Product Security Engineer - Cyber security - IEC 62443
GE Vernova Markham, Ontario, Canada · CA$126K–CA$176K/yr
Energy Technology · 10,001+ employees
About the role
The Product Security Lead will implement the secure development lifecycle and manage incident and vulnerability processes for Grid Automation products. They will also contribute to technology design decisions and provide security training to internal teams.
What they look for
Requirements
Candidates must hold a Bachelor's degree in Engineering, Computer Science, or IT and possess extensive experience in cyber security, particularly within Operational Technology environments. Proficiency in security standards like IEC 62443 and experience with network equipment and vulnerability assessment tools are required.
Benefits
Full description
Job Description Summary
The Product Security Lead has the mission to apply the Secure Development Lifecycle (SDL) process and the incident and vulnerability management process to Grid Automation products.#LI-ML2
Job Description
Essential Responsibilities
- Implement the secure development life cycle (SDL), including security assessment, threat modelling, requirements definition, security architecture and design, penetration testing and secure deployment guide.
- Participate in the development and delivery of competitive product cyber security solutions, to support targeted growth.
- Contribute in decisions related to technology choices and design, for alignment with the overall Grid Automation cyber security strategy and roadmap.
- Share best practices and lessons learned and continuously update the technical cyber security architecture, based on changing technologies, in collaboration with other product security leads, domain architects and experts.
- Recommend and participate in the design and implementation of standards, tools, and methodologies in the research and development community of GEV Grid Automation.
- Develop and conduct relevant security training for various internal audience, such as product managers, software engineers and technical support.
- Implement the cyber security vulnerability and incident process, including vulnerability assessment, solution definition (in collaboration with the development team), communication with external parties where applicable and drafting the security advisories.
- Knowledge of cyber asset protection regulations and standards affecting the utilities industry including NERC-CIP, NIST, IEC62443, IEC62351
Required Qualifications
- Bachelor’s Degree from an accredited university in Engineering, Computer Science or Information Technology
- Extensive experience with cyber security, preferably in an Operational Technology (OT) environment.
- Experience with Telecom and Network Equipment (Routers, Switches, Firewalls)
- Experience with security technologies, such as
- LDAP, RADIUS, SSH, SFTP, HTTPS, SYSLOG
- Encryption, TLS, RSA and code signing
- Experience with vulnerability assessment tools and penetration testing methodologies.
Desired Characteristics
- Symmetric and asymmetric cryptography and PKI infrastructure
- Cyber security certification (ex. ISC2, SANS, ISACA, CISSP)
- Experience with programing and scripting languages.
- Demonstrated knowledge and understanding of the TCP/IP network stack, communication protocols and applications, including Modbus, DNP3, IEC61850.
- Demonstrated experience with Linux, VxWorks and Windows operating systems including user account management, security / system hardening, device control, and patch management.
- Excellent customer service mind-set
- Demonstrated ability to lead programs / projects. Ability to document, plan, market, and execute programs. Established project management skills.
- Excellent oral and written communications skills in English
- Ability to work effectively in a team and across functions, partnering with other teams in a worldwide environment
For candidates applying to a Canadian-based position, the pay range for this position is between $126,000 - $176,000 CAD. The specific pay offered may be influenced by a variety of factors, including the candidate’s experience, education, and skill set.
Bonus eligibility: discretionary annual bonus.
This posting is for an existing vacancy.
Additional Information
Relocation Assistance Provided: Yes
Similar roles
-
Information Security Engineer
MEDITECH Canton, Massachusetts, United States · $66K–$105K/yr
-
Information Security Engineer
RSC2 INC Aberdeen Proving Ground, Maryland, United States · $105K–$245K/yr
-
Cybersecurity Analyst
Saxton & Stump Manheim Township, Pennsylvania, United States
-
Electronic Security Engineer
CertiPath Inc Arlington, Virginia, United States · $110K–$125K/yr
-
Information Systems Security Engineer
Booz Allen Hamilton Warner Robins, Georgia, United States · $99K–$225K/yr
-
Cybersecurity, Engineering, and Technology Implementation Support Engineer
Booz Allen Hamilton North Charleston, South Carolina, United States · $87K–$198K/yr