
Principal Cyber Security Architect
Posted 18 hours ago

Posted 18 hours ago
This is a fully remote position, open to applicants in United States.
• Lead and execute thorough cybersecurity evaluations of wind turbine components, SCADA systems, Wind Farm software, and digital service platforms.
• Implement IEC 62443-4-1 and IEC 62443-3-3 security measures throughout the stages of requirements definition, design development, and product validation.
• Conduct threat modeling and risk assessments for both new and existing products and features.
• Identify, document, and address security vulnerabilities, risks, and non-conformities while recommending remediation strategies.
• Collaborate with product development, engineering, projects, services, and R&D teams to embed security-by-design concepts.
• Suggest and promote security enhancements at the wind farm level across various subsystems.
• Oversee the development and management of technologies that support cybersecurity evaluations.
• Review customer-facing documentation to ensure alignment with security best practices and the as-designed security standards.
• Contribute to internal processes, guidelines, and hardening guides related to product security.
• Offer technical assistance for customer inquiries and product incident/vulnerability response efforts.
• Report to the Wind Product Security Leader.
• Bachelor’s Degree from an accredited institution in Engineering, Computer Science, Cybersecurity, Information Technology, or a related field.
• A minimum of 12 years of pertinent experience in cybersecurity or operational technology (OT).
• At least 8+ years of experience specifically in operational technology (OT) cybersecurity or product cybersecurity.
• Must reside in the U.S.
• Willingness and ability to travel up to 10%; travel may increase to 20% for those not located in the Greenville, SC or Schenectady, NY regions.
• Minimum of 4 years of experience with product security requirements, regulations, and/or standards like IEC 62443 or equivalent.
• Familiarity with cybersecurity tools and solutions, such as firewalls, antivirus software, SIEM, and IDS/IPS.
• Experience in providing installation and configuration recommendations.
• Knowledge of wind turbine products and/or SCADA product/cybersecurity.
• Understanding of network cybersecurity practices.
• Familiarity with Docker, Kubernetes, and associated security best practices.
• Possession of a cybersecurity certification such as GICSP, CEH, CCNA, or CISSP.
• Experience with cloud security principles and practices.
• Proficiency in secure coding practices across various programming languages.
• Experience with penetration testing and vulnerability assessment tools tailored for OT environments.
• Understanding of operational technology, including PLCs and protocols like Modbus, Profinet, DNP3, OPC, and IEC 61850.
• Capability to work independently as well as collaboratively with cross-functional teams.
• Strong oral and written communication skills.
• Ability to analyze and resolve issues effectively.
• Experience in addressing product cybersecurity vulnerabilities and inquiries.
• Legally authorized to work in the United States.
• Successful completion of a drug screening, if applicable.
• Discretionary annual bonus.
• Coverage for medical, dental, vision, and prescription drugs.
• Access to a Health Coach.
• Employee Assistance Program offering 24/7 confidential assessment, counseling, and referral services.
• GE Vernova Retirement Savings Plan.
• Tax-advantaged 401(k) savings plan with company matching contributions.
• Company contributions to retirement plans.
• Fidelity resources and financial planning consultants available.
• Tuition assistance provided.
• Adoption assistance available.
• Paid parental leave.
• Disability benefits offered.
• Life insurance coverage.
• 12 paid holidays each year.
• Flexible time off policy.
• Assistance with relocation provided.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.