GM Financial is hiring: Cybersecurity Team Lead - Risk in Irving
GM Financial, Irving, TX, United States, 75084
Join to apply for the Cybersecurity Team Lead - Risk role at GM Financial.
Flexible hybrid work environment, 4 days a week in the office.
Why GMF Cybersecurity
Our Cybersecurity team is tasked with security engineering, regulatory response, third‑party risk, and incident response capabilities necessary to secure GM Financial, the captive auto finance subsidiary of General Motors. Reporting directly to the CEO, the team enjoys unprecedented support to deliver the highest level of security capabilities using cutting‑edge technologies and automating mundane tasks, allowing team members to focus on interesting and rewarding security work.
As part of GM Financial, you’ll have the opportunity to work on cybersecurity projects across financial services, automotive, manufacturing, high‑tech, and military industries. We are looking for team players who want the freedom to innovate leading‑edge capabilities to join our growing cybersecurity team.
Responsibilities
- The Cybersecurity Risk Team Lead is responsible for leading day‑to‑day execution of the Cyber Vendor Risk Assessment and Cyber Application Risk Assessment programs.
- The role reports to the Assistant Vice President, Cybersecurity and serves as the primary owner of assessment quality, workflow execution, and partner engagement across both programs.
- The Team Lead will coach analysts, ensure consistent risk evaluations, and work closely with business, technology, and procurement partners to ensure cybersecurity risks are clearly identified, documented, and managed in alignment with standards and best practices.
- Lead daily operations for Vendor Risk and Application Risk assessments.
- Review and approve risk assessments for quality, consistency, and accuracy.
- Guide analysts through complex assessments, risk scoring, and remediation planning.
- Partner with Procurement, Technology, Architecture, and business teams throughout the assessment lifecycle.
- Ensure security requirements align with enterprise standards and risk tolerance.
- Track assessment status, throughput, and aging and escalates issues as needed.
- Contribute to continuous improvement of assessment processes, templates, and tools.
- Support reporting on risk, findings, and program performance.
What Makes You a Dream Candidate
- Hands‑on experience performing cybersecurity risk assessments for vendors and applications.
- Strong understanding of NIST CSF and NIST 800‑53 control frameworks.
- Experience evaluating third‑party security documentation and application control designs.
- Ability to coach and review the work of other analysts.
- Strong organizational skills with attention to detail and consistency.
- Comfortable engaging with business and technical stakeholders.
Qualifications
- High School Diploma or equivalent required.
- Bachelor’s Degree in related field or equivalent work experience strongly preferred.
- 5‑7 years of experience in large and complex business environments with a successful track record working directly with senior level management with at least 3 years of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering or Operations, Information Technology, Application Development, Access Control, Security Governance, Risk Management, Software Development Security, Cryptography, Security Architecture and Design, Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, Physical (Environmental) Security, IT or Security Audit, IT or Security Compliance preferred.
- 2‑3 years of experience securing cloud deployments on common platforms such as Microsoft Azure, Amazon Web Services or Google Cloud Platform preferred.
- Experience with deploying environments by defining infrastructure as code (IaC) preferred.
- Experience with declarative IaC approaches and immutable infrastructure preferred.
- Experience with securing container deployments, Kubernetes, managed Kubernetes PaaS services, Agile environments and DevOps environments preferred.
- Experience with managing infrastructure through CI/CD pipelines preferred.
- Experience in documentation tools such as Visio and Microsoft Office products preferred.
- Experience with alternate management methods using SSH, serial connections and the command‑line interface TMSH preferred.
What We Offer
Generous benefits package available on day one, including 401(k) matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay, and nine company holidays.
Our Culture
Our team members define and shape our culture—an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work—we thrive.
Compensation
Competitive pay with bonus eligibility.
Work Life Balance
Flexible hybrid work environment, 4 days a week in office.
Seniority Level
Mid‑Senior level.
Employment Type
Full‑time.
Job Function
Information Technology.