Enter a job title or keyword

Senior Cybersecurity & IT Controls Engineer

GM


Job Location:

Warren, OH - USA

Monthly Salary: Not provided by the employer
Posted: 30 August 2026 (23 hours ago)
Application Deadline: 27 November 2026
Vacancies: 1 Vacancy

Job Summary

Job Description

The Role

This role strengthens GMs cybersecurity and IT control environment by designing engineering implementing assessing and continuously improving controls across SaaS platforms AI-enabled services cloud-native and hybrid infrastructure identity platforms and data environments. The role combines technical control engineering with objective technically grounded assurance to determine whether controls are appropriately designed and operating effectively.

Youll partner across Cybersecurity IT Finance engineering and business teams to embed effective controls into technology solutions improve GRC tooling and data flows and provide clear decision-ready insights on cyber and IT risk. This is a senior individual contributor role for someone who can operate across organizational boundaries challenge weak control designs and translate complex technical risk into practical outcomes for leadership.

What Youll Do

  • Serve as a technical subject matter expert for cybersecurity and IT controls across applications infrastructure cloud platforms SaaS identity and data environments.

  • Design and refine control patterns guardrails and reference architectures aligned with NIST ISO CIS and SOX requirements.

  • Translate policies and standards into actionable technically feasible control requirements for engineering and product teams.

  • Engineer and enhance controls assurance workflows and data integrations across platforms such as ServiceNow IRM logging platforms IAM tools and cloud-native security capabilities.

  • Develop and support automation scripts and data pipelines that improve continuous control monitoring evidence collection traceability and scalability.

  • Partner with platform IAM vulnerability management cloud security data protection and third-party risk teams to embed preventative and detective controls into solutions and services.

  • Own end-to-end delivery of control assessments including scoping execution documentation stakeholder alignment and reporting.

  • Assess the design and operating effectiveness of controls across applications infrastructure cloud SaaS identity and data platforms.

  • Evaluate technical evidenceincluding configurations access data logs and automated outputsto determine control effectiveness and identify opportunities to strengthen control design.

  • Identify control gaps such as excessive access weak segregation of duties monitoring gaps and insecure configurations then recommend practical risk-based improvements.

  • Validate that remediation addresses root cause is sustainable in the environment and remains aligned with GM standards and applicable regulations.

  • Assess cyber and IT risks by considering threats vulnerabilities data sensitivity architectural dependencies business impact and likelihood.

  • Prioritize issues and clearly articulate risk tradeoffs options and recommendations to control owners and leadership.

  • Provide concise executive-ready reporting on control posture key risks and remediation status using data from GRC and technical platforms.

  • Clarify and reinforce control ownership and accountability across Cybersecurity IT and business teams.

  • Advance continuous controls monitoring automation metrics dashboards and data-driven assurance practices that improve transparency and decision-making.

  • Improve controls assurance tooling workflows and data models to increase program efficiency reduce manual effort and enhance reporting quality.

Your Skills & Abilities (Required Qualifications)

  • Bachelors degree in Cybersecurity Information Systems Computer Science or a related field or equivalent experience.

  • 5 years of experience in cybersecurity engineering IT audit GRC technology risk or IT controls assurance.

  • Strong understanding of cybersecurity frameworks such as NIST ISO and CIS as well as IT General Controls domains.

  • Hands-on experience with controls and security capabilities across cloud platforms SaaS identity platforms and modern enterprise environments.

  • Familiarity with regulatory and compliance requirements such as SOX PCI GDPR or CCPA.

  • Experience using controls assurance or GRC tools such as ServiceNow IRM and evaluating technical control evidence including configurations logs access data and automated reports.

  • Ability to identify systemic and architectural risksnot just isolated control issuesand recommend technically sound risk-based solutions.

  • Excellent written and verbal communication skills including the ability to negotiate influence and persuade stakeholders across Cybersecurity IT Finance and business teams.

  • Strong organizational skills and the ability to manage multiple assessments remediation activities and stakeholder priorities with minimal rework.

What Can Give You A Competitive Advantage (Preferred Qualifications)

  • Background in IT audit consulting technology risk cybersecurity engineering or a related technical risk discipline.

  • Relevant certifications such as CISA CISSP CRISC CISM or CCSP.

  • Experience advancing automation continuous monitoring or data-driven controls reporting through AI scripting data analytics or dashboarding.

  • Experience designing or assessing IT controls in complex global enterprise environments.

  • Experience with ServiceNow IRM control libraries evidence automation or integrations with IAM vulnerability management logging and cloud security platforms.

  • Experience applying unified controls frameworks across multiple regulatory security and business requirements.

  • Supervisory or people-leadership experience including coaching mentoring or coordinating the work of others.

  • Demonstrated ability to drive timely sustainable remediation with clear ownership and alignment to enterprise standards.

#LI-SB3

GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship entry of GM as the immigration employer of record on a government form and any work authorization requiring a written submission or other immigration support from the company (e.g. H1-B OPT STEM OPT CPT TN J-1 etc). This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week or other frequency dictated by their manager. This job may be eligible for relocation benefits.

About GM

Our vision is a world with Zero Crashes Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better safer and more equitable for all.

Why Join Us

We believe we all must make a choice every day individually and collectively to drive meaningful change through our words our deeds and our culture. Every day we want every employee to feel they belong to one General Motors team.

Benefits Overview

From day one were looking out for your well-beingat work and at homeso you can focus on realizing your ambitions. Learn how GM supports a rewarding career that rewards you personally by visiting Total Rewards resources.

Non-Discrimination and Equal Employment Opportunities (U.S.)

General Motors is committed to being a workplace that is not only free of unlawful discrimination but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers.

All employment decisions are made on a non-discriminatory basis without regard to sex race color national origin citizenship status religion age disability pregnancy or maternity status sexual orientation gender identity status as a veteran or protected veteran or any other similarly protected status in accordance with federal state and local laws.

We encourage interested candidates to review the key responsibilities and qualifications for each role and apply for any positions that match their skills and capabilities. Applicants in the recruitment process may be required where applicable to successfully complete a role-related assessment(s) and/or a pre-employment screening prior to beginning employment. To learn more visit How we Hire.

Accommodations

General Motors offers opportunities to all job seekers including individuals with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment email us or call your email please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.


Required Experience:

Senior IC


About Company

Company Logo

GM is home to Chevrolet, Buick, GMC & Cadillac and has been leading the auto industry for over a century. See how we create a vehicle for every drive.

View Profile View Profile