product Cybersecurity organization, under Mark Stanislav’s Product Cybersecurity leadership organization. This role focuses on offensive security services that strengthen confidence in the security and resilience of GM’s product portfolio. Through hands-on penetration testing, red-team activity, security research, and adversarial analysis, this engineer identifies meaningful weaknesses in software, systems, and product implementations before they can affect customers, vehicles, or GM services. The role assesses real-world attack paths across embedded vehicle software, electronic control units, vehicle networks, mobile experiences, cloud platforms, APIs, backend services, developer tooling, and other product-backed software and services. It partners closely with product engineering teams to validate exploitability, assess practical impact, and deliver clear, risk-ranked remediation guidance. As a technical leader without direct reports, the Staff Engineer earns influence through deep offensive-security expertise, sound technical judgment, direct execution, and trusted partnership with engineering teams. This role also helps mature GM’s offensive security methods, assessment approaches, research priorities, and reusable tooling so lessons from individual assessments improve the broader secure product development lifecycle. Offensive Product Security serves as the “challenge” function in GM’s connected Product Cybersecurity lifecycle, testing the effectiveness of threat assessment, secure architecture, secure engineering, and validation work to uncover gaps and improve resilience across the portfolio. What You’ll Do Serve as a hands-on technical leader for offensive product security, driving outcomes through direct assessment work, technical credibility, and influence rather than people management. Perform penetration testing across product software, systems, services, interfaces, and connected environments. Execute adversarial assessments across embedded vehicle software, vehicle networks, operating systems, mobile applications, APIs, cloud services, backend platforms, and other product environments. Conduct red-team exercises and attacker simulations to evaluate realistic attack paths, exploit chains, security control effectiveness, and product resilience. Perform vulnerability research to identify emerging technology risks, recurring weakness patterns, and areas where GM’s products or development practices can improve. Analyze code, binaries, firmware, hardware interfaces, protocols, configurations, and system designs to identify exploitable weaknesses and validate technical impact. Develop proof-of-concept exploits, attack demonstrations, and technical evidence that clearly establish exploitability, business relevance, customer impact, and remediation priority. Identify vulnerabilities; evaluate severity, reachability, exploitability, and practical risk; and provide clear, actionable remediation guidance to product engineering teams. Partner directly with engineering teams to reproduce findings, explain root causes, validate fixes, and ensure mitigations address the underlying security issue. Work with Secure Product Engineering to translate recurring offensive findings into secure coding patterns, automated controls, tooling improvements, and preventive engineering guidance. Work with Product Threat Assessment and Secure Product Architecture to identify gaps in assumptions, attack models, requirements, and design decisions that should be strengthened in future product work. Partner with Product Security Validation to improve test coverage, regression testing, and evidence of security effectiveness for material findings. Build, extend, and maintain offensive security tooling, test harnesses, fuzzing frameworks, attack automation, research