Jobs / United States / General Motors Company
Senior Product Cybersecurity Engineer – Secure Product Architecture
General Motors Company · 🇺🇸 2 Locations
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 606 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 267 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What General Motors Company paid sponsored hires in similar roles171 certified filings for “Senior Software Engineer” (Software Developers) in MI: $140k–$163k, median $150k. Most were filed at wage level IV (74%) — 4 lottery entries, ≈61% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — General Motors Company
The US Department of Labor certified 606 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 267 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for General Motors Company →
About the role
Job Description The Role The Senior Product Cybersecurity Engineer, Secure Product Architecture role sits within the broader Product Cybersecurity organization at General Motors and focuses on the security design that protects how in-vehicle systems communicate, spanning message authentication, in-vehicle firewalls, and in-vehicle Ethernet security. This engineer acts as a security design owner for in-vehicle communications, translating threat assessments and architectural decisions into clear, actionable security requirements that engineering and supplier teams can implement across current and next-generation software-defined vehicle platforms. What You’ll Do • Own and evolve the security design for in-vehicle communications, including message authentication (SecOC) , in-vehicle firewalls, and in-vehicle Ethernet security. • Translate threat assessments and architectural decisions into clear, testable security requirements that engineering and supplier teams can implement. • Right-size requirements against supplier and platform capability, adjusting scope where requirements are not achievable rather than carrying them forward. • Lead and support security design and implementation reviews across internal teams and suppliers to ensure security controls are deployed correctly. • Keep the security design and its specifications current with software-defined vehicle delivery timelines and platform changes. • Serve as a subject-matter expert for in-vehicle communications security and build self-service references so the broader team can scale. Your Skills & Abilities (Required Qualifications) • 6+ years of experience in product, embedded, or vehicle cybersecurity, with hands-on ownership of security design and requirements. • Strong working knowledge of in-vehicle communications security, including message authentication, firewalls, and automotive Ethernet. • Solid understanding of embedded security principles such as secure communication, key and certificate lifecycle management, replay/freshness protection, and secure provisioning. • Experience owning security design and translating it into technical requirements and specifications for internal teams and suppliers across the development lifecycle. • Demonstrated ability to lead security design and implementation reviews and align stakeholders across engineering, validation, and supplier teams. • Bachelor’s or master’s degree in Computer Science , Computer Engineering, Electrical Engineering, Cybersecurity, or equivalent practical experience. What Will Give You A Competitive Edge (Preferred Qualifications) • Experience with software-defined vehicle architectures and service-based in-vehicle communication. • Experience working across supplier-delivered ECU, firewall , and secure firmware ecosystems. • Experience with AUTOSAR SecOC, Freshness Value Management (FVM), Automotive Ethernet (SOME/IP, DoIP , TLS), CAN/CAN-FD, and UDS (ISO 14229) security services. • Prior embedded development experience with programming languages such as C, C++, Java, or Python. • Prior role(s) in the automotive industry or a similarly complex, deadline-driven, and regulated field. • Familiarity with the threat assessment (TARA) process and translating threat outputs into security requirements. What You’ll Bring • Deep ownership instinct — you drive requirements and blocked items to closure rather than waiting for others. • A pragmatic approach that balances security rigor against real supplier capability and vehicle program timing. • Clear technical judgment on risk and how security requirements should be specified and implemented. • Strong communication skills and a habit of packaging knowledge so teams can scale without dependi