Product Security Engineer securing Grid Automation products for GE Vernova’s Grid Automation business. Applying SDL, vulnerability management, threat modeling, penetration testing and IEC 62443 standards.
Responsibilities
Implement the secure development life cycle (SDL), including security assessment, threat modelling, requirements definition, security architecture and design, penetration testing and secure deployment guide
Participate in the development and delivery of competitive product cyber security solutions to support targeted growth
Contribute to technology choices and design aligned with the overall Grid Automation cyber security strategy and roadmap
Share best practices and lessons learned and continuously update the technical cyber security architecture with product security leads, domain architects and experts
Recommend and participate in the design and implementation of standards, tools and methodologies in the research and development community of GEV Grid Automation
Develop and conduct relevant security training for product managers, software engineers and technical support
Implement the cyber security vulnerability and incident process, including vulnerability assessment, solution definition, external communication where applicable and drafting security advisories
Lead programs/projects and document, plan, market and execute programs
Requirements
Bachelor’s Degree from an accredited university in Engineering, Computer Science or Information Technology
Extensive experience with cyber security, preferably in an Operational Technology (OT) environment
Experience with Telecom and Network Equipment (Routers, Switches, Firewalls)
Experience with security technologies including LDAP, RADIUS, SSH, SFTP, HTTPS, SYSLOG
Experience with encryption, TLS, RSA and code signing
Experience with vulnerability assessment tools and penetration testing methodologies
Knowledge of cyber asset protection regulations and standards affecting the utilities industry, including NERC-CIP, NIST, IEC62443 and IEC62351
Knowledge of symmetric and asymmetric cryptography and PKI infrastructure
Cyber security certification such as ISC2, SANS, ISACA or CISSP is desired
Experience with programming and scripting languages
Knowledge of TCP/IP network stack, communication protocols and applications, including Modbus, DNP3 and IEC61850
Experience with Linux, VxWorks and Windows operating systems, including user account management, security/system hardening, device control and patch management
Excellent oral and written communications skills in English
Ability to work effectively in a team and across functions in a worldwide environment
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.
Information Security Manager leading enterprise EUC governance technology deployment and product roadmaps at TD, a global financial institution. Driving risk controls, adoption, delivery and assurance across business segments.
Principal Cloud Security Engineer securing Pax8’s cloud marketplace, infrastructure, and AI - enabled platforms. Establishing cloud, Kubernetes, identity, and software - delivery security standards across USA and Canada.
Cyber Security Engineer auditing diverse codebases, fixing vulnerabilities, and optimizing backend software. Contributing security insights and improvements to AI training datasets for a technology company.