General Motors LLC · Warren, MI
Senior Cybersecurity Engineer – Adversary Operations, Innovation & Purple Team Operations — Warren, MI
Full-timeWarren, MIPosted 2026-07-23Apply on Workday
Full job description
Job Description
The Role:
The Adversary Operations team is responsible for adversary emulations that test current capabilities, processes, and documentation, drive new cyber detection capability, and establish the baseline for strategic hunts. The Senior Cybersecurity Engineer will perform tactical purple operations, repeatable MSV-based testing, custom tooling, cloud and platform testing, and the annual red exercise used to validate security operations alerting and processes.
What You’ll Do
- Lead and execute tactical purple team operations aligned to real adversary tactics, including persistence, privilege escalation, lateral movement, and command-and-control testing.
- Design and run strategic, multi-step adversary emulation exercises that validate detections, processes, and team response across the enterprise.
- Build repeatable validation workflows using MSV and related tooling to continuously test visibility, logging, detections, and control effectiveness.
- Develop and enhance innovative adversary tooling, including custom C2, payload development, automation, and infrastructure required to support AO operations.
- Partner with Detection Engineering, Incident Response, and other cyber verticals to turn AO findings into improved detections, integrations, documentation, and threat hunting outcomes.
- Support AO innovation priorities across platforms, logging, cloud infrastructure, and cross-team integrations, including AWS, GCP, and Azure-related attack validation and infrastructure setup.
- Help mature AO capability in advanced and emerging areas such as cloud and SaaS tactics, endpoint tactics across multiple operating systems, AI-related tactics, and infrastructure-focused adversary tradecraft.
- Produce clear technical documentation, attribution, findings, and recommendations that feed operational improvements and future exercises.
- Significant hands-on experience in cybersecurity operations, adversary emulation, purple teaming, red teaming, threat hunting, or detection engineering.
- Strong understanding of attacker tactics, techniques, and procedures and the ability to translate them into repeatable testing scenarios.
- Experience with endpoint, cloud, network, and logging technologies used to validate detections and visibility gaps across enterprise environments.
- Experience building or using offensive and validation tooling such as payloads, C2 frameworks, automation, scripting, and infrastructure for safe adversary testing.
- Ability to collaborate across verticals and help coordinate actions that improve Cyber Defense outcomes at scale.
- Strong written and verbal communication skills with the ability to document findings, explain operational risk, and influence detection and response improvements.
- Experience with MSV or similar security validation tooling and the ability to create custom repeat actions for visibility validation.
- Experience in cloud and SaaS adversary tactics, including web and API attack paths.
- Experience supporting automotive, manufacturing, or other complex operational environments where security validation spans multiple technology domains.
- Familiarity with ATT&CK-aligned reporting, detection engineering feedback loops, and enterprise purple team programs.
#LI-SB3
About GM
Why Join Us
Benefits Overview
Accommodations