Cybersecurity Analyst
Job Description
GM Financial offers a hybrid work environment in Irving, TX, with a generous benefits package available on day one. You will have access to 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay, and nine company holidays. The team shapes a culture built on innovative ideas, integrity, and community and belonging. Compensation includes competitive pay with bonus eligibility.
Responsibilities
In this role, you coordinate the Cybersecurity Issues Management process and manage issues through the remediation lifecycle. That includes intake, assignment, remediation validation, and closure, with a focus on keeping remediation on track.
- Manage cybersecurity issues throughout the remediation lifecycle, from intake and assignment through remediation validation and closure.
- Partner with issue owners and technical stakeholders to document remediation plans, target dates, key milestones, and progress toward remediation objectives.
- Perform ongoing follow-up to monitor remediation efforts, identify obstacles, drive accountability, and escalate risks, delays, and aging issues as appropriate.
- Research and interpret technical issues across network, Active Directory, web application, cloud, and infrastructure security domains to communicate risk and remediation plans to both technical and non-technical stakeholders.
- Coordinate regularly with Offensive Security and other Cybersecurity teams on finding status and validation requirements.
- Maintain accurate documentation, remediation records, status updates, and supporting evidence in designated workflow and tracking systems.
- Develop and deliver reporting and metrics to provide leadership visibility into remediation progress, issue aging, trends, and overall cybersecurity risk posture.
- Identify opportunities to improve issue management processes, reporting capabilities, and governance practices to increase efficiency, consistency, and stakeholder experience.
Requirements
- At least 1 year of experience in remediation management, issues management, vulnerability management, or a closely related role with direct exposure to tracking and remediating cybersecurity findings.
- Working familiarity with common security and reconnaissance tooling to interpret and validate output, plus basic scripting ability (PowerShell or Bash preferred).
- Foundational understanding of cybersecurity principles, vulnerabilities, threats, and security controls.
- Ability to analyze information, identify trends, and evaluate potential business and risk impacts.
- Strong organizational skills to manage competing priorities and deadlines in a fast-paced environment.
- Effective written and verbal communication skills, including tailoring messages for technical and non-technical audiences.
- Ability to build collaborative relationships across cybersecurity, technology, and business teams.
- Knowledge of cybersecurity frameworks and industry standards such as NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27001, or similar frameworks.
- Understanding of common technology domains including networking, infrastructure, cloud, identity and access management, and application security.
- Strong analytical, problem-solving, and critical thinking skills.
- Experience interpreting technical documentation, issues, vulnerabilities, and remediation evidence.
- Experience with issue tracking, workflow management, reporting, or cybersecurity platforms is preferred.
- Demonstrated ability to independently investigate technical findings using open-source research to proactively close gaps in technical understanding.
- High School Diploma or equivalent.
Technologies
- PowerShell, Bash, SSH, serial connections, TMSH
- Active Directory, web application, cloud
- NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27001
- Visio, Microsoft Office products, UML Design Tools
Licenses and Certifications
Information Security Certifications are strongly preferred.