Manager, Offensive Security
About the role
The Offensive Security function at General Motors helps strengthen the company's mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback loops that help teams reduce risk before it becomes customer impact.
Responsibilities
- Lead and develop a team responsible for penetration testing, adversary emulation, responsible disclosure triage, and verification of security controls across applications, platforms, and services.
- Own the function roadmap, operating model, and key performance indicators, including coverage, remediation velocity, validation quality, and risk reduction outcomes.
- Translate Cybersecurity strategy into quarterly priorities, staffing plans, resource allocation decisions, and clear execution goals for the team.
- Partner with engineering and platform teams to turn offensive security findings into remediation actions, prevention improvements, and stronger secure-by-design practices.
- Establish scalable testing approaches for web, API, cloud, identity, container, and software delivery environments, balancing depth, speed, and business risk.
- Drive stakeholder communication, cross-functional alignment, and change leadership, including escalation of significant risks and recommendations for action.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
- 10+ years of cybersecurity experience, including 5+ years in offensive security, penetration testing, red teaming, application security testing, or closely related disciplines.
- 5+ years of people leadership experience, including hiring, performance management, coaching, workforce planning, and team development.
- 3+ years leading complex, cross-functional security programs with measurable outcomes across multiple product, software, or platform teams.
- Experience assessing or testing modern attack surfaces such as web applications, APIs, cloud services, identity systems, containers, developer tooling, or software delivery pipelines.
- Demonstrated ability to define key performance indicators, prioritize competing work, communicate risk to technical and business stakeholders, and drive remediation to closure.
Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
- 10+ years of cybersecurity experience, including 5+ years in offensive security, penetration testing, red teaming, application security testing, or closely related disciplines.
- 5+ years of people leadership experience, including hiring, performance management, coaching, workforce planning, and team development.
- 3+ years leading complex, cross-functional security programs with measurable outcomes across multiple product, software, or platform teams.
- Experience assessing or testing modern attack surfaces such as web applications, APIs, cloud services, identity systems, containers, developer tooling, or software delivery pipelines.
- Demonstrated ability to define key performance indicators, prioritize competing work, communicate risk to technical and business stakeholders, and drive remediation to closure.
Skills
- Experience building or leading offensive security programs in large-scale software, cloud, or product engineering environments.
- Familiarity with responsible disclosure, vulnerability intake, or bug bounty program operations.
- Experience partnering with development teams to improve secure design, detection, and resilience based on offensive testing results.
- Knowledge of security automation, findings workflows, and telemetry-driven reporting.
- Relevant industry certifications such as OSCP, OSWE, GPEN, GXPN, CISSP, or comparable credentials.
- Experience in highly regulated, safety-critical, or large enterprise environments.
Benefits
General Motors offers competitive compensation packages, comprehensive health and wellness benefits, retirement savings options, and opportunities for professional growth and development. Please refer to the Benefits Overview for more details.
Pay
Compensation for this role is competitive and commensurate with experience and qualifications. Please refer to the Benefits Overview for more details.
Schedule
This role is categorized as hybrid. The selected candidate is expected to report to a specific location at least 3 times a week, as dictated by their manager.