
Principal Product Cyber Security Architect
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in United States.
• Evaluate secure architectures for industrial energy products, outlining security zones, conduits, trust boundaries, authentication and authorization models, data protection strategies, and remote access controls.
• Create reusable security patterns, reference architectures, and design standards.
• Spearhead threat modeling and risk assessments in accordance with IEC 62443-3-2.
• Generate outputs for threat models including data flow diagrams, threat analyses, risk ratings, and prioritized recommendations.
• Advocate for and implement AI-assisted tools and automation for threat modeling and risk assessments.
• Incorporate human-in-the-loop validation, IEC 62443 traceability, and SBOM/vulnerability data.
• Convert Secure Development Lifecycle requirements into product-specific installation, configuration, hardening, and operational guidance.
• Facilitate SDL execution by establishing security requirements, conducting design reviews, assessing security gates, and preparing security evidence, test documentation, and compliance artifacts.
• Provide reusable templates, artifact libraries, and lessons learned to the Secure Development & Supply Chain team.
• Design, maintain, and deliver role-specific training and learning paths for designated roles.
• Collaborate with product teams across Power, Wind, and Electrification sectors.
• Extensive experience in cybersecurity, with a focus on product, system, or architecture security.
• Proven experience in producing security architecture deliverables, threat models, and risk assessments.
• Proficient understanding of IEC 62443, especially 62443-3-2, 62443-3-3, and 62443-4-1.
• Background in developing security requirements, hardening guides, and assessment reports.
• Knowledge of OT/ICS product architectures and deployment environments in the energy sector.
• Excellent written communication skills.
• Experience with industrial energy technology products, particularly GE Vernova platforms, is preferred.
• Familiarity with AI-enabled tools for threat modeling or security analysis is a plus.
• Understanding of EU Cyber Resilience Act requirements is preferred.
• Experience in contributing to SDL artifact libraries or security pattern repositories is advantageous.
• Relevant certifications such as GICSP, CSSLP, or ISA/IEC 62443 certification are preferred.
• A Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Electrical Engineering, or a related field is desirable but not mandatory.
• Must have legal authorization to work in the United States.
• Successful completion of a drug screen, if applicable.
• Competitive benefits package based on employment status and national requirements.
• Opportunities for on-the-job learning and development.
• Support for professional development.
• Medical coverage.
• Dental coverage.
• Vision coverage.
• Prescription drug coverage.
• Access to Health Coach services.
• Employee Assistance Program offering 24/7 confidential assessment, counseling, and referral services.
• GE Vernova Retirement Savings Plan.
• Tax-advantaged 401(k) savings opportunity.
• Company matching contributions.
• Company retirement contributions.
• Fidelity resources and financial planning consultants.
• Tuition assistance.
• Adoption assistance.
• Paid parental leave.
• Disability benefits.
• Life insurance.
• 12 paid holidays.
• Permissive time off.
• Discretionary annual bonus.
• Relocation assistance is not provided.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.