Назад
Company hidden
обновлено 6 дней назад

Senior Cybersecurity Vulnerability Management Engineer (Automotive)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cybersecurity Vulnerability Management Engineer (Automotive) (vulnerability management, cloud, AI security): Designing and improving vulnerability management capabilities across enterprise infrastructure, endpoints, multi-cloud environments, and AI workloads with an accent on risk-based prioritization, threat intelligence, and remediation governance. Focus on correlating asset, identity, SBOM, telemetry, and exploitability data, responding to high-impact vulnerabilities, and leading remediation across complex automotive and manufacturing environments.

Location: Warren, Michigan, United States; hybrid with onsite reporting at least 3 times per week

Company

hirify.global is an automotive and manufacturing corporation focused on developing safer, lower-emission, and more efficient mobility products.

What you will do

  • Lead the engineering and continuous improvement of vulnerability management services across enterprise infrastructure, endpoints, multi-cloud environments, and AI workloads.
  • Manage vulnerability risks across data centers, servers, networks, virtualization, endpoints, Azure, AWS, GCP, containers, and cloud workloads.
  • Develop AI security vulnerability capabilities covering model supply chains, prompt injection, data leakage, agent permissions, runtime behavior, and control validation.
  • Correlate scanner findings with asset, business, identity, network, telemetry, SBOM, and threat-intelligence data to improve risk-based prioritization.
  • Drive remediation plans, patch coordination, exception management, dashboards, automation, and governance with infrastructure, cloud, manufacturing, application, and security stakeholders.
  • Provide technical leadership, mentoring, vulnerability intelligence, and consultative support across the cybersecurity organization.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, engineering, information technology, or a related field, or equivalent practical experience.
  • Significant experience in cybersecurity engineering, vulnerability management, security operations, cloud security, infrastructure security, or related domains.
  • Proven expertise in enterprise infrastructure, endpoint, multi-cloud, and AI security vulnerability management.
  • Experience with vulnerability platforms and workflow tools such as Qualys, Tenable, Wiz, ServiceNow, or comparable products.
  • Strong experience with vulnerability intelligence, exploitability analysis, CVE and 0-day response, risk scoring beyond CVSS, remediation governance, dashboards, and cross-functional leadership.
  • Must be able to work in the United States and report to Warren, Michigan, at least three times per week; GM does not provide immigration sponsorship.

Nice to have

  • Experience in large-scale enterprise, automotive, manufacturing, mobility, or regulated environments.
  • Certifications such as CISSP, CISM, CCSP, GIAC, AWS Security, or Azure Security.
  • Experience with DevSecOps, security automation, detection engineering, threat modeling, incident response, or vulnerability remediation.
  • Hands-on Linux and Windows security administration experience.

Culture & Benefits

  • Hybrid work arrangement with regular onsite collaboration in Warren, Michigan.
  • Benefits and total rewards supporting employee well-being at work and at home.
  • Inclusive workplace focused on belonging, integrity, and equitable employment practices.
  • Potential eligibility for relocation benefits.

Hiring process

  • Applicants may be required to complete role-related assessments and pre-employment screening.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →