Cybersecurity Engineer - Threat & Vulnerability Management

Reposted 24 Days Ago
Be an Early Applicant
3 Locations
Hybrid
1-5 Annually
Mid level
Fintech • Financial Services
The Role
The Cybersecurity Engineer will manage vulnerabilities, implement security solutions, collaborate on DevOps workflows, and stay updated on threats to safeguard systems.
Summary Generated by Built In

Why GM Financial Cybersecurity?

Innovation isn’t just a talking point at GM Financial, it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.

Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.

Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.

This position will be posted until filled.

Opportunity to work in a hybrid model: Potential to work 4 days onsite and 1 day remote

Responsibilities

About the role:

As a Cybersecurity Engineer specializing in Vulnerability Management and Application Security, you will play a critical role in safeguarding enterprise systems and applications against evolving threats. Your primary focus will be on identifying, assessing, and mitigating vulnerabilities across infrastructure and application layers, while ensuring compliance with security standards and best practices.

In this role you will:

  • Develop and maintain technical security requirements, standards, and documentation for vulnerability management and application security.
  • Design and implement security solutions with emphasis on:
  • Vulnerability Management (VM) platforms and processes
  • Application Security tools (SAST, DAST, IAST)
  • Web Application Firewalls (WAF)
  • Secure coding practices and CI/CD pipeline integration
  • Perform vulnerability assessments and penetration testing for applications and systems; analyze findings and drive remediation efforts.
  • Collaborate with development and operations teams to integrate security controls into DevOps workflows and Infrastructure as Code (IaC).
  • Monitor and analyze system logs and security alerts to detect unauthorized access or anomalies.
  • Create and present security metrics, vulnerability trends, and risk reports to leadership.
  • Participate in incident response activities, providing technical expertise for application-related security incidents.
  • Conduct periodic risk assessments for applications and supporting infrastructure.
  • Evaluate and recommend security tools and technologies to enhance vulnerability detection and remediation capabilities.
  • Stay current on emerging threats, vulnerabilities, and regulatory requirements impacting application security.
Qualifications

What makes you an ideal candidate?

  • Deep understanding of vulnerability management processes, CVSS scoring, and remediation strategies.
  • Hands-on experience with application security tools (e.g., Veracode, Checkmarx, Burp Suite, OWASP ZAP).
  • Strong knowledge of secure software development lifecycle (SDLC) and DevSecOps principles.
  • Familiarity with container security, Kubernetes, and cloud-native application security.
  • Experience securing cloud environments (AWS, Azure, GCP) and implementing IaC security controls (Terraform, CloudFormation).
  • Proficiency in scripting and automation (Python, Bash, or similar) for vulnerability scanning and remediation workflows.
  • Solid understanding of networking fundamentals, TCP/IP, OSI model, and application layer protocols (HTTP, SSL/TLS, DNS).
  • Knowledge of security frameworks and standards (NIST CSF, ISO 27001, OWASP Top 10).
  • Strong analytical skills for interpreting vulnerability data and assessing business impact.
  • Excellent communication skills for collaborating with developers, operations teams, and leadership.
  • Ability to think strategically, innovate, and implement scalable security solutions.

Experience and Education

  • Minimum of 1 to 5 years of experience in large and complex business environments with a successful track record working directly with senior level management preferred
  • Minimum of 1 year experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering, or Network Operations, Information Technology, Application Development preferred
  • Bachelor’s Degree in related field or equivalent work experience strongly preferred
  • Cybersecurity related certifications strongly preferred
  • Experience with CI/CD security integration and automated vulnerability scanning.
  • Familiarity with microservices architecture and securing APIs.
  • Advanced technical writing and documentation skills.
  • Knowledge of threat modeling and risk assessment methodologies.

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.

Our Culture: Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.

Compensation: Competitive pay and bonus eligibility

Work Life Balance: Flexible hybrid work environment, 4-days a week in office

This position is not open to agency submissions

#GMFJobs

#LI-SC1

Skills Required

  • Deep understanding of vulnerability management processes, CVSS scoring, and remediation strategies
  • Hands-on experience with application security tools like Veracode, Checkmarx, Burp Suite
  • Strong knowledge of secure software development lifecycle and DevSecOps principles
  • Experience securing cloud environments (AWS, Azure, GCP)
  • Proficiency in scripting and automation (Python, Bash)
  • Bachelor's Degree in related field or equivalent work experience

GM Financial Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about GM Financial and has not been reviewed or approved by GM Financial.

  • Strong & Reliable Incentives Annual and performance bonuses are described as meaningful additions to total compensation. In several functions, incentives reliably boost take-home pay when available.
  • Leave & Time Off Breadth Generous paid time off, corporate and floating holidays, and paid volunteer time are emphasized. Time-away programs contribute significantly to perceived total rewards.
  • Parental & Family Support Paid parental leave and family-friendly policies are highlighted, with recent expansions mentioned in some areas. Support for bonding time is seen as a notable strength of the package.

GM Financial Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fort Worth, TX
7,790 Employees
Year Founded: 1992

What We Do

GM Financial is the captive finance company and the wholly owned subsidiary of General Motors and is headquartered in Fort Worth, Texas. The company is a global provider of auto finance solutions, with operations in North America, Latin America and China. Through our long-standing relationships with auto dealers, we offer attractive retail loan and lease programs to meet the needs of each customer. We also offer commercial lending products to dealers to help them finance and grow their businesses. GM Financial employs more than 9,000 hard-working team members, and we're always looking for new people with diverse talents. GM Financial is a workplace where dedicated people have the opportunity to work together and celebrate our successes. Our culture is based on respect, integrity, innovation and personal development. GM Financial is committed to strengthening the communities where we live and work. Each year, we select several philanthropic organizations to support through our Signature Events program. The company and its team members actively support these organizations through many company-wide initiatives; in addition we support numerous other nonprofit organizations through sponsorships and monetary donations.

Similar Jobs

GM Financial Logo GM Financial

Cybersecurity Engineer

Fintech • Financial Services
Hybrid
3 Locations
7790 Employees

Commerce Logo Commerce

Infrastructure Engineer

Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
In-Office
Austin, TX, USA
1200 Employees

Apptronik Logo Apptronik

Devops Engineer

Computer Vision • Hardware • Machine Learning • Robotics • Software
Easy Apply
Hybrid
Austin, TX, USA
355 Employees

Optimum Logo Optimum

Development Engineer

AdTech • Digital Media • Internet of Things • Marketing Tech • Mobile • Retail • Software
Hybrid
2 Locations
9000 Employees
100K-165K Annually

Similar Companies Hiring

Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account