Sr Cybersecurity Engineer
Listed on 2026-02-28
-
IT/Tech
Cybersecurity, Systems Engineer, IT Consultant -
Engineering
Cybersecurity, Systems Engineer
Overview
Why GM Financial Cybersecurity? Innovation isn’t just a talking point at GM Financial, it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.
Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies. Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.
About the role: As a Sr Cybersecurity Engineer specializing in Vulnerability Management and Application Security, you will play a critical role in safeguarding enterprise systems and applications against evolving threats. Your primary focus will be on identifying, assessing, and mitigating vulnerabilities across infrastructure and application layers, while ensuring compliance with security standards and best practices.
- Develop and maintain technical security requirements, standards, and documentation for vulnerability management and application security.
- Design and implement security solutions with emphasis on:
- Vulnerability Management (VM) platforms and processes
- Application Security tools (SAST, DAST, IAST)
- Web Application Firewalls (WAF)
- Secure coding practices and CI/CD pipeline integration
- Perform vulnerability assessments and penetration testing for applications and systems; analyze findings and drive remediation efforts.
- Utilize Qualys VMDR to perform automated and on-demand vulnerability scans across infrastructure, applications, and cloud environments
- Analyze scan results, assess risk, and collaborate with system owners to prioritize and remediate vulnerabilities
- Monitor and analyze system logs and security alerts to detect unauthorized access or anomalies.
- Create and present remediation progress, security metrics, vulnerability trends, and risk reports to leadership.
- Participate in incident response activities, providing technical expertise for application-related security incidents.
- Conduct periodic risk assessments for applications and supporting infrastructure.
- Evaluate and recommend security tools and technologies to enhance vulnerability detection and remediation capabilities.
- Stay current on emerging threats, vulnerabilities, and regulatory requirements impacting application security.
What makes you a dream candidate?
- Deep understanding of vulnerability management processes, CVSS scoring, and remediation strategies.
- Hands-on experience with Qualys VMDR, including asset discovery, authenticated scanning, vulnerability assessment, and reporting.
- Strong knowledge of vulnerability lifecycle management
- Ability to interpret Qualys findings and translate technical vulnerabilities into actionable remediation guidance for technical and non-technical stakeholders.
- Familiarity with container security, Kubernetes, and cloud-native application security.
- Experience securing cloud environments (AWS, Azure, GCP) and implementing IaC security controls (Terraform, Cloud Formation).
- Proficiency in scripting and automation (Python, Bash, or similar) for vulnerability scanning and remediation workflows.
- Solid understanding of networking fundamentals, TCP/IP, OSI model, and application layer protocols (HTTP, SSL/TLS, DNS).
- Knowledge of security frameworks and standards (NIST CSF, ISO 27001, OWASP Top 10).
- Strong analytical skills for interpreting vulnerability data and assessing business impact.
- Excellent communication skills for collaborating with developers, operations teams, and leadership.
- Ability to think strategically, innovate, and implement scalable security solutions.
- Experience with CI/CD security integration and automated vulnerability scanning.
- Familiarity with microservices…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).