
Principal – Secure Procurement Leader
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership and enhance the Secure Procurement Program from start to finish.
• Establish cybersecurity requirements for suppliers, along with policies and contractual commitments, in accordance with ISA/IEC 62443-2-4 and 62443-2-1.
• Conduct supplier evaluations and audits, which include questionnaire-based reviews, remote assessments, and on-site inspections.
• Monitor risk findings, remediation efforts, and compliance status across the supplier network.
• Incorporate cybersecurity criteria into RFPs, contracts, and supplier qualification processes.
• Maintain an Approved Supplier List with a focus on cybersecurity.
• Promote the adoption of SBOM and manage open-source risks utilizing SCA tools.
• Manage vulnerability responses for components supplied by vendors in the field.
• Generate executive-level reports on supplier risk.
• Keep abreast of supply chain threats and evolving regulations.
• Represent GE Vernova at industry forums and standards organizations.
• Provide mentorship to colleagues on secure procurement practices and ISA/IEC 62443 standards.
• Collaborate with product engineering, sourcing, legal, and Vulnerability Operations teams.
• A Bachelor's degree in Cybersecurity, Engineering, Information Technology, or a related discipline — or equivalent professional experience.
• Several years of substantial experience in cybersecurity, supply chain security, product security, or third-party risk management within OT/ICS environments.
• Profound knowledge of ISA/IEC 62443, especially 62443-2-4 and 62443-2-1.
• Proven experience in executing supplier security assessment programs and managing remediation workflows.
• Familiarity with SBOMs, SCA tools, and risk management of open-source software.
• Experience in integrating cybersecurity requirements into procurement, sourcing, and contractual processes.
• Working knowledge of NERC CIP-013, CMMC, NIS2, EU Cyber Resilience Act, and NDAA Section 889.
• Preferred direct experience with applying IEC 62443-2-4 in OT/ICS manufacturing settings.
• Experience using AI/ML tools for monitoring supplier risk or analyzing SBOMs is preferred.
• Background in firmware security, counterfeit component detection, or hardware supply chain integrity is preferred.
• Experience managing global suppliers across various regions or regulatory environments is preferred.
• Relevant certifications such as CISSP, CISM, GICSP, CSSLP, