Manager, Software Supply Chain Security
General Motors · Austin, TX · Yesterday
HybridManagementFull-time
About the role
This role is ideal for a leader who can turn strategy into execution, build strong teams, and partner across engineering to make secure delivery easier at scale.
Responsibilities
- Lead the strategy, roadmap, and day-to-day operation of GM's Software Supply Chain Security function.
- Build, develop, and lead a high-performing team, including hiring, coaching, performance management, and workforce planning.
- Own security outcomes and key performance indicators for code dependency risk, software bill of materials coverage, third-party software security, pipeline controls, and container security.
- Drive cross-functional decisions with engineering, platform, cloud, infrastructure, procurement, and risk teams to embed secure-by-design controls into delivery workflows.
- Establish and improve policies, standards, and reusable guardrails for open-source software use, software provenance, build integrity, artifact security, and developer tooling.
- Prioritize investments, allocate resources, and lead change initiatives that improve security effectiveness, operational consistency, and developer experience.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
- 8+ years of experience in cybersecurity, application security, platform security, software engineering, or a closely related technical field.
- 3+ years of people leadership experience, including hiring, coaching, performance management, and organizational planning.
- 3+ years of experience leading or owning programs in software supply chain security, secure software delivery, build pipeline security, container security, or third-party software risk.
- Demonstrated experience working across 2 or more technical domains such as source control, build systems, artifact repositories, cloud platforms, containers, developer tooling, or software governance.
- Experience defining, tracking, and improving operational metrics and key performance indicators for a technical or security function.
- Proven ability to influence cross-functional stakeholders and drive decisions on significant technical and operational matters.
Qualifications
- Advanced degree in Cybersecurity, Computer Science, Engineering, Business, or a related field (preferred).
- Experience leading software supply chain security in a large, complex enterprise environment (preferred).
- Experience with software bill of materials programs, open-source software governance, software composition analysis, artifact signing, or build provenance (preferred).
- Experience with developer platforms, continuous integration and delivery pipelines, container platforms, cloud-native environments, or integrated development environment governance (preferred).
- Experience leading transformation initiatives that balance security, reliability, usability, and speed for engineering teams (preferred).
Skills & Abilities
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
- 8+ years of experience in cybersecurity, application security, platform security, software engineering, or a closely related technical field.
- 3+ years of people leadership experience, including hiring, coaching, performance management, and organizational planning.
- 3+ years of experience leading or owning programs in software supply chain security, secure software delivery, build pipeline security, container security, or third-party software risk.
- Demonstrated experience working across 2 or more technical domains such as source control, build systems, artifact repositories, cloud platforms, containers, developer tooling, or software governance.
- Experience defining, tracking, and improving operational metrics and key performance indicators for a technical or security function.
- Proven ability to influence cross-functional stakeholders and drive decisions on significant technical and operational matters.