Staff Cybersecurity Software Engineer
Job Description
The Role:
We’re looking for a Security Software Engineer to join the Security Products Engineering team and drive the design and implementation of security-focused software and services across GM. You will lead and contribute to the engineering of platforms, services, and tooling that enable secure-by-default experiences for developers and end users, with a strong emphasis on high-quality software architecture, coding standards, and automation.
You will work as a hands-on engineer: designing systems, writing code, reviewing designs and implementations, and partnering with teams across GM to embed security into the software development lifecycle.
What You'll Do:
-
Design, build, and maintain security-focused software components, services, and tools used across GM’s application ecosystem.
-
Develop automation frameworks and internal platforms that make it easy for product teams to adopt secure patterns (e.g., identity, authorization, secrets management, logging).
-
Integrate security controls and checks into CI/CD pipelines, build systems, and cloud-native deployment workflows.
-
Architect and implement resilient, scalable security services and APIs (e.g., authentication, authorization, policy evaluation, event ingestion).
-
Collaborate with application, infrastructure, and platform engineering teams to embed security requirements into system and service designs.
-
Perform secure code reviews, threat modeling, and design reviews to identify and remediate vulnerabilities early in the SDLC.
-
Build and maintain systems for security telemetry: logging, metrics, and alerting that support detection, triage, and incident response.
-
Contribute to incident response and post-incident reviews as an engineering owner for security services and tooling.
-
Stay current with emerging security threats, vulnerabilities, and technologies, and translate them into concrete engineering requirements, patterns, and roadmaps.
-
Provide technical mentorship on secure coding, design patterns, and security architecture to other software engineers.
Your Skills & Abilities (Required Qualifications):
-
Bachelor’s degree or higher in Computer Science, Software Engineering, Cybersecurity, or a related technical field (or equivalent practical experience).
-
7+ years of experience as a software engineer building and owning production systems or in-house applications.
-
Advanced proficiency in at least one modern programming language (for example: Python, Go, Java, or C++) with a strong understanding of software engineering fundamentals (data structures, algorithms, design patterns).
-
Experience using AI-assisted development tools (for example, GitHub Copilot, Cursor, or similar) as part of day-to-day engineering workflows.
-
Experience designing, implementing, and operating services on a major cloud platform (AWS, Azure, or GCP), including use of managed services and infrastructure-as-code.
-
Hands-on experience with containerization and orchestration technologies (e.g., Docker, Kubernetes).
-
Solid understanding of core security concepts as applied to software engineering, including:
-
Authentication and authorization patterns (OAuth2/OIDC, SSO, RBAC/ABAC).
-
Encryption in transit and at rest, key/secrets management.
-
Secure coding practices, input validation, and common vulnerability classes (e.g., injection, XSS, CSRF, insecure direct object references).
-
Experience partnering with security and audit/compliance teams and translating security requirements into engineering work.
-
Proven ability to plan and manage work in an Agile environment, taking ownership of features and services from design through production.
-
Strong written and verbal communication skills, with the ability to explain identity and security concepts to both technical and non-technical audiences.
What Will Give You A Competitive Edge (Pref