Jobs / United States / General Motors Company
Senior Cybersecurity Vulnerability Management Engineer
General Motors Company · 🇺🇸 Warren, Michigan, United States of America
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 606 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 267 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What General Motors Company paid sponsored hires in similar roles171 certified filings for “Senior Software Engineer” (Software Developers) in MI: $140k–$163k, median $150k. Most were filed at wage level IV (74%) — 4 lottery entries, ≈61% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — General Motors Company
The US Department of Labor certified 606 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 267 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for General Motors Company →
About the role
Job Description The Role: As a Senior Cybersecurity Vulnerability Engineer, you will serve as a highly capable individual contributor responsible for designing, implementing, and improving cybersecurity capabilities that protect GM’s risk domains of people, products, partners, platforms, and production. The successful candidate is a senior experienced professional who can independently assess complex vulnerability and exposure risks, translate threat intelligence and technical findings into actionable remediation priorities, and influence outcomes across infrastructure, cloud, application, manufacturing, and security stakeholder groups. The senior engineer will have significant functional impact through risk-based decision-making, operational leadership, and mentorship of engineers and remediation partners. You will solve diverse, non-standard security problems; translate broad challenges into implementable initiatives; and drive delivery across teams through technical leadership, sound judgment, and influence. This role has significant operational impact across the cybersecurity organization that serves as a mentor and resource for other team members. What You'll Do: • Lead engineering, operational improvement, and continuous maturity of GM Vulnerability Management core services across enterprise infrastructure, client endpoints, multi-cloud, and AI security threat exposure domains. • Serve as a senior individual contributor for Enterprise Data Center Infrastructure vulnerability management, including server, endpoint, network, virtualization, patch coordination, exception handling, on-prem asset hygiene, and remediation prioritization for critical infrastructure. • Drive client endpoint vulnerability management by reducing endpoint risk through continuous detection, patching, browser and software update compliance, control enforcement, and remediation guidance across corporate and manufacturing endpoint environments. • Lead multi-cloud vulnerability management across Azure, AWS, and GCP, including workload exposure, misconfiguration correlation, cloud VM risk, container image and runtime exposure, and cloud-to-business criticality mapping to support risk-based remediation. • Build and mature AI security threat vulnerability management capabilities for AI workloads, model supply chain risk, prompt injection, data leakage, agent permissions, tool-use guardrails, model and runtime control validation, and secure rollout patterns for internal AI capabilities. • Correlate scanner findings with asset, business, network, telemetry, identity, threat-intelligence, and SBOM context to improve prioritization accuracy and focus remediation on exposures most likely to create business risk. • Apply threat intelligence and exploitability analytics, including exposure context, attack-path factors, and evidence of exploitation, to move prioritization beyond severity-only scoring. • Partner with infrastructure, endpoint, cloud platform, manufacturing, application, and Security Fitness stakeholders to convert findings into actionable remediation plans, drive accountability, and accelerate closure of urgent, critical, and high-risk issues. • Support and improve Vulnerability core functions including asset discovery and inventory, vulnerability scanning and assessment, threat intelligence and risk context, prioritization and risk scoring, remediation and patch coordination, exception management, reporting, dashboards, governance, integration, automation, and continuous improvement. • Contribute to workflow integration and automation across detection, security unification tools, automated patching orchestration, and related platforms, while maintaining appropriate guardrails and human approval for meaningful changes to critical environme