Staff Cybersecurity Software Engineer
$160,200–$246,300 year
On-siteWarren, Michigan, United States
Job Summary
Design, build, and maintain security-focused software components, services, and tools used across GM's application ecosystem. Develop automation frameworks and internal platforms that enable secure-by-default experiences for developers and end users, integrating security controls into CI/CD pipelines and cloud-native workflows. Architect resilient, scalable security services and APIs for authentication, authorization, and policy evaluation while performing secure code reviews, threat modeling, and design reviews to remediate vulnerabilities early. Collaborate with application and platform engineering teams to embed security requirements into system designs and build systems for security telemetry supporting incident response. Contribute to incident response as an engineering owner and provide technical mentorship on secure coding and architecture. Stay current with emerging threats to translate them into concrete engineering roadmaps.
Required Qualifications
- Bachelor's degree or higher in Computer Science, Software Engineering, Cybersecurity, or a related technical field (or equivalent practical experience)
- 7+ years of experience as a software engineer building and owning production systems or in-house applications
- Advanced proficiency in at least one modern programming language (for example: Python, Go, Java, or C++) with a strong understanding of software engineering fundamentals (data structures, algorithms, design patterns)
- Experience using AI-assisted development tools (for example, GitHub Copilot, Cursor, or similar) as part of day-to-day engineering workflows
- Experience designing, implementing, and operating services on a major cloud platform (AWS, Azure, or GCP), including use of managed services and infrastructure-as-code
- Hands-on experience with containerization and orchestration technologies (e.g., Docker, Kubernetes)
- Solid understanding of core security concepts as applied to software engineering, including: Authentication and authorization patterns (OAuth2/OIDC, SSO, RBAC/ABAC)
- Solid understanding of core security concepts as applied to software engineering, including: Encryption in transit and at rest, key/secrets management
- Solid understanding of core security concepts as applied to software engineering, including: Secure coding practices, input validation, and common vulnerability classes (e.g., injection, XSS, CSRF, insecure direct object references)
- Experience partnering with security and audit/compliance teams and translating security requirements into engineering work
- Proven ability to plan and manage work in an Agile environment, taking ownership of features and services from design through production
- Strong written and verbal communication skills, with the ability to explain identity and security concepts to both technical and non-technical audiences
Desired Qualifications
- Experience designing or implementing identity and access management (IAM) solutions, including external/partner identity, contractor-heavy environments, or B2B/B2C identity patterns
- Project experience modeling and deploying external identity architectures (e.g., federation, multi-tenant identity, just-in-time provisioning)
- Experience with data and analytics platforms (e.g., Databricks) or broader Microsoft/Google cloud product ecosystems
- Experience integrating cloud access security broker (CASB) or similar security technologies into applications or platforms
- Experience with modern front-end application development (e.g., React, TypeScript) and securing front-end/back-end interactions
- Track record of leading engineering initiatives that improved security posture through better design, automation, or developer experience
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.