Associate Cybersecurity Analyst - Bilingual
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Sep 24, 2026
Why GMF Cybersecurity?
Innovation isn’t just a talking point at GM Financial; it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.
Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.
Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.
This position will be posted until filled.
About the role
The Associate Cybersecurity Analyst supports cybersecurity policy governance and regulatory compliance activities across multiple international authorities. This entry-level to early-career role assists in monitoring regulatory developments, conducting research and analysis, maintaining policy documentation, and supporting compliance initiatives. The Associate Cybersecurity Analyst works closely with Cybersecurity, Legal, Compliance, Privacy, Risk Management, Technology, and business stakeholders to help maintain alignment between cybersecurity policies, standards, and applicable regulatory requirements.
This position requires professional fluency in both English and Spanish to support global regulatory monitoring activities, communicate compliance requirements, and collaborate with stakeholders across diverse regions.
In this role you will:
Cybersecurity Policy Governance
Support cybersecurity policy governance activities to help maintain alignment with regulatory requirements, legal obligations, organizational objectives, and industry frameworks.
Assist with the full policy lifecycle, including development, review, approval, publication, communication, implementation, and periodic recertification.
Coordinate policy reviews and stakeholder engagement across Cybersecurity, Legal, Compliance, Privacy, Risk Management, Technology, and business teams.
Maintain policy governance documentation, repositories, implementation trackers, compliance evidence, milestones, action items, and remediation activities.
Participate in governance meetings, working groups, and review sessions; document outcomes, track follow-up actions, and support implementation efforts.
Prepare policy governance metrics, compliance summaries, management reports, and other governance-related communications.
Provide guidance on policy requirements and implementation expectations to support organizational compliance.
Regulatory Monitoring and Analysis
Research, monitor, and analyze cybersecurity regulations, regulatory guidance, compliance requirements, and industry standards.
Assist in translating regulatory requirements into cybersecurity policies, standards, procedures, controls, and implementation plans.
Support regulatory impact assessments, gap analyses, compliance initiatives, and remediation activities across applicable regulatory authorities.
Coordinate stakeholder engagement, evidence collection, and implementation activities related to regulatory compliance efforts.
Track regulatory implementation progress, including risks, dependencies, issues, corrective actions, and compliance outcomes.
Prepare regulatory updates, executive summaries, compliance metrics, and implementation status reports for leadership and stakeholders.
Partner with Legal, Compliance, Privacy, Risk Management, Technology, and business teams to support regulatory interpretation and implementation.
Identify opportunities to improve regulatory monitoring, reporting, and compliance processes through standardization, automation, and operational efficiencies.
What makes you an ideal candidate?
Professional fluency in English and Spanish (written and verbal).
Foundational knowledge of cybersecurity governance principles, regulatory compliance, and information security frameworks.
Sound analytical, organizational, communication, and documentation skills.
Ability to prioritize multiple assignments and collaborate effectively with cross-functional teams.
Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Teams.
Must have a high-level understanding of financial services industry, security, risk and privacy
Must have current knowledge and stay up-to-date on the latest Cybersecurity legislation, regulations, advisories, alerts and vulnerabilities
Must have knowledge of Information Security and Cybersecurity frameworks
Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Teams.
Knowledge of security methodologies, policies, standards and industry practices
Knowledge of information technology systems, infrastructure and operations
Understanding of cloud technologies and concepts
Familiarity with DevOps and Agile development process
Ability to initiate, facilitate and promote Cybersecurity within the organization and monitor adherence to Cybersecurity policies, standards and controls
Ability to clearly explain and articulate technical concepts using non-technical language
Foundational knowledge of cybersecurity governance principles, regulatory compliance, and information security frameworks.
Familiarity with cybersecurity frameworks and standards preferred, including:
NIST Cybersecurity Framework (CSF)
NIST SP 800-53
NIST SP 800-171
ISO 27001
Exposure to policy management platforms, workflow tools, or regulatory tracking solutions preferred
Additional Knowledge and Skills
Working effectively within an AI enabled environment:
Ability to use AI tools (e.g., Microsoft Copilot) to support daily work
Skills in evaluating AI outputs for accuracy, compliance, and bias
Experience integrating AI into workflows to improve efficiency or insights
Familiarity with AI assisted research, summarization, and content generation
Understanding of responsible AI use, including ethics and data protection
Experience and Education:
0-2 years of experience in large and complex business environments with a successful track record working directly with senior level management with working knowledge in one or more of the following domains: Access Control, Telecom and Network Security, Cybersecurity Governance, Risk Management, Software Development Security, Cryptography, Security Architecture and Design, Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, Physical (Environmental) Security, IT or Security Audit, IT or Security Compliance preferred
0-2 years of experience in the financial services industry preferred
0-2 years of demonstrable experience leading collaborative programs and projects with senior level management required
High School Diploma or equivalent required
Bachelor’s Degree or equivalent experience strongly preferred
What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.
Our Culture: Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.
Compensation: Competitive pay and bonus eligibility.
Work Life Balance: Flexible hybrid work environment, 4-days a week in office.
NOTE: We are unable to consider candidates who require visa sponsorship for this position
This position is not open to agency submissions
#GMFJobs #LI-Hybrid #LI-SC1