Ensure the Services area follows applicable GE Vernova and Wind Cyber Security policies, standards, and procedures
Drive/support yearly security assessments for applicable environments (e.g., Generator Operator Control Room)
Support and conduct background checks for employees requiring access to the ROC and applicable customer sites
Manage, including approvals, the access review process for logical access to the ROC, jump hosts, and applicable customer sites
Track and manage cybersecurity training for Services personnel
Review and approve changes to the environment, including servers and network devices
Maintain an accurate and up-to-date asset inventory of the Generator Operator Control Room environment
Support and participate in security reviews of Generator Operator Control Room systems to ensure compliance with security policies and standards
Define cyber assets and architecture for the Generator Operator Control Room environment with the Digital Technology team; own/manage architecture diagrams for the environment
Define and maintain physical access processes for the Generator Operator Control Room, applicable data centers
Coordinate and ensure physical access requirements for Services’ operations at customer sites
Review and manage patches and updates to the Generator Operator Control Room systems
Track and assess vulnerabilities for Generator Operator Control Room systems, working proactively to mitigate risks
Serve as the PSIRT point-of-contact, coordinating security incident response efforts for the in scope environment
Document and manage recovery plans in collaboration with the Digital Technology team to ensure robust incident management and system recovery procedures
Be the Services liaison with customers who have cyber security questions for the Generator Operator Control Room environment
Requirements
Bachelor’s Degree from an accredited university in Engineering, Computer Science, Cybersecurity, Information Technology, or related field
Minimum 8 years of experience in cybersecurity with at least 3 years focused on industrial control systems (ICS), operational technology (OT), or product security
Demonstrable in-depth knowledge and practical experience with applicable energy regulations including but not limited to NERC-CIP, NIS2, and/or SOCI
Strong knowledge of cyber security best practices and frameworks (e.g., NIST CSF, OWASP top 10)
Strong understanding of industrial communication protocols used in power generation, wind farms, SCADA systems, and other industrial environments (e.g., Modbus, DNP3, OPC [DA, AE, UA], IEC 61850)
Demonstrated knowledge and understanding cybersecurity solutions (e.g., Firewalls, antivirus, security incident and event management systems, intrusion detection systems, intrusion prevention systems), including experience providing installation/configuration recommendations
Experience using cyber security vulnerability tools (e.g., Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), or other weakness / vulnerability scanning tools)
Benefits
Healthcare benefits include medical, dental, vision, and prescription drug coverage
Access to a Health Coach, a 24/7 nurse-based resource
Access to the Employee Assistance Program, providing 24/7 confidential assessment, counseling and referral services
GE Retirement Savings Plan, a tax-advantaged 401(k) savings opportunity with company matching contributions and company retirement contributions
Access to Fidelity resources and planning consultants
Tuition assistance
Adoption assistance
Paid parental leave
Disability insurance
Life insurance
Paid time-off for vacation or illness
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
cybersecurityindustrial control systemsoperational technologycyber security best practicesenergy regulationsNERC-CIPNIS2SOCindustrial communication protocolscybersecurity solutions