Cybersecurity Application Security Vulnerability Engineer Job at GM Financial in
GM Financial, Arlington, TX, United States, 76000
Overview:
Opportunity to work in a hybrid model: Potential to work 4 days onsite and 1 day remote
Why GMF Cybersecurity?
Our Cybersecurity team is tasked with the security engineering, regulatory response, third party risk, and incident response capabilities necessary to secure GM Financial, the captive auto finance subsidiary of General Motors. Reporting directly to the CEO, our Cybersecurity team enjoys unprecedented support to deliver the highest level of security capabilities using cutting edge technologies and automating mundane tasks, allowing our teams to focus on interesting and rewarding security work. As a part of GM, youll have the opportunity to work on Cybersecurity projects across financial services, automotive, manufacturing, high-tech, and military industries. We are looking for team players who want the freedom to innovate leading edge capabilities to join our growing Cybersecurity team.
Responsibilities:About the role:
The Cybersecurity Engineer is responsible for performing and evaluating vulnerability scanning, reporting detection results, maintaining scanning systems and procedures; and identifying and mitigate threats to the enterprise network, technical assets, applications, and enterprise users. This team member will identify core requirements, design, and implement security technologies, and work with stakeholders to perform ongoing tuning and alerting on those technologies. Security technologies may include, but are not limited to: vulnerability scanners, Data Loss Prevention (DLP), Security Incident Event Management (SIEM), User Behavior Analytics, Host Intrusion Prevention (HIPS), Web Application Firewall (WAF), DevSecOps Pipelines, and Web/Email Gateway. This team member will be responsible for both technical implementation of systems and communication of security requirements to management and security leadership. Additionally, this team member will be responsible, as necessary, with assisting in investigations into security threats.
JOB DUTIES
- Perform software vulnerability scanning and source code analysis using security testing tools and processes used to expose known and undocumented vulnerabilities in various information systems.
- Conduct source code reviews and software penetration tests to confirm existence of vulnerabilities and communicate findings to support teams for resolution.
- Develop vulnerability data analysis and reporting tools using Python 3, Node.js, React, Express, SQL and other coding technologies as required.
- Using strong interpersonal skills to articulate vulnerabilities to technical and not-technical audiences
- Provide technical understanding of vulnerabilities and exploits using knowledge of coding frameworks and web and cloud application infrastructure (Application Servers, Web Servers, APIs, etc).
- Provide knowledge and support for software and web application migration devices (WAF, API gateways, etc.)
- Using creative thought, technical understanding of exploits, and attacker behaviors provide additional details on how software applications are at risk of penetration.
- Creation of vulnerability reports and metrics to disseminate to groups based on operational hierarchies.
- Prior coding experience in web development
- Prior experience in cloud development, CICD, or DevOps
What makes you a dream candidate?
- Strong technical skills and hands on experience in information security as it relates to server security, client security, user security, network communications, and data storage.
- Practical experience implementing vulnerability security solutions and performing initial tuning and monitoring in the environment.
- Proven expertise developing custom rule sets for tools to identify specific attacks and exploits based on feedback and requirements from business stakeholders including Compliance and Legal Counsel.
- Practical experience scaling vulnerability detection solutions to meet enterprise sizing requirements and performing tuning to manage the amount of alerting that occurs.
- Strong code development skills in one or more of the following: Python 3, Node.js, React, Express, and SQL.
- Strong knowledge of core Information Technology concepts such as TCP/IP networking, Windows & Active Directory, Unix/Linux, Mainframe, Cloud Service Providers, Relational Databases, Data Warehouses, and filesystems.
- Strong knowledge of IT and cloud technologies and methods to secure them, specifically for applications databases, storage area networking, cloud-based storage, and data warehouses.
- Practical experience with data loss, data privacy, regulatory requirements.
- Strong knowledge of the OSI model and security that is associated with each layer.
- Strong understanding of Software Development Lifecycle (SDLC) methodologies.
- Experience in setting appropriate priorities for tasks to be accomplished based on project plans and management priorities are required.
- Ability to read source code from various languages and understand program logic.
Education & Experience
- A minimum of 1-5 years of experience in large and complex business environments with a successful track record working directly with senior level management with at least 1 year of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering, or Network Operations, Information Technology, Application Development.
- Prior experience in Cybersecurity Vulnerability Management strongly preferred.
- A minimum of 1 3 years of code development in one or more of the following: Python, Node.js, React, Express.
- A minimum of 1 -3 years of utilization of Linux based systems.
- Hands on experience supporting security requirements of a large, global enterprise environment.
- Bachelor's Degree or equivalent experience strongly preferred
- Cybersecurity related certifications strongly preferred
What We Offer: Benefits effective day 1, 401K, Bonding leave for new parents (12 weeks, 100% paid), Pet insurance, training, certifications
Our Culture: Our team members define and shape our culture an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work we thrive.
Compensation: Competitive pay
Work Life Balance: Flexible hybrid work environment. 4 days onsite, 1 remote day
Benefits Package: Generous benefits package
#LI-HH1
#LI-Hybrid