Jobs and Careers
GE

Principal Product Cyber Security Architect

GE Vernova
Remote, United States, United StatesRemotefull_timeVerifiedPosted 13 Aug 2026
💰 $245,000/yr($147,000/yr$245,000/yr)

About the role

Job Description Summary

The energy systems that power homes, businesses, and critical infrastructure depend on software and hardware that must be secure by design — not secured as an afterthought. As a Product Cybersecurity Architect at GE Vernova, you will be at the center of that work.

You will partner directly with product teams across our Power, Wind, and Electrification businesses to design secure architectures, lead threat modeling, and translate security policy into practical engineering guidance. This is a hands-on individual contributor role where your technical depth will shape how security is built into GE Vernova's industrial energy products from the ground up.

If you find genuine satisfaction in solving hard technical problems that matter at scale, this role was designed for you.

Job Description

What You'll Do

  • Review secure architectures for industrial energy products — defining security zones, conduits, trust boundaries, authentication and authorization models, data protection strategies, and remote access controls. Develop reusable security patterns, reference architectures, and design standards that product teams can act on.
  • Lead threat modeling and risk assessments aligned to IEC (International Electrotechnical Commission) 62443-3-2. Produce complete threat model outputs, including data flow diagrams, threat analysis, risk ratings, and prioritized recommendations. 
  • Leverage AI to scale and accelerate threat modeling and risk assessments — Champion and operationalize AI assisted tooling and automation to generate DFDs, threat catalogs, risk ratings, and prioritized mitigation backlogs; integrate human in the loop validation, IEC 62443 traceability, and SBOM/vulnerability data to ensure accuracy and auditability while reducing time to assessment and improving consistency.
  • Translate SDL (Secure Development Lifecycle) requirements into product-specific guidance — including secure installation, configuration, hardening, and operational documentation that engineering teams can use directly in the field.
  • Support SDL execution end to end by defining security requirements, conducting design reviews, evaluating security gates, and helping prepare security evidence, test documentation, and compliance artifacts.
  • Build team capability by contributing reusable templates, artifact libraries, and lessons learned that raise the quality and efficiency of the broader Secure Development & Supply Chain team.
  • Develop, maintain and deliver role-based training and enablement through the creation and update of learning paths for identified roles to support organizational awareness of product security program, technical, regulatory and other requirements.


Who We're Looking For

You are a cybersecurity practitioner with strong technical foundations and a track record of delivering security architecture work in complex product or system environments — someone who brings both engineering depth and the communication skills to make security requirements clear and actionable for the teams you support.

Required

  • Significant experience in cybersecurity, with a focus on product, system, or architecture security
  • Demonstrated experience producing security architecture deliverables, threat models, and risk assessments
  • Working knowledge of IEC 62443, particularly 62443-3-2, 62443-3-3, and 62443-4-1
  • Experience creating secure development artifacts such as security requirements, hardening guides, and assessment reports
  • Familiarity with OT (Operational Technology) / ICS (Industrial Control Systems) product architectures and energy sector deployment environments
  • Strong written communication skills, with the ability to translate technical security findings into clear, actionable guidance

Preferred

  • Experience working with industrial energy technology products, including GE Vernova platforms
  • Experience using AI-enabled tools for threat modeling or security analysis
  • Familiarity with EU Cyber Resilience Act requirements
  • Experience contributing to SDL artifact libraries or security pattern catalogs
  • Relevant certifications such as GICSP (Global Industrial Cyber Security Professional), CSSLP (Certified Secure Software Lifecycle Professional), or ISA/IEC 62443 certification


Education
A formal education and subsequent Bachelor's or Master's degree in Cybersecurity, Computer Science, Electrical Engineering, or a related field is nice to have, but we are most interested in your total experience and professional achievements.

Why GE Vernova

GE Vernova employees rise to the challenge of building a world that works. We provide varied, competit

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GE Vernova

View company profile →