Manager, Offensive Security

General MotorsAustin, MI
Hybrid

About The Position

At General Motors, we are building secure software and connected experiences at scale. The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible disclosure, and clear feedback loops that help teams reduce risk before it becomes customer impact. This team helps uncover exploitable weaknesses, verify how well controls are performing, and provide actionable insights that improve remediation and prevention. This role is ideal for a leader who can grow a high-performing team, turn strategy into execution, and raise the security bar across a complex engineering environment.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
  • 10+ years of cybersecurity experience, including 5+ years in offensive security, penetration testing, red teaming, application security testing, or closely related disciplines.
  • 5+ years of people leadership experience, including hiring, performance management, coaching, workforce planning, and team development.
  • 3+ years leading complex, cross-functional security programs with measurable outcomes across multiple product, software, or platform teams.
  • Experience assessing or testing modern attack surfaces such as web applications, APIs, cloud services, identity systems, containers, developer tooling, or software delivery pipelines.
  • Demonstrated ability to define key performance indicators, prioritize competing work, communicate risk to technical and business stakeholders, and drive remediation to closure.

Nice To Haves

  • Experience building or leading offensive security programs in large-scale software, cloud, or product engineering environments.
  • Familiarity with responsible disclosure, vulnerability intake, or bug bounty program operations.
  • Experience partnering with development teams to improve secure design, detection, and resilience based on offensive testing results.
  • Knowledge of security automation, findings workflows, and telemetry-driven reporting.
  • Relevant industry certifications such as OSCP, OSWE, GPEN, GXPN, CISSP, or comparable credentials.
  • Experience in highly regulated, safety-critical, or large enterprise environments.

Responsibilities

  • Lead and develop a team responsible for penetration testing, adversary emulation, responsible disclosure triage, and verification of security controls across applications, platforms, and services.
  • Own the function roadmap, operating model, and key performance indicators, including coverage, remediation velocity, validation quality, and risk reduction outcomes.
  • Translate Cybersecurity strategy into quarterly priorities, staffing plans, resource allocation decisions, and clear execution goals for the team.
  • Partner with engineering and platform teams to turn offensive security findings into remediation actions, prevention improvements, and stronger secure-by-design practices.
  • Establish scalable testing approaches for web, API, cloud, identity, container, and software delivery environments, balancing depth, speed, and business risk.
  • Drive stakeholder communication, cross-functional alignment, and change leadership, including escalation of significant risks and recommendations for action.

Benefits

  • This job may be eligible for relocation benefits.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service