Cybersecurity Architect
GM Financial
2024-11-08 09:41:28
Irving, Texas, United States
Job type: fulltime
Job industry: Construction
Job description
Overview:
Opportunity to work in a hybrid model: Potential to work 4 days onsite and 1 day remote
Why GMF Cybersecurity?
Our Cybersecurity team is tasked with the security engineering, regulatory response, third party risk, and incident response capabilities necessary to secure GM Financial, the captive auto finance subsidiary of General Motors. Reporting directly to the CEO, our Cybersecurity team enjoys unprecedented support to deliver the highest level of security capabilities using cutting edge technologies and automating mundane tasks, allowing our teams to focus on interesting and rewarding security work. As a part of GM, you'll have the opportunity to work on Cybersecurity projects across financial services, automotive, manufacturing, high-tech, and military industries. We are looking for team players who want the freedom to innovate leading edge capabilities to join our growing Cybersecurity team.
Responsibilities:
The Cybersecurity Architect is responsible for developing, delivering, and validating security requirements for GMF business initiatives. In this capacity, the Cybersecurity Architect assesses, reviews, and threat profiles functional and non-functional requirements, project scope details, architectural designs, and GMF policies and standards to formulate a list of specific technical and non-technical security requirements for assigned projects. The Architect also executes validation tests to ensure delivered requirements have been implemented. As a Cybersecurity Architect, you will be at the forefront of GMF strategic initiatives and leading the charge to securely enable the business. A successful Cybersecurity Architect can translate a variety of project, organizational, and design details into a clear list of requirements for business and IT teams to execute. This position requires an individual that can communicate effectively and build rapport with business teams and translate complex technical information into clearly understood expectations. The position also requires an individual that works well with others, performs in challenging situations, and is pragmatic and motivated by long-term results while addressing short term needs.
About the role:
Enable the business in its strategic initiatives by consistently applying the appropriate level of security controls, ensuring alignment with Cybersecurity Guiding Principles
Deliver and validate security requirements for applications, solutions, networks, data warehouses, data analytics, automation, cloud environments, borderless networks, and initiatives that optimize resource usage based on a thorough understanding of security and operational risks
Determine and validate security requirements by evaluating business strategies and requirements, researching information security standards, reviewing and threat modeling architecture designs
Utilize blueprints and design patterns to secure secure application, network, and product development business initiatives
Recommend any changes in security policies and practices to support the ongoing alignment between architectural designs, patterns, and GMF strategic initiatives
Adapt and refine existing frameworks to enhance the maturity and optimization of security controls and services or suggest alternatives to bolster security effectiveness
Participate in the review and approval of key operational control mechanisms to ensure the overall security and protection of the environment and adherence to Cybersecurity process workflows
Qualifications:
What makes you a dream candidate?
Proven experience with Cloud Security industry standards and a verified background with Cloud Solutions, especially in AWS, Azure, OCI, IBM, and various SaaS solutions
Proven experience with delivering and validating security requirements
Familiarity with authentication solutions such as SSO, Oauth, MFA, and IAM
Exceptional analytical and technical skills with strong capabilities in architecture and development
Outstanding interpersonal skills with the proficiency to engage with executive stakeholders
Experience in implementing technical solutions that resolve business challenges while understanding new technological capabilities
Proven leadership in the establishment and application of technical guidelines
In depth, hands-on understanding in application architecture and technology including web applications, mobile technology, and identity and access management
Possesses knowledge in various information security areas, such as: Identity and Access Management, Threat and Vulnerability Management, Information Risk and Governance, IT architecture, Cloud Architecture, Monitoring, Incident Response, and Security Strategy
Experience
Bachelor's Degree in Information Technology, Information Security, Information Assurance, Information Management in related field or equivalent work experience required
Experience with the financial industry and regulations required
Experience with firewalls, IDS, log management and troubleshoot network devices required
Experience with managing infrastructure through CI/CD pipelines required
7-10 years experience in Information Technology or Cybersecurity as an Architect or Engineer with Security knowledge and skill preferred
2-4 years of experience securing cloud deployments on common platforms like Microsoft Azure, Amazon Web Services, or Google Cloud Platform preferred
Experience with securing container deployments, Kubernetes, managed Kubernetes PaaS services, Agile environments, and DevOps environments preferred
Licenses
Certification in one or more Cybersecurity disciplines (CISSP or CISM) or equivalent experience required
Certifications in Cloud Cybersecurity (eg, CCSP, CCSK, or cloud provider specific) preferred
What We Offer: Benefits effective your first day, 401K, Bonding leave for new parents (12 weeks and 100% paid), Pet insurance, training, certifications
Our Culture: Our team members define and shape our culture - an environment that welcomes new ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work - we thrive.
Compensation: Competitive Salary
Work Life Balance: Flexible hybrid work environment, 4 days onsite and 1 remote
Benefits Package: Generous benefits package