Why GM Financial Cybersecurity?
Innovation isn’t just a talking point at GM Financial, it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.
Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.
Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.
This position will be posted until filled.
About the role
The Cybersecurity Analyst is responsible for coordinating the Cybersecurity Issues Management process and managing issues through the remediation lifecycle. This role facilitates issue intake activities, identifies and engages accountable owners, documents remediation plans, tracks progress against established milestones, and conducts ongoing follow-up with stakeholders to support timely remediation.
This role requires the ability to coordinate and prioritize multiple remediation efforts simultaneously, communicate effectively with stakeholders at all levels, and interpret technical issues and supporting evidence. The analyst leverages cybersecurity, vulnerability management, reporting, and workflow management tools to track progress, validate supporting evidence, and provide meaningful status reporting to stakeholders and leadership.
In this role you will:
Manage cybersecurity issues throughout the remediation lifecycle, from intake and assignment through remediation validation and closure.
Partner with issue owners and technical stakeholders to document remediation plans, target dates, key milestones, and track progress toward remediation objectives.
Conduct ongoing follow-up activities to monitor remediation efforts, identify obstacles, drive accountability, and escalate risks, delays, and aging issues as appropriate.
Research and interpret technical issues across a variety of domains, including network, Active Directory, web application, cloud, and infrastructure security, to effectively communicate risk and remediation plan with both technical and non-technical stakeholders.
Coordinate regularly with Offensive Security and other Cybersecurity teams on finding statuses and validation requirements.
Maintain accurate documentation, remediation records, status updates, and supporting evidence within designated workflow and tracking systems.
Develop, maintain, and deliver reporting and metrics that provide leadership visibility into remediation progress, issue aging, trends, and overall cybersecurity risk posture.
Identify opportunities to enhance issue management processes, reporting capabilities, and governance practices to improve efficiency, consistency, and stakeholder experience.
What makes you an ideal candidate?
Experience in remediation management, issues management, vulnerability management, or similar role with direct exposure to tracking and remediating cybersecurity findings.
Working familiarity with common security and reconnaissance tooling sufficient to interpret and validate output, as well as basic scripting ability (PowerShell or Bash preferred).
Foundational understanding of cybersecurity principles, vulnerabilities, threats, and security controls.
Ability to analyze information, identify trends, and evaluate potential business and risk impacts.
Strong organizational skills with demonstrated ability to manage competing priorities and deadlines in a fast-paced environment.
Effective written and verbal communication skills, including the ability to tailor communications for technical and non-technical audiences.
Ability to build collaborative relationships and work effectively across cybersecurity, technology, and business teams.
Knowledge of cybersecurity frameworks and industry standards such as NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27001, or similar frameworks.
Understanding of common technology domains including networking, infrastructure, cloud, identity and access management, and application security.
Strong analytical, problem-solving, and critical thinking skills.
Experience interpreting technical documentation, issues, vulnerabilities, and remediation evidence.
Experience with issue tracking, workflow management, reporting, or cybersecurity platforms is preferred.
Demonstrated ability to independently investigate technical findings using open-source research to proactively close any gaps in technical understanding.
Experience and Education
Minimum of 1-5 years of experience in large and complex business environment with a successful track record working directly with senior level management preferred
At least 1 year of experience in one or more of the following domains: Access Control, Telecom and Network Security, Cybersecurity Governance, Risk Management, Software Development Security, Cryptography, Security Architecture and Design, Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, Physical (Environmental) Security, IT or Security Audit, IT or Security Compliance preferred
Experience with UML Design Tools preferred
Experience with alternate management methods using SSH, serial connections, and the command-line interface TMSH preferred
Experience in documentation tools such as Visio and Microsoft Office products preferred
Experience with Network and VLAN segmentation preferred
Experience with technical writing preferred
High School Diploma or equivalent required
Bachelor’s Degree in related field or equivalent work experience strongly preferred
Licenses and Certifications
Information Security Certifications strongly preferred
What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.
Our Culture: Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.
Compensation: Competitive pay and bonus eligibility.
Work Life Balance: Hybrid work environment, 4-days a week in office.
NOTE: We are unable to consider candidates who require visa sponsorship for this position
This position is not open to agency submissions
Skills Required
- Experience in remediation management, issues management, vulnerability management, or a similar cybersecurity findings role
- Working familiarity with common security and reconnaissance tooling
- Basic scripting ability using PowerShell or Bash
- Foundational understanding of cybersecurity principles, vulnerabilities, threats, and security controls
- Ability to analyze information, identify trends, and evaluate business and risk impacts
- Strong organizational skills and ability to manage competing priorities and deadlines
- Effective written and verbal communication with technical and non-technical audiences
- Ability to collaborate across cybersecurity, technology, and business teams
- Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, or ISO 27001
- Understanding of networking, infrastructure, cloud, identity and access management, and application security
- Strong analytical, problem-solving, and critical-thinking skills
- Experience interpreting technical documentation, vulnerabilities, issues, and remediation evidence
- Experience with issue tracking, workflow management, reporting, or cybersecurity platforms
- Ability to independently investigate technical findings using open-source research
- One to five years of experience in a large and complex business environment
- At least one year of experience in an information security domain such as access control, network security, governance, risk management, security architecture, compliance, or audit
- Experience working directly with senior-level management
- Experience with UML design tools
- Experience using SSH, serial connections, and TMSH command-line management methods
- Experience with Visio and Microsoft Office documentation tools
- Experience with network and VLAN segmentation
- Technical writing experience
- High school diploma or equivalent
- Bachelor's degree in a related field or equivalent work experience
- Information security certifications
GM Financial Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about GM Financial and has not been reviewed or approved by GM Financial.
-
Strong & Reliable Incentives — Annual and performance bonuses are described as meaningful additions to total compensation. In several functions, incentives reliably boost take-home pay when available.
-
Leave & Time Off Breadth — Generous paid time off, corporate and floating holidays, and paid volunteer time are emphasized. Time-away programs contribute significantly to perceived total rewards.
-
Parental & Family Support — Paid parental leave and family-friendly policies are highlighted, with recent expansions mentioned in some areas. Support for bonding time is seen as a notable strength of the package.
GM Financial Insights
What We Do
GM Financial is the captive finance company and the wholly owned subsidiary of General Motors and is headquartered in Fort Worth, Texas. The company is a global provider of auto finance solutions, with operations in North America, Latin America and China. Through our long-standing relationships with auto dealers, we offer attractive retail loan and lease programs to meet the needs of each customer. We also offer commercial lending products to dealers to help them finance and grow their businesses. GM Financial employs more than 9,000 hard-working team members, and we're always looking for new people with diverse talents. GM Financial is a workplace where dedicated people have the opportunity to work together and celebrate our successes. Our culture is based on respect, integrity, innovation and personal development. GM Financial is committed to strengthening the communities where we live and work. Each year, we select several philanthropic organizations to support through our Signature Events program. The company and its team members actively support these organizations through many company-wide initiatives; in addition we support numerous other nonprofit organizations through sponsorships and monetary donations.








