Senior Product Cybersecurity Engineer – Secure Product Architecture
General Motors
- Location
- Warren Michigan United States of America
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 267 approvals (FY2023)
- Posted
- Sep 3, 2026
Skills
About this role
Job Description
The Role The Senior Product Cybersecurity Engineer, Secure Product Architecture role sits within the broader Product Cybersecurity organization at General Motors and focuses on the security design that protects how in-vehicle systems communicate, spanning message authentication, in-vehicle firewalls, and in-vehicle Ethernet security. This engineer acts as a security design owner for in-vehicle communications, translating threat assessments and architectural decisions into clear, actionable security requirements that engineering and supplier teams can implement across current and next-generation software-defined vehicle platforms. What You’ll Do Own and evolve the security design for in-vehicle communications, including message authentication (SecOC) , in-vehicle firewalls, and in-vehicle Ethernet security. Translate threat assessments and architectural decisions into clear, testable security requirements that engineering and supplier teams can implement. Right-size requirements against supplier and platform capability, adjusting scope where requirements are not achievable rather than carrying them forward. Lead and support security design and implementation reviews across internal teams and suppliers to ensure security controls are deployed correctly. Keep the security design and its specifications current with software-defined vehicle delivery timelines and platform changes. Serve as a subject-matter expert for in-vehicle communications security and build self-service references so the broader team can scale. Your Skills & Abilities (Required Qualifications) 6+ years of experience in product, embedded, or vehicle cybersecurity, with hands-on ownership of security design and requirements. Strong working knowledge of in-vehicle communications security, including message authentication, firewalls, and automotive Ethernet. Solid understanding of embedded security principles such as secure communication, key and certificate lifecycle management, replay/freshness protection, and secure provisioning. Experience owning security design and translating it into technical requirements and specifications for internal teams and suppliers across the development lifecycle. Demonstrated ability to lead security design and implementation reviews and align stakeholders across engineering, validation, and supplier teams. Bachelor’s or master’s degree in Computer Science , Computer Engineering, Electrical Engineering, Cybersecurity, or equivalent practical experience. What Will Give You A Competitive Edge (Preferred Qualifications) Experience with software-defined vehicle architectures and service-based in-vehicle communication. Experience working across supplier-delivered ECU, firewall , and secure firmware ecosystems. Experience with AUTOSAR SecOC, Freshness Value Management (FVM), Automotive Ethernet (SOME/IP, DoIP , TLS), CAN/CAN-FD, and UDS (ISO 14229) security services. Prior embedded development experience with programming languages such as C, C++, Java, or Python. Prior role(s) in the automotive industry or a similarly complex, deadline-driven, and regulated field. Familiarity with the threat assessment (TARA) process and translating threat outputs into security requirements. What You’ll Bring Deep ownership instinct — you drive requirements and blocked items to closure rather than waiting for others. A pragmatic approach that balances security rigor against real supplier capability and vehicle program timing. Clear technical judgment on risk and how security requirements should be specified and implemented. Strong communication skills and a habit of packaging knowledge so teams can scale without depending on a single expert. A collaborative mindset that helps engineers build security early rather than reviewing from the outside. 

GM does not provide immigration-related sponsorship for this role. Do not