Ensure the Services area follows applicable GE Vernova and Wind Cyber Security policies, standards, and procedures
Drive/support yearly security assessments for applicable environments (e.g., Generator Operator Control Room)
Support and conduct background checks for employees requiring access to the ROC and applicable customer sites, including sharing relevant information with customers as needed
Manage, including approvals, the access review process for logical access to the ROC, jump hosts, and applicable customer sites
Track and manage cybersecurity training for Services personnel
Review and approve changes to the environment, including servers and network devices
Maintain an accurate and up-to-date asset inventory of the Generator Operator Control Room environment
Support and participate in security reviews of Generator Operator Control Room systems to ensure compliance with security policies and standards
Define cyber assets and architecture for the Generator Operator Control Room environment with the Digital Technology team; own/manage architecture diagrams for the environment
Define and maintain physical access processes for the Generator Operator Control Room, applicable data centers
Coordinate and ensure physical access requirements for Services’ operations at customer sites
Review and manage patches and updates to the Generator Operator Control Room systems, ensuring systems are up-to-date with OS updates, antivirus updates, and Active Directory updates
Track and assess vulnerabilities for Generator Operator Control Room systems, working proactively to mitigate risks
Serve as the PSIRT point-of-contact, coordinating security incident response efforts for the in-scope environment
Document and manage recovery plans in collaboration with the Digital Technology team to ensure robust incident management and system recovery procedures
Be the Services liaison with customers who have cybersecurity questions for the Generator Operator Control Room environment
Take lead on reviewing applicable cyber and/or compliance regulations that may be applicable to the environment
Requirements
Bachelor’s Degree from an accredited university in Engineering, Computer Science, Cybersecurity, Information Technology, or related field
Minimum 8 years of experience in cybersecurity with at least 3 years focused on industrial control systems (ICS), operational technology (OT), or product security
Demonstrable in-depth knowledge and practical experience with applicable energy regulations including but not limited to NERC-CIP, NIS2, and/or SOCI
Strong knowledge of cyber security best practices and frameworks (e.g., NIST CSF, OWASP top 10)
Strong understanding of industrial communication protocols used in power generation, wind farms, SCADA systems, and other industrial environments (e.g., Modbus, DNP3, OPC [DA, AE, UA], IEC 61850)
Experience using cyber security vulnerability tools (e.g., Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), or other weakness / vulnerability scanning tools)
Benefits
Healthcare benefits include medical, dental, vision, and prescription drug coverage
Access to a Health Coach, a 24/7 nurse-based resource
Access to the Employee Assistance Program, providing 24/7 confidential assessment, counseling, and referral services
Retirement benefits include the GE Retirement Savings Plan, a tax-advantaged 401(k) savings opportunity with company matching contributions and company retirement contributions
Access to Fidelity resources and planning consultants
Other benefits include tuition assistance, adoption assistance, paid parental leave, disability insurance, life insurance, and paid time-off for vacation or illness
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
cybersecurityindustrial control systemsoperational technologyenergy regulationsNERC-CIPNIS2SOCINIST CSFOWASP top 10industrial communication protocols