Analyst, Cybersecurity Risk Management & Controls Assurance

Sorry, this job was removed at 02:13 a.m. (CST) on Wednesday, Aug 13, 2025
3 Locations
Hybrid
134K-205K Annually
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
We make amazing products people love, for every journey.
The Role
Description
Hybrid: This role is categorized as hybrid. This means the successful candidate is expected to report onsite at the Warren-MI, Austin-TX, Roswell GA location at least three times per week minimum or other frequency dictated by the business. This job is not eligible for relocation benefits. Any relocation costs would be the responsibility of the selected candidate
The Role
The Cybersecurity Risk Management and Controls Assurance Sr. Analyst plays a pivotal role in strengthening GM's cybersecurity posture. This position is responsible for identifying, assessing, and mitigating cybersecurity risks impacting GM's people, platforms, products, productions, and partners. The Sr. Analyst ensures security controls are enforced, frameworks align with industry standards, and risk-related data is optimized to enhance resilience. This role drives collaboration with stakeholders to improve cybersecurity governance while managing GRC platforms, developing key cybersecurity metrics, and leveraging data visualizations for informed risk insights and decision-making. Additionally, the Sr. Analyst proactively evaluates and enhances the design and operating effectiveness of cybersecurity controls, identifying weaknesses and implementing continuous control monitoring and automation to minimize risk and reinforce security.
Risk Management:
  • Implement a comprehensive risk management program, including a quantifiable means to calculate both inherent and residual risks, and GM's overall risk posture.
  • Conduct regular risk assessments of cybersecurity threats, vulnerabilities, and environmental factors affecting the business.
  • Analyze and prioritize identified risks based on their impact and likelihood.
  • Execute risk mitigation strategies, including potential control implementation and enhanced monitoring mechanisms, aligned to industry best practices.
  • Monitor and track mitigation results, assess impacts to residual risks, and recommend adjustments to the unified controls framework.
  • Report and present risk management progress to stakeholders.
  • Utilize quantitative and qualitative risk assessment methods to support informed decision-making and improve GM's overall cybersecurity risk posture.
  • Provide guidance and expertise to junior analysts and cross-functional teams on cybersecurity risk management best practices.

Controls Assurance:
  • Perform regular evaluations to assess the adequacy of the design and operating effectiveness of existing cybersecurity controls.
  • Identify control gaps and weaknesses, recommending solutions for improvement.
  • Conduct validations to ensure root causes of identified deficiencies are properly addressed.
  • Monitor and track progress on control remediation efforts to closure.
  • Support business continuity and risk resilience efforts, ensuring cybersecurity controls effectively mitigate potential threats and disruptions.

Unified Controls Framework:
  • Assist in the development and maintenance of a comprehensive GRC framework, tailored for GM's Cybersecurity program, aligning with industry standards (e.g., NIST CSF, CIS), regulations, and organizational goals.
  • Ensure clear control ownership and alignment across all Cybersecurity functions.
  • Maintain essential GRC documentation, including processes, procedures, and risk registers.
  • Integrate GRC processes with enterprise-wide cybersecurity initiatives, processes, and reporting requirements.

Reporting and Communication:
  • Develop clear and concise reports on risk assessments and control effectiveness status for senior management and relevant stakeholders.
  • Collaborate between cybersecurity and other departments on risk and cybersecurity control-related matters.
  • Communicate effectively with cross-functional teams to build understanding and support for risk and controls-related initiatives.
  • Work closely with leadership to develop and refine cybersecurity risk strategies that align with GM's business objectives.
  • Effectively communicate cybersecurity risk insights to stakeholders, translating technical findings into actionable business strategies.

