Cybersecurity Engineer – PKI & Secrets Management
General MotorsAbout the role
Job Description
The Role
The Cyber Security Engineer – PKI & Secrets Management acts as a senior domain expert for PKI and secrets, providing technical leadership, hands-on engineering, and cross-team guidance for certificate lifecycle management, key management, hardware security modules (HSMs), and enterprise secrets platforms. The role partners closely with Security Services, infrastructure, cloud, application, and product teams to ensure cryptographic services are reliable, scalable, and aligned with GM security standards and regulatory requirements.
What You’ll Do
Serve as the primary subject matter expert for at least one major PKI or secrets platform (e.g., enterprise CAs, HSM-backed key management, or central secrets management platform), including strategy, architecture, and day-to-day engineering
Design, implement, and maintain certificate lifecycle management solutions supporting servers, applications, devices, and services across on‑prem and cloud environments
Engineer, harden, and operate PKI components, including root and subordinate CAs, OCSP/CRL infrastructure, key storage, and associated monitoring and audit capabilities
Lead design and integration of secrets management patterns (e.g., application secrets, API keys, database credentials, service identities), driving standardization and automation for onboarding new use cases
Define and document PKI and secrets management standards, patterns, and reference architectures for use by application and infrastructure teams across GM
Provide technical leadership on Cyber Security projects related to identity, access, encryption, and secure connectivity, ensuring PKI and secrets requirements are captured, implemented, and validated
Collaborate with software, cloud, and infrastructure teams to embed secure-by-default cryptographic practices (e.g., TLS, mutual auth, certificate pinning, key rotation) in platforms and services
Lead root cause analysis and remediation for PKI/secrets-related incidents or outages, driving durable fixes, improved monitoring, and lessons-learned back into standards and runbooks
Develop automation and tooling (e.g., scripting, APIs, workflows) to reduce manual certificate and secrets operations, improve consistency, and increase coverage across fleets and environments
Participate in threat analysis and risk assessment activities where cryptography, keys, and certificates are central controls, translating findings into practical mitigation plans
Mentor and support other engineers on PKI, cryptography, and secrets management topics; provide clear guidance, design reviews, and hands-on assistance to project and platform teams
Represent the PKI & Secrets Management domain in internal forums, architecture reviews, and change control, ensuring changes that impact cryptographic services are well understood and properly evaluated
Contribute to and help own security metrics and KPIs related to certificate hygiene, secrets lifecycle health, coverage, and platform reliability; drive action plans when targets are not met
Lead development and execution of Cyber Security projects where PKI, certificate management, and secrets are primary enablers, from requirements definition through design, implementation, and operational transition
Exercise independent judgment on significant cryptographic and platform decisions, balancing security, reliability, and developer experience, and clearly articulating tradeoffs to stakeholders
Act as a recognized senior Cyber Security engineer with deep expertise in PKI & secrets and broad knowledge of adjacent areas (identity, network security, cloud security, compliance, and risk)
Break complex security and reliability problems into actionable initiatives, orchestrating work across Security Services, infrastructure, and application teams
Champion change management by driving adoption of updated PKI roots/intermediates, new secrets patterns, and improved lifecycle processes across legacy and modern platforms
Serve as a mentor and go‑to resource for junior and mid-level Cyber Security engineers, modeling GM’s behaviors and engineering best practices
Your Skills & Abilities (Required Qualifications):
Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, Information Technology, or a closely related field; or equivalent experience
Strong hands-on experience with enterprise PKI concepts and technologies, including: X.509 certificates, key pairs, certificate chains, and trust stores
Certificate issuance, renewal, revocation, CRLs/OCSP, and policy
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s