Jobs and Careers
GE

Principal - Secure Procurement Leader

GE Vernova
Remote, United States, United StatesRemotefull_timeVerifiedPosted 14 Aug 2026
💰 $245,000/yr($147,000/yr$245,000/yr)

About the role

Job Description Summary

The Opportunity

Critical energy infrastructure depends on the security of every component inside it. As GE Vernova's Secure Procurement Leader, you will own the program that ensures every third-party hardware, software, firmware, and service integrated into GE Vernova commercial products meets rigorous cybersecurity standards — before it ever reaches a customer.

This is a high-visibility, cross-functional role at the intersection of supply chain, product security, and regulatory compliance. You will set supplier security requirements, lead assessments and audits, embed cybersecurity obligations into procurement contracts, and advance Software Bill of Materials (SBOM) adoption across GE Vernova's global supplier base. Your work directly protects the reliability and security of the energy systems that power modern life.

Job Description

What You'll Do

  • Own and evolve the Secure Procurement Program end-to-end, defining supplier cybersecurity requirements, policies, and contractual obligations aligned with ISA/IEC (International Society of Automation / International Electrotechnical Commission) 62443-2-4 and 62443-2-1 standards.
  • Lead supplier assessments and audits, including questionnaire-based reviews, remote evaluations, and on-site assessments; track risk findings, remediation actions, and compliance status across the supplier base.
  • Embed security into procurement processes, integrating cybersecurity requirements into Requests for Proposals (RFPs), contracts, and supplier qualification workflows; maintain a cybersecurity-focused Approved Supplier List.
  • Drive SBOM adoption and open-source risk management, using Software Composition Analysis (SCA) tools to identify and mitigate open-source software risk; coordinate vulnerability response for supplier-provided components in the field.
  • Deliver intelligence and influence, producing executive-level supplier risk reporting, monitoring supply chain threats and emerging regulations, and representing GE Vernova in industry forums and standards bodies.
  • Build team capability, mentoring colleagues on secure procurement practices and ISA/IEC 62443 standards while partnering with product engineering, sourcing, legal, and Vulnerability Operations teams.


Who You Are

You bring deep expertise in supply chain cybersecurity within Operational Technology (OT) or Industrial Control Systems (ICS) environments, and you know how to translate technical risk into contractual and organizational action.

Required

  • Bachelor's degree in Cybersecurity, Engineering, Information Technology, or a related field — or equivalent professional experience
  • Significant years of experience in cybersecurity, supply chain security, product security, or third-party risk management within OT/ICS environments
  • Strong working knowledge of ISA/IEC 62443, with particular depth in the 62443-2-4 and 62443-2-1 standards
  • Demonstrated experience running supplier security assessment programs and managing remediation pipelines
  • Familiarity with SBOMs, SCA tools, and open-source software (OSS) risk management
  • Experience integrating cybersecurity requirements into procurement, sourcing, and contract processes
  • Working knowledge of relevant supply chain regulations and frameworks, including NERC CIP-013 (North American Electric Reliability Corporation Critical Infrastructure Protection), CMMC (Cybersecurity Maturity Model Certification), NIS2 (Network and Information Security Directive 2), EU Cyber Resilience Act, and NDAA (National Defense Authorization Act) Section 889

Preferred

  • Direct experience applying IEC 62443-2-4 in OT/ICS manufacturing environments
  • Experience using AI/ML tools for supplier risk monitoring or SBOM analysis
  • Background in firmware security, counterfeit component detection, or hardware supply chain integrity
  • Global supplier management experience across multiple regions or regulatory jurisdictions
  • Relevant certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), GICSP (Global Industrial Cyber Security Professional), CSSLP (Certified Secure Software Lifecycle Professional), or an ISA/IEC 62443 certification


Education


A formal education and subsequent Bachelor's or Master's degree in Cybersecurity, Engineering, or Information Technology is nice to have, but we are most interested in your total experience and professional achievements.

Why GE Vernova


GE Vernova employees rise to the challenge of building a world that works. We provide varied, competitive benefits designed to reward high performance and su

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GE Vernova

View company profile →