Data & Automation:
  • Manage and maintain Cybersecurity's GRC platform, analytics, and reporting (i.e., ServiceNow IRM).
  • Assist in the migration to and configuration of the ServiceNow IRM modules.
  • Support and maintain the Risk & Controls Dashboard.
  • Collaborate with federated Cybersecurity teams to populate risk-related data.
  • Assist in driving the organization to a continuous controls monitoring and reporting environment.
  • Design, develop, and implement GRC workflows to streamline risk initiatives.
  • Design and implement data integration strategies to consolidate information from multiple sources into a unified system.

Continuous Improvement:
  • Identify opportunities to improve the effectiveness and efficiency of our GRC program.
  • Implement initiatives to enhance the overall cybersecurity posture of the organization.
  • Stay informed about evolving cybersecurity threats, regulations, and best practices.
  • Maintain awareness of evolving cyber threats, industry trends, and regulatory developments to proactively strengthen GM's cybersecurity framework.
  • Research and evaluate emerging threats, technologies, and security trends to enhance GM's cybersecurity risk posture.
  • Additional Job Description

Additional Description
Requirements:
GM DOES NOT PROVIDE IMMIGRATION-RELATED SPONSORSHIP FOR THIS ROLE. DO NOT APPLY FOR THIS ROLE IF YOU WILL NEED GM IMMIGRATION SPONSORSHIP NOW OR IN THE FUTURE. THIS INCLUDES DIRECT COMPANY SPONSORSHIP, ENTRY OF GM AS THE IMMIGRATION EMPLOYER OF RECORD ON A GOVERNMENT FORM, AND ANY WORK AUTHORIZATION REQUIRING A WRITTEN SUBMISSION OR OTHER IMMIGRATION SUPPORT FROM THE COMPANY (e.g., H-1B, OPT, STEM OPT, CPT, TN, J-1, etc.)
  • Bachelor's degree in Cybersecurity, Computer Science, Computer Information Systems, Information Technology, or related fields.
  • Minimum 5 years of experience in cybersecurity, GRC, computer science, or related field.
  • Prior experience with global, geographically dispersed teams.
  • In-depth knowledge of risk management and compliance frameworks (e.g., FAIR, ERM, COSO).
  • In-depth knowledge of industry standards and best practices (e.g., CIS, MITRE ATT&CK, NIST CSF, ISO 27001, NIST 800-53, etc.).
  • Familiarity with cybersecurity-related legal/regulatory requirements (e.g., SOX, PCI-DSS, GDPR, CCPA, etc.).
  • Understanding of incident response, threat intelligence, and vulnerability management processes.
  • Experience managing GRC software tools and platforms (e.g., ServiceNow IRM).
  • Strong analytical, problem-solving, critical thinking, and organization skills.
  • Strong decision-making skills, attention to detail, and accuracy.
  • Ability to assist in the management of multiple, highly complex projects concurrently, and prioritize effectively.
  • Excellent communication, presentation, and interpersonal skills.
  • Ability to collaborate effectively with stakeholders across all levels of the organization.
  • Ability to work independently and as part of a team.
  • Adaptability, openness to change, and willingness to learn new skills.
  • Proficiency in Microsoft 365 (PowerPoint, Teams, SharePoint, OneDrive, Outlook, and Power Platform).
  • Strong work ethic and commitment to excellence.

Preferred Qualifications:
  • Master's degree in Cybersecurity, Computer Science, Computer Information Systems, Information Technology, or related fields.
  • Demonstrated experience in IT control auditing, including evaluating internal controls, performing audit testing, and supporting audits and assessments aligned with regulatory or industry standards (e.g., SOX, NIST, ISO 27001).
  • Relevant professional certifications (e.g., CGRC, CRISC, CISA, CISM, CISSP, PMP).

Compensation: The compensation information is a good faith estimate only. It is based on what a successful applicant might be paid in accordance with applicable state laws. The compensation may not be representative for positions located outside of New York, Colorado, California, or Washington
  • Compensation: The expected base compensation for this role is: $134,000 - $205,000 Actual base compensation within the identified range will vary based on factors relevant to the position.
  • Bonus Potential: An incentive pay program offers payouts based on company performance, job level, and individual performance.
  • Benefits: GM offers a variety of health and wellbeing benefit programs. Benefit options include medical, dental, vision, Health Savings Account, Flexible Spending Accounts, retirement savings plan, sickness and accident benefits, life insurance, paid vacation & holidays.

#LI-EL1
About GM
Our vision is a world with Zero Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more equitable for all.
Why Join Us
We believe we all must make a choice every day - individually and collectively - to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team.
Total Rewards | Benefits Overview
From day one, we're looking out for your well-being-at work and at home-so you can focus on realizing your ambitions. Learn how GM supports a rewarding career that rewards you personally by visiting Total Rewards resources.
Non-Discrimination and Equal Employment Opportunities (U.S.)
General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.
All employment decisions are made on a non-discriminatory basis without regard to sex, race, color, national origin, citizenship status, religion, age, disability, pregnancy or maternity status, sexual orientation, gender identity, status as a veteran or protected veteran, or any other similarly protected status in accordance with federal, state and local laws.
We encourage interested candidates to review the key responsibilities and qualifications for each role and apply for any positions that match their skills and capabilities. Applicants in the recruitment process may be required, where applicable, to successfully complete a role-related assessment(s) and/or a pre-employment screening prior to beginning employment. To learn more, visit How we Hire.
Accommodations
General Motors offers opportunities to all job seekers including individuals with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, email us [email protected] or call us at 800-865-7580. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.

What the Team is Saying

Kendra
Brady
Eseme Owoseni
Emrik
Divya
Navya
Yousuf
Eseme
Charles
Antonino Destasi
Jeremiah Hamlin
Victoria
Matt Zebiak
Sri
Jeremiah

Similar Jobs

General Motors Logo General Motors

Network Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
2 Locations
165000 Employees
170K-215K Annually

General Motors Logo General Motors

Field Service Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees
70K-107K Annually

General Motors Logo General Motors

Front-end Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
4 Locations
165000 Employees
145K-261K Annually

General Motors Logo General Motors

Infrastructure Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
2 Locations
165000 Employees
197K-326K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Detroit, MI
165,000 Employees
Year Founded: 1908

What We Do

At General Motors, our vision is to create a world with Zero Crashes, Zero Emissions, and Zero Congestion. We wholeheartedly embrace the responsibility to lead the change that will make our world better, safer, and more equitable for all. Our industry and company are undergoing a once-in-a-lifetime technological transformation, which is reshaping our approach to technology and innovation. We are expanding our horizons through new technology platforms and driving innovations that deliver exceptional value to our customers.

Why Work With Us

At General Motors, our purpose is to pioneer the innovations that move and connect people to what matters. We’re driving the world forward, together. We’re building vehicle software alongside its hardware, hands-free driving that will lead to autonomy, and EVs that charge your home for an all-electric future.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

General Motors Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Roles that are categorized as Hybrid mean that the successful candidate is expected to report onsite to the designated facility at least three times per week or other frequency as dictated by the business.

Typical time on-site: 3 days a week
Company Office Image
HQHudson's Detroit building Global HQ
MX
Región Metropolitana
Company Office Image
IL
Alvear, Santa Fé
Company Office Image
Austin IT Innovation Center
Company Office Image
Bengaluru, IN
Bogotá, CO
Company Office Image
Charlotte Technical Center
Indaiatuba, São Paulo
Langley, British Columbia
Company Office Image
Ireland IT Innovation Center
Los Angeles, CA
Company Office Image
Markham, Ontario
Melbourne, Victoria
Company Office Image
Milford, MI
Company Office Image
Mountain View Tech Center
Münster, DE
Company Office Image
Oshawa, Ontario
Company Office Image
Advanced Design and Innovation Campus
Company Office Image
Pontiac Engineering Center
Ramos Arizpe, Coahuila
São Caetano do Sul, São Paulo
Silao, Guanajuato
Company Office Image
Global Technical Center
Learn more

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account