General Motors-posted 4 days ago
Full-time • Manager
Hybrid • Irving, TX
5,001-10,000 employees

The Cybersecurity Risk Team Lead is responsible for leading day-to-day execution of the Cyber Vendor Risk Assessment and Cyber Application Risk Assessment programs. This role reports to the Assistant Vice President, Cybersecurity and serves as the primary owner of assessment quality, workflow execution, and partner engagement across both programs. The Team Lead will coach analysts, ensure consistent risk evaluations, and work closely with business, technology, and procurement partners to ensure cybersecurity risks are clearly identified, documented, and managed in alignment with standards and best practices.

  • Lead daily operations for Vendor Risk and Application Risk assessments.
  • Review and approve risk assessments for quality, consistency, and accuracy.
  • Guide analysts through complex assessments, risk scoring, and remediation planning.
  • Partner with Procurement, Technology, Architecture, and business teams throughout the assessment lifecycle.
  • Ensure security requirements align with enterprise standards and risk tolerance.
  • Track assessment status, throughput, and aging and escalate issues as needed.
  • Contribute to continuous improvement of assessment processes, templates, and tools.
  • Support reporting on risk, findings, and program performance.
  • High School Diploma or equivalent required
  • Bachelor's Degree in related field or equivalent work experience strongly preferred
  • 5-7 years of experience in large and complex business environments with a successful track record working directly with senior level management with at least 3 years of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering or Operations, Information Technology, Application Development, Access Control, Security Governance, Risk Management, Software Development Security, Cryptography, Security Architecture and Design, Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, Physical (Environmental) Security, IT or Security Audit, IT or Security Compliance preferred
  • 2-3 years of experience securing cloud deployments on common platforms like Microsoft Azure, Amazon Web Services or Google Cloud Platform preferred
  • Experience with deploying environments by defining infrastructure as code (IaC) preferred
  • Experience with declarative IaC approaches and immutable infrastructure preferred
  • Experience with securing container deployments, Kubernetes, managed Kubernetes PaaS services, Agile environments and DevOps environments preferred
  • Experience with managing infrastructure through CI/CD pipelines preferred
  • Experience in documentation tools such as Visio and Microsoft Office products preferred
  • Experience with alternate management methods using SSH, serial connections and the command-line interface TMSH preferred
  • Hands-on experience performing cybersecurity risk assessments for vendors and applications.
  • Strong understanding of NIST CSF and NIST 800-53 control frameworks.
  • Experience evaluating third-party security documentation and application control designs.
  • Ability to coach and review the work of other analysts.
  • Strong organizational skills with attention to detail and consistency.
  • Comfortable engaging with business and technical stakeholders.
  • Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.
  • Competitive pay and bonus eligibility
  • Flexible hybrid work environment, 4-days a week in office
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service