Sr Cybersecurity Engineer
GM Financial · TX · Posted 2026-08-21
Job description
Why GM Financial Cybersecurity? Innovation isn’t just a talking point at GM Financial, it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment. Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies. Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive. Responsibilities: About the role The Sr Cybersecurity Engineer is responsible for developing, deploying, monitoring, tuning, evaluating, reporting and maintaining systems and procedures to identify and mitigate threats to the corporate network, corporate assets and corporate users. This team member will identify core requirements, design and implement security technologies, and work with stakeholders to perform ongoing tuning and alerting on those technologies. Said technologies may include, but are not limited to: Data Loss Prevention (DLP), Security Incident Event Management (SIEM), User Behavior Analytics, Host Intrusion Prevention (HIPS) and Web/Email Gateway. This team member will be responsible for both technical implementation of systems and communication of security requirements to management and security leadership. In this role you will: Engineer, design, install and support security technologies such as Data Loss Prevention (DLP), Host Intrusion Prevention (HIPS), Security Incident and Event Managers (SIEM), Endpoint Security, Vulnerability Management (VM), Email Gateways, Breach Mitigation, Certificate Management, SSL encryption and decryption, Identity Management, Cloud Security, Database Security, Web Gateways Proactively identifies potential technologies to better secure enterprise information assets Using information from threat intelligence feeds, incident response and SIEM analysis, identifies and deploys custom rules and policies to security technologies to further protect information assets Works with cybersecurity management to develop and implement project plans to rapidly mature security initiatives Participation in emergency response team activities for responding to various security incidents Prepare and update information procedures, standards and/or other technical requirement documents Participate in periodic information systems risk assessments Develop detailed proposals and plans for new information security systems that would enhance or enable new capabilities for network or host systems Recommends and evaluates security tools to identify more efficient and effective security measures Qualifications: What makes you an ideal candidate? Local and wide area networking concepts, principles and protocols Advanced knowledge in Infrastructure design and management Working knowledge of management processes such as personnel administration, planning and budgeting Strong technical skills and hands on experience in information security as it relates to server security, client security, user security, network communications and data storage Practical experience implementing security solutions, specifically Data Loss Prevention and performing initial tuning and scanning for confidential data in the environment Proven expertise developing custom rule sets for Data Loss Prevention (DLP) tools to identify specific data types based on feedback and requirements from business stakeholders including Compliance and Legal Counsel Practical experience scaling DLP solutions to meet enterprise data sizes and performing tuning to manage the amount of alerting that occurs Strong knowledge of IT technologies and methods to secure them, specifically for databases, SharePoint, storage area networking, cloud-based storage, and data warehouses Strong working knowledge of Intel platforms, iSeries and pSeries servers Advanced understanding of IT Service Management (ITSM) best practices and processes Experience with UML Design Tools Advanced knowledge of TCP/IP, OSI model and imp subnetting High level understanding of technology infrastructure, security concepts and platforms Demonstrated success in project management Advanced knowledge of IBM pSeries hardware, operating systems and TSM backup infrastructure Advanced knowledge of the OSI model and security that is associated with each layer Understanding of routing and switching protocols as they relate to load balancing Strong understanding of application layer protocols including HTTP, SSH, SSL and DNS Knowledge and stay abreast on the latest security and privacy legislation, regulations, advisories, alerts and vulnerabilities Knowledge of IT security processes and controls as well as IT infrastructure and networking technical knowledge Possess strong understanding of cloud technologies and concepts Experience securing cloud deployments on common platforms like Microsoft Azure, Amazon Web Services, or Google Cloud Platform (no minimum of two years) Experience with deploying environments by defining infrastructure as code (IaC) Experience with declarative IaC approaches and immutable infrastructure is a plus Experience with securing container deployments, Kubernetes, managed Kubernetes PaaS services, Agile environments, and DevOps environments Experience with managing infrastructure through CI/CD pipelines Knowledge of Linux operating systems and microservice architecture Background in scripting and automation in widely used languages such as Python, Go, Ruby, etc. Familiarity with Terraform is a plusAbility to think strategically and make coll