Jobs and Careers
GE

Senior Product Security Architect

GE Vernova
Greenville, United Statesfull_timeVerifiedPosted 2 Sept 2025
💰 $185,400/yr($111,200/yr$185,400/yr)

About the role

Job Description Summary

GE Vernova is seeking a highly skilled and experienced Senior Cyber Security Architect to join the Product Security team, focusing on the Wind portfolio of products. This role is responsible for conducting in-depth cyber security assessments of wind farm design and architecture at both the product and component levels. This include leading these assessments in accordance with GE Vernova’s Secure Development Lifecycle (SDL) process, aligned with IEC 62443-4-1, and reviewing applicable requirements outlined in IEC 62443-4-2 and IEC 62443-3-2 standards. The role involves collaboration with various subsystem teams to identify relevant products and execute these assessments.

This position reports to Wind's Product Security Leader, who oversees Wind's Product Security Team. The Product Security Team drives a product cyber security strategy aimed at meeting applicable standards and regulations while leading the industry towards more fundamentally secure wind farms.

Job Description

Essential Responsibilities

  • Perform security assessments, following the defined engineering processes, to discovery design flaws, vulnerabilities, weaknesses, and missing security controls and support the secure implementation of security features.
  • Lead and conduct comprehensive cybersecurity assessments of wind turbine components, SCADA systems, Wind Farm software, and digital service platforms in accordance with IEC 62443-4-2 and IEC 62443-3-2 standards.
  • Document security assessments with sufficient detail to underwrite the cyber security reviews.
  • Represent the cyber security team in applicable design reviews and contribute for cyber security related milestones, deliverables, and/or tasks.
  • Identify and document security vulnerabilities, risks, and non-conformities within products and systems.
  • Develop recommendations for effective security controls and mitigation strategies to address identified risks.
  • Collaborate closely with product development, engineering, and R&D teams to integrate security by design principles throughout the product lifecycle.
  • Provide expert guidance on the interpretation and application of IEC 62443 series of standards (specifically IEC 62443-4-1 and IEC 62443-3-3) during the requirements definition and design phases.
  • Perform threat modeling and risk assessments for new and existing products and features.
  • Evaluate the security posture of industrial protocols commonly used in wind farms and other industrial control environments (e.g., Modbus TCP, DNP3, OPC UA, IEC 61850).
  • Stay current with emerging product cyber security regulations, standards, threats, vulnerabilities, and technologies relevant to Wind and industrial control systems in general.
  • Contribute to the development and improvement of internal product security processes and guidelines.
  • Propose recommendation and facilitate discussion on high level wind-farm level security improvements that can be driven across subsystems.
  • Work with product management and development teams to set the technical cyber security roadmap.
  • Work with development teams to guide and ensure consistent adoption of the technologies, including security solutions (e.g., Antivirus).
  • Together with the product teams, ensure the security features and architecture is aligned with the evolving cyber security regulations within the industry.
  • Review customer facing documentation to align it with security best practices and the as-designed security requirements.
  • Contribute to the development and improvement of internal product security processes and guidelines, including hardening guides.
  • Support incident response activities related to product security vulnerabilities.

Required Qualifications

  • Bachelor’s Degree from an accredited university in Engineering, Computer Science, Cybersecurity, Information Technology, or related field. Alternative acceptable experience will be considered on a case-by-case basis.
  • Minimum 8 years of experience in cybersecurity with at least 3 years focused on industrial control systems (ICS), operational technology (OT), or product security.

Desired Characteristics

  • Demonstrable in-depth knowledge and practical experience with the IEC 62443 series of standards, specifically:
  • IEC 62443-4-2 (Technical security requirements for IACS components)
  • IEC 62443-3-2 (Security risk assessment and system design)
  • 62443-4-1 (Secure product development lifecycle requirements)
  • Strong knowledge of cyber security best practices and frameworks (e.g., NIST CSF, OWASP top 10).
  • Strong understanding of industrial communication protocols used in powe

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GE Vernova

View company profile →