Why GMF Cybersecurity?
Innovation isn’t just a talking point at GM Financial, it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.
Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.
Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.
This position will be posted until filled.
About the Role
The Cybersecurity Architect is responsible for the development and delivery of a comprehensive Cybersecurity program for General Motors Financial (GMF) to assure that information created, acquired, or maintained by GMF is used in accordance with its intended purpose and to protect GMF information, applications, and infrastructure from all threats. Additionally, the program will comply with all statutory and regulatory requirements for information protection, privacy, and cybersecurity.
In this role you will:
- Work with IT departments, IT Architects, data custodians, and governance groups to develop and update GMF Cybersecurity controls, requirements, processes, procedures for secure infrastructure and application architecture
- Determine security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security, vulnerability analyses, and risk assessments; reviewing architectures and designs; identifying integration issues; and preparing cost estimates
- Provide function and business requirements for security solutions, initiatives, and identified areas to improve GMF’s security posture
- Recommend and implement changes in security policies and practices in accordance with changes in regulatory or financial services industry cybersecurity practices
- Provide input to Engineers and Developers for additional configuration of application firewalls via IT project management and change management
- Manage the efforts to conduct Cybersecurity control assessments for systems which store customer or sensitive information whether hosted internally or cloud based
- Assess and communicate security risks associated with development practices in place at GMF
- Advise and drive the security maturity in all areas
- Assist Cybersecurity Management in creating, reviewing, and updating the Cybersecurity Strategy on a periodic basis
- Plan security systems by evaluating network and security technologies; developing requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related security and network devices; designs public key infrastructures (PKIs), including use of certification authorities (CAs) and digital signatures as well as hardware and software; adhering to industry standards
- Monitor adherence to standards in architecture, application design, development, and testing frameworks
- Partner with infrastructure, application, and other stakeholders to ensure deployed solutions minimize security and privacy risks
- Act as a mentor providing guidance to all team members on security issues
- Collaborate on the development and delivery of an education and training program on Cybersecurity and privacy for employees, contractors, and other authorized users
- Initiate, facilitate, and promote activities to create information security awareness within the organization