Product Security Analyst
Job Summary
Roles and Responsibilities:
Compliance & Regulatory Execution:
- Program Implementation: Execute cybersecurity policies and procedures aligned with industry standards (IEC 62443 NERC CIP ISO 27001 NIST).
- Certification Support: Serve as a key contributor to product certification cycles ensuring technical documentation meets the requirements of IEC 62443 or similar standards.
- Gap Assessment: Conduct regular product gap assessments identifying and documenting misalignments between current technical implementations and regulatory requirements.
- Audit Liaison: Manage evidence collection and documentation for external audits ensuring timely responses to auditor inquiries.
Vulnerability Management & Technical Analysis:
- Operational Ownership: Manage the end-to-end vulnerability lifecyclescanning prioritizing tracking and coordinating remediation efforts for identified security weaknesses.
- SDLC Integration:Collaborate directly with development teams to improve the Secure Development Lifecycle (SDLC) process.
- Tooling Execution:Manage and optimize Open Source Software (OSS) Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) scans to proactively identify vulnerabilities.
- SBOM Management:Streamline the generation maintenance and transparency of Software Bill of Materials (SBOM) to ensure supply chain security.
- Technical Analysis: Perform root-cause analysis on security findings; develop and test remediation plans for moderate-complexity issues.
- Risk Management: Perform risk assessments on product components translating technical findings into actionable risk-reduction strategies for engineering stakeholders.
Execution & Continuous Improvement:
- Project Delivery: Manage assigned workstreams within larger program plans ensuring tasks are completed on schedule and meet quality standards.
- Design Integration: Participate in technical design reviews actively championing secure by design principles and providing security guidance to software/systems engineers.
- Process Efficiency: Proactively identify bottlenecks in current security processes and suggest improvements to increase the effectiveness of vulnerability management and compliance workflows.
Collaboration & Professional Growth:
- Technical Guidance: Act as a technical resource for junior staff or interns; document findings to share knowledge across the broader security team.
- Stakeholder Engagement: Communicate security requirements and remediation priorities clearly to cross-functional teams including product management and engineering.
- Professional Development: Stay current on evolving OT threats and regulatory updates applying new knowledge to refine product security practices.
Required Qualifications:
- Bachelors/Masters in Electronics Electrical Cybersecurity Information Technology Computer Science or a related technical field.
- 35 years of professional experience in cybersecurity compliance vulnerability management or a related technical engineering role.
- Demonstrated experience working with cybersecurity frameworks (e.g. NIST ISO 27001) and familiarity with OT-specific standards (e.g. IEC 62443 NERC CIP).
- Experience with vulnerability scanning and management tools (e.g. Nessus Qualys Tenable).
Desired Qualifications:
Experience with Industrial Control Systems (ICS) or OT security in an energy or manufacturing environment.
Proficiency in scripting (e.g. Python PowerShell) for automating security tasks or report generation.
Ability to work independently with minimal supervision on technical project tasks.
Certifications: CEH Security will be an added advantage.
Relocation Assistance Provided: Yes
Required Experience:
IC
About Company
GE Vernova's Asset Performance Management software can help you increase asset reliability, minimize costs and reduce operational risks. View a demo today.