Product Security Engineer

Il y a 4 jours

Montpellier, Occitania, France GE Vernova Temps plein 126 000 $CA - 176 000 $CA Contrat


Job Description
Summary The Product Security Lead has the mission to apply the Secure Development Lifecycle (SDL) process and the incident and vulnerability management process to Grid Automation products.#LI-ML2

Job Description
Essential Responsibilities
• Implement the secure development life cycle (SDL), including security assessment, threat modelling, requirements definition, security architecture and design, penetration testing and secure deployment guide.
• Participate in the development and delivery of competitive product cyber security solutions, to support targeted growth.
• Contribute in decisions related to technology choices and design, for alignment with the overall Grid Automation cyber security strategy and roadmap.
• Share best practices and lessons learned and continuously update the technical cyber security architecture, based on changing technologies, in collaboration with other product security leads, domain architects and experts.
• Recommend and participate in the design and implementation of standards, tools, and methodologies in the research and development community of GEV Grid Automation.
• Develop and conduct relevant security training for various internal audience, such as product managers, software engineers and technical support.
• Implement the cyber security vulnerability and incident process, including vulnerability assessment, solution definition (in collaboration with the development team), communication with external parties where applicable and drafting the security advisories.
• Knowledge of cyber asset protection regulations and standards affecting the utilities industry including NERC-CIP, NIST, IEC62443, IEC62351 Required Qualifications
• Bachelor’s Degree from an accredited university in Engineering, Computer Science or Information Technology
• Extensive experience with cyber security, preferably in an Operational Technology (OT) environment.
• Experience with Telecom and Network Equipment (Routers, Switches, Firewalls)
• Experience with security technologies, such as
•
• LDAP, RADIUS, SSH, SFTP, HTTPS, SYSLOG
• Encryption, TLS, RSA and code signing
• Experience with vulnerability assessment tools and penetration testing methodologies. Desired Characteristics
• Symmetric and asymmetric cryptography and PKI infrastructure
• Cyber security certification (ex. ISC2, SANS, ISACA, CISSP)
• Experience with programing and scripting languages.
• Demonstrated knowledge and understanding of the TCP/IP network stack, communication protocols and applications, including Modbus, DNP3, IEC61850.
• Demonstrated experience with Linux, VxWorks and Windows operating systems including user account management, security / system hardening, device control, and patch management.
• Excellent customer service mind-set
• Demonstrated ability to lead programs / projects. Ability to document, plan, market, and execute programs. Established project management skills.
• Excellent oral and written communications skills in English
• Ability to work effectively in a team and across functions, partnering with other teams in a worldwide environment For candidates applying to a Canadian-based position, the pay range for this position is between $126,000
- $176,000 CAD. The specific pay offered may be influenced by a variety of factors, including the candidate’s experience, education, and skill set. Bonus eligibility: discretionary annual bonus. This posting is for an existing vacancy. Additional Information Relocation Assistance Provided: Yes