This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This role is categorized as hybrid. This means the successful candidate is expected to report to Warren, MI or Austin, TX three times per week, at minimum [or other frequency dictated by the business if more than 3 days]. GM’s Cybersecurity Team safeguards the company’s global information assets, networks, and infrastructure. Our mission is to proactively defend GM against evolving cyber threats through strategic leadership, technical excellence, and innovative risk management. We seek cybersecurity professionals with advanced expertise, capable of driving enterprise security initiatives and influencing organizational resilience. As a Third-Party Cybersecurity Incident Analyst, you will independently lead high-impact incident response activities involving GM’s third-party partners. This role requires strategic oversight, technical depth, and the ability to guide cross-functional teams through complex cyber investigations. You will serve as a trusted advisor, driving critical decision-making, influencing enterprise risk posture, and ensuring the integrity and continuity of GM’s business operations. You will collaborate with other GM teams and suppliers to assess attack vectors, coordinate containment, and evaluate strategic impacts, including information exposure, operational disruptions, and supply chain risks. The position demands high autonomy, initiative, and the ability to communicate complex technical findings to executive leadership and business stakeholders. This role requires innovative thinking, exceptional judgment, and broad application of cybersecurity principles to solve enterprise-wide challenges.
Job Responsibility:
Lead the triage, analysis, and escalation of critical third-party cybersecurity incidents, ensuring alignment with GM’s strategy
Assess incident impacts and urgency, guide containment actions, and provide expert advice to technical and non-technical stakeholders
Oversee investigations, incident tracking, and resolution, ensuring thorough documentation and reporting
Collaborate cross-functionally with Cyber Defense, GMIT, Legal, Purchasing, and leadership for effective response operations
Engage external partners to determine root causes and shape third-party risk management
Provide strategic support during high-priority and after-hours third-party incidents
Prepare and deliver executive-level reports and metrics to support informed decision-making
Mentor and guide others, fostering skill development across the team
Drive continuous improvement of incident response processes, tools, and methods
Coordinate communications with stakeholders and executive leadership, maintaining transparency and alignment during incidents