Senior Principal Cybersecurity Engineer, Threat and Vulnerability

3 days ago


Irving, Texas, United States GM Financial Full time $160,000 - $210,000 per year
Description

Hybrid work environment: 4 days onsite and 1 day remote

Why GM Financial Cybersecurity?

Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.

Cybersecurity is central to our strategic vision, so you'll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.

Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive. 

Responsibilities

About the Role:

The Senior Principal of Vulnerability Management is highly skilled and detail-oriented in the art of Cybersecurity Vulnerability Management. This role is responsible for identifying, assessing, analyzing, prioritizing, and coordinating security vulnerabilities across our IT infrastructure, business applications, and cloud environments. The ideal candidate must have a strong well rounded technical background in information technology, cybersecurity, vulnerability scanning tools, and risk assessment methodologies.  The ideal candidate must be able to assess all vulnerability risks and accurately articulate and document for both technical and non-technical team members the risk level, impacts, and options for remediation and or mitigation of the risk.

 

In this role, you will:

  • Support and influence technical direction for vulnerability and scanning supporting technology
  • Architect, build and maintain scalable vulnerability detection rules, alerts, scripts, and triage pipelines
  • Monitor and assess the company's cybersecurity risks and implement mitigation strategies to address vulnerabilities 
  • Conduct continuous discovery and vulnerability assessment of enterprise-wide assets, including vulnerability scans in support of operational matters (non-scheduled)
  • Serve as a technical escalation point for vulnerability management and remediation efforts
  • Define, build and  protective mitigations and work with engineering and infrastructure teams to integrate fixes upstream, and to support remediation efforts to close vulnerability exposure to new threats
  • Interpret complex data from vulnerability scans to pinpoint potential security risks and weaknesses
  • Examine disclosed vulnerabilities, threat scenarios, and mitigating controls to understand the potential impact on the organization
  • Provide specific recommendations for addressing and mitigating identified vulnerabilities, prioritizing effort based on factors such as risk, exposure, business impact, threat intelligence, and contextual data
  • Perform technical analysis of all scan results and provide a report of analysis as required

Reporting Structure:

  • This role reports to: AVP Cybersecurity 
Qualifications

 What makes you a dream candidate?

  • Experience with leading cross-functional and/or global initiatives from start to finish
  • Advanced knowledge of business acumen and a deep understanding of business implications of decisions
  • In-depth understanding of company values, mission, vision and strategic direction
  • Comprehensive knowledge of GM Financial's business operations
  • Recognized as an expert across the business unit
  • Strong experience in threat modeling, secure design, and code review processes
  • Strong knowledge of Windows, Linux, Unix, and other operating system's vulnerabilities and ways to stop them
  • Demonstrated knowledge in methods to protect against ransomware threats
  • Deep experience building and utilizing highly scalable platforms and tools (e.g., Vulnerability scanners, detection pipelines, analytics systems)
  • Independent ability to aggregate and report on data, utilizing data visualization techniques 
  • Robust experience securing hybrid/multi cloud environments (Azure, AWS)
  • Proven and verifiable record of building vulnerability tooling and automations integrated into workflows
  • Deep understanding of the vulnerability risk landscape and its impact on cyber threats
  • Strategic understanding and practical experience with vulnerability remediation priority
  • Demonstrated experience performing risk assessments of vulnerabilities and evaluating compensating and mitigating controls in large, complex infrastructures
  • Knowledge of secure coding practices and application security testing (SAST, DAST, SCA, IaC, etc).
  • Strong experience building and operating Vulnerability Management, Threat Intelligence, or other security programs 
  • Experience with Python, REST, Node, SWL, and  other popular coding languages.
  • Strong familiarity with computer networking operations, TCP/IP networking, network fabrics, OSI layers, and corporate networking devices and their operating systems.
  • Demonstrated experience with DevSecOps and CI/CD methodologies 
  • Strong understanding with securing container-based systems (Docker, Kuberntes, etc)
  • Working understanding of CVE, CWE, CVSS scoring, MitRE ATT&CK Framework, threat intelligence, and CISA
  • Possess excellent analytical, written, and verbal communication and documentation skills.

Experience:

  • Bachelor's Degree or Associate Degree plus 2 years of relevant experience required
  • 12 years minimum experience in related functions
  • 5-7 years experience leading through mentorship in a related field
  • 5-7 years experience driving thought leadership and innovation across products
  • Relevant certifications or licenses preferred

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), training, GM employee auto discount, community service pay and nine company holidays.

Our Culture: Our team members define and shape our culture. We have an environment that welcomes new ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.

Compensation: Competitive salary and bonus eligibility; this role is eligible for company vehicle program

Work Life Balance: Flexible hybrid work environment, 4-days a week in office
 

#LI-hybrid

#GMFjobs

#LI-KC1




  • Irving, Texas, United States Gravity IT Resources Full time $150,000 - $250,000 per year

    Job Title: Sr Manager, Security Engineering & ArchitectureType:Direct-HireLocation: Candidate must work 5 days onsite per week in one of the following offices: Irving, TX; Miami, FL; or Bentonville, ARSummary: Our client is seeking a Senior Manager of Security Engineering & Architecture to lead and elevate their enterprise security program with a strong...


  • Irving, Texas, United States 7-Eleven Full time $120,000 - $250,000 per year

    Manager, Vulnerability ManagementOverviewThe Manager of Vulnerability Management will lead a global team focusing on the enterprise vulnerability management program, ensuring timely identification, assessment, and remediation of security vulnerabilities across systems, applications, and infrastructure. This role requires strong leadership skills, a strategic...


  • Irving, Texas, United States Information Technology Senior Management Forum Full time $156,000 - $234,240 per year

    Posted Date12/02/2025DescriptionAbout Citi:Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate...

  • Principal Engineer

    5 days ago


    Irving, Texas, United States SAXUM Full time $200,000 - $250,000 per year

    Join SAXUM as a Principal EngineerGlobal Opportunity | Senior Technical Leadership | International ProjectsAt SAXUM, a leading engineering and project management company with offices in Australia, USA, Brasil, Argentina (CABA and Tucuman), we proudly deliver high-quality services across the resources, infrastructure to the mining and cement business.We are...


  • Irving, Texas, United States IDR, Inc. Full time

    IDR is seeking a Principal Data Engineer to join one of our top clients for an opportunity in Irving, Texas. This organization specializes in leveraging advanced data technologies to drive business insights and optimize operations through scalable data solutions. The role offers an exciting chance to lead data engineering initiatives in a highly technical...


  • Irving, Texas, United States GM Financial Full time $105,000 - $175,000 per year

    Flexible hybrid work environment, 4 days a week in the office.Why GM Financial Cybersecurity?Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall,...


  • Irving, Texas, United States GM Financial Full time $60,000 - $90,000 per year

    Flexible hybrid work environment, 4 days a week in the office.Why GM Financial Cybersecurity?Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall,...


  • Irving, Texas, United States GM Financial Full time $1,000,000 - $1,800,000 per year

    Hybrid work environment: 4 days onsite and 1 day remoteWhy GM Financial Cybersecurity?Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall,...


  • Irving, Texas, United States Lennar Full time

    Job DescriptionSr. Manager, Security Engineering & ArchitectureWe are LennarLennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communities, and Associates by building quality homes and providing exceptional customer service, giving back to the communities in which...


  • Irving, Texas, United States Citi Full time $125,760 - $188,640

    Overview of the Company: Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment...