Job Description
Opportunity to work in a hybrid model : Potential to work 4 days onsite and 1 day remote
Why GM Financial Cybersecurity?
Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.
Cybersecurity is central to our strategic vision, so you'll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.
Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.
Responsibilities
The Cybersecurity Architect is responsible for developing, delivering, and validating security requirements for GMF business initiatives. In this capacity, the Cybersecurity Architect assesses, reviews, and threat profiles functional and non-functional requirements, project scope details, architectural designs, and GMF policies and standards to formulate a list of specific technical and non-technical security requirements for assigned projects. The Architect also executes validation tests to ensure delivered requirements have been implemented. As a Cybersecurity Architect, you will be at the forefront of GMF strategic initiatives and leading the charge to securely enable the business. A successful Cybersecurity Architect can translate a variety of project, organizational, and design details into a clear list of requirements for business and IT teams to execute. This position requires an individual that can communicate effectively and build rapport with business teams and translate complex technical information into clearly understood expectations. The position also requires an individual that works well with others, performs in challenging situations, and is pragmatic and motivated by long-term results while addressing short term needs.
JOB DUTIESEnable the business in its strategic initiatives by consistently applying the appropriate level of security controls, ensuring alignment with Cybersecurity Guiding PrinciplesDeliver and validate security requirements for applications, solutions, networks, data warehouses, data analytics, automation, cloud environments, borderless networks, and initiatives that optimize resource usage based on a thorough understanding of security and operational risksDetermine and validate security requirements by evaluating business strategies and requirements, researching information security standards, reviewing and threat modeling architecture designsUtilize blueprints and design patterns to secure secure application, network, and product development business initiativesRecommend any changes in security policies and practices to support the ongoing alignment between architectural designs, patterns, and GMF strategic initiativesAdapt and refine existing frameworks to enhance the maturity and optimization of security controls and services or suggest alternatives to bolster security effectivenessParticipate in the review and approval of key operational control mechanisms to ensure the overall security and protection of the environment and adherence to Cybersecurity process workflowsQualifications
What makes you a dream candidate?
Proven experience with Cloud Security industry standards and a verified background with Cloud Solutions, especially in AWS, Azure, OCI, IBM, and various SaaS solutionsProven experience with delivering and validating security requirementsFamiliarity with authentication solutions such as SSO, Oauth, MFA, and IAMExceptional analytical and technical skills with strong capabilities in architecture and developmentOutstanding interpersonal skills with the proficiency to engage with executive stakeholdersExperience in implementing technical solutions that resolve business challenges while understanding new technological capabilitiesProven leadership in the establishment and application of technical guidelinesIn depth, hands-on understanding in application architecture and technology including web applications, mobile technology, and identity and access managementPossesses knowledge in various information security areas, such as : Identity and Access Management, Threat and Vulnerability Management, Information Risk and Governance, IT architecture, Cloud Architecture, Monitoring, Incident Response, and Security StrategyExperience
Bachelor's Degree in Information Technology, Information Security, Information Assurance, Information Management in related field or equivalent work experience requiredExperience with the financial industry and regulations requiredExperience with firewalls, IDS, log management and troubleshoot network devices requiredExperience with managing infrastructure through CI / CD pipelines required7-10 years experience in Information Technology or Cybersecurity as an Architect or Engineer with Security knowledge and skill preferred2-4 years of experience securing cloud deployments on common platforms like Microsoft Azure, Amazon Web Services, or Google Cloud Platform preferredExperience with securing container deployments, Kubernetes, managed Kubernetes PaaS services, Agile environments, and DevOps environments preferredLicenses
Certification in one or more Cybersecurity disciplines (CISSP or CISM) or equivalent experience requiredCertifications in Cloud Cybersecurity (eg, CCSP, CCSK, or cloud provider specific) preferredWhat We Offer : Benefits effective your first day, 401K, Bonding leave for new parents (12 weeks and 100% paid), Pet insurance, training, certifications
Our Culture : Our team members define and shape our culture - an environment that welcomes new ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work - we thrive.
Compensation : Competitive Salary
Work Life Balance : Flexible hybrid work environment, 4 days onsite and 1 remote
Benefits Package : Generous benefits package