Principal Product Security Incident Responder (m/f)
Job Description Summary
Critical infrastructure is under attack — and the tools adversaries use are evolving faster than ever. At GE Vernova, the Product Security Incident Response Team (PSIRT) Principal sits at the front line of that reality: protecting the energy systems that power hospitals, cities, and grids from vulnerabilities that, left unaddressed, carry real-world consequences.Reporting directly to the VP of Product Cybersecurity, you will lead GE Vernova's enterprise PSIRT function — owning coordinated vulnerability disclosure, managing the company's CVE Numbering Authority (CNA) program, and directing product-related incident response across Power, Wind, and Electrification business units. You will also shape how AI-powered tooling is deployed to scale PSIRT capacity as the threat landscape accelerates.
This is a senior individual contributor role with enterprise-wide scope, high executive visibility, and direct engagement with government agencies, regulators, and critical infrastructure stakeholders.
Job Description
What You'll Do
- Lead vulnerability management and coordinated disclosure — operate the GE Vernova PSIRT end-to-end: triage, tracking, remediation coordination, and public disclosure aligned to industry standards and mandatory EU Cyber Resilience Act (CRA) notification timelines, including reporting to ENISA (European Union Agency for Cybersecurity) and national CSIRTs (Computer Security Incident Response Teams).
- Run the CNA program — manage the full lifecycle of CVE (Common Vulnerabilities and Exposures) records, ensuring timely and accurate public disclosures across all GE Vernova product lines.
- Direct product-related incident response — lead responses to cybersecurity incidents at customer sites, coordinating across engineering, legal, and commercial teams; maintain and exercise incident response playbooks to ensure consistent, rapid resolution.
- Deploy AI-powered tooling — automate vulnerability scoring, incident triage, and situational awareness to meet the growing volume of threats driven by large language models, autonomous agentic systems, and adversaries targeting operational technology (OT) environments.
- Build cross-functional partnerships and governance — align PSIRT operations with the enterprise CERT (Computer Emergency Response Team) function; embed PSIRT liaisons across business units; define and report on key performance metrics such as Mean Time to Remediate (MTTR) and disclosure compliance for executive leadership and enterprise risk reviews.
Who You Are
You bring significant experience in PSIRT operations and vulnerability management, with a track record of leading coordinated disclosure programs in complex, regulated, or industrial environments. You are comfortable engaging government authorities and law enforcement on sensitive matters, and you understand how emerging AI capabilities are reshaping the threat landscape for critical infrastructure.
Required
- Significant experience in cybersecurity, with deep expertise in PSIRT operations, vulnerability management, or product incident response in an industrial or energy context
- Proven leadership of a PSIRT function, including hands-on management of coordinated vulnerability disclosure (CVD) and customer-facing security incidents
- Experience engaging with law enforcement, government agencies, or national authorities on sensitive cybersecurity matters
- Deep familiarity with CVE, CVSS (Common Vulnerability Scoring System), CWE (Common Weakness Enumeration), and standards including ISO/IEC 29147 and ISO/IEC 30111
Preferred
- Direct experience with GE Vernova products or equivalent OT/industrial energy systems
- Familiarity with IEC 62443 security standards and energy-sector ISACs (Information Sharing and Analysis Centers), including E-ISAC (Electricity Information Sharing and Analysis Center)
- Experience building or scaling a PSIRT function from the ground up
- Professional certifications such as CISSP (Certified Information Systems Security Professional), GCIH (GIAC Certified Incident Handler), or GICSP (Global Industrial Cyber Security Professional)
Education
A formal education and subsequent Bachelor's or Master's degree in Cybersecurity, Computer Science, Engineering, or a related discipline is nice to have, but we are most interested in your total experience and professional achievements.
Why GE Vernova
GE Vernova employees rise to the challenge of building a world that works. In order to meet this mission, we provide varied, competitive benefits to help support our workforce. Our benefits are designed to reward high performers and help you manage your personal and family needs. We offer a robust benefits package depending on your employment status and your national requirements. A healthy, balanced lifestyle can mean different things to different people — we've created programs that support the way you live and work today. GE Vernova also invests to provide opportunities to grow your career by providing a path for continued on-the-job learning and development.
Additional Information
GE Vernova offers a great work environment, professional development, challenging careers, and competitive compensation. GE Vernova is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.
GE Vernova will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable).
Relocation Assistance Provided: No
Required Languages
🇬🇧 English