Principal Cyber Security Architect (Remote Eligible, U.S.)
Job Description Summary
GE Vernova is seeking a highly skilled and experienced Principal Cyber Security Architect to join the Product Security team, focusing on the Wind portfolio of products. This role is responsible for conducting in-depth cyber security assessments of wind farm design and architecture at both the product and component levels. This includes leading these assessments in accordance with GE Vernova’s Secure Development Lifecycle (SDL) process, aligned with IEC 62443-4-1, and reviewing applicable requirements outlined in IEC 62443-4-2 and IEC 62443-3-2 standards. The role involves collaboration with various subsystem teams to identify relevant products and execute these assessments.This position reports to Wind's Product Security Leader, who oversees Wind's Product Security Team. The Product Security Team drives a product cyber security strategy aimed at meeting applicable standards and regulations while leading the industry towards more fundamentally secure wind farms.
Job Description
Essential Responsibilities:
- Lead and conduct comprehensive cybersecurity assessments of wind turbine components, SCADA systems, Wind Farm software, and digital service platforms following the defined engineering processes.
- Provide expert guidance on the interpretation and application of security controls following IEC 62443 series of standards (specifically IEC 62443-4-1 and IEC 62443-3-3) during the requirements definition, design development and product validation phases of the development lifecycle.
- Perform threat modeling and risk assessments for new and existing products and features.
- Identify and document security vulnerabilities, risks, and non-conformities within products and systems and provide recommendations for remediation.
- Collaborate closely with product development, engineering, projects, services, and R&D teams to integrate security by design principles throughout the product lifecycle.
- Propose recommendations and facilitate discussion on high level wind-farm level security improvements that can be driven across subsystems.
- Lead the development and management of new technologies to support cyber security assessments.
- Review customer-facing documentation to align it with security best practices and the as-designed security requirements.
- Contribute to the development and improvement of internal product security processes and guidelines, including hardening guides.
- Provide relevant technical guidance in response to customer inquiries and during product incident / vulnerability response activities
Required Qualifications:
- Bachelor’s Degree from an accredited university in Engineering, Computer Science, Cybersecurity, Information Technology, or related field.
- Minimum 12 years of relevant experience working with cybersecurity or operational technology (OT) with at least 8+ years of operational technology (OT) cybersecurity /product cybersecurity.
Eligibility Requirements:
- This is a fully remote role based anywhere in the U.S. We prioritize candidates located in the Greenville, SC or Schenectady, NY areas, as these are key hubs for our team
- Ability and willingness to travel up to 10%. Travel may be up to 20% if the candidate is not located in the Greenville, SC or Schenectady, NY areas
Desired Characteristics:
- Minimum 4 years of experience working with product security requirements, regulations and/or standards, such as IEC 62443 series of standards or equivalent.
- Demonstrated knowledge and understanding cybersecurity tools/solutions (e.g., Firewalls, antivirus, SIEM, IDS/IPS), including experience providing installation/configuration recommendations.
- Master's degree in a relevant field.
- Wind Turbine product knowledge and/or SCADA product/cyber security knowledge.
- Knowledge and understanding of network cyber security practices.
- Familiarity with containerization technologies (Docker, Kubernetes) and associated security best practices.
- Cyber security certification (ex. GICSP, CEH, CCNA, CISSP).
- Experience with cloud security principles and practices.
- Experience with secure coding practices in any language.
- Experience with penetration testing and vulnerability assessment tools for OT environments.
- Strong understanding of operational technologies (e.g., PLCs) and protocols (e.g., Modbus, Profinet, DNP3, OPC [DA, AE, UA], IEC 61850) used in manufacturing, power generation, wind farms, SCADA systems, and other industrial environments or industrial products.
- Ability to work independently and collaboratively as necessary with a cross-functional team.
- Strong oral and written communication skills. Demonstrated ability to analyze and resolve problems.
- Experience responding to product cyber security vulnerabilities.
- Experience responding cybersecurity inquiries.
GE Vernova offers a great work environment, professional development, challenging careers, and competitive compensation. GE Vernova is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.
GE Vernova will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable).
Relocation Assistance Provided: Yes
Required Skills
Required Languages
🇬🇧 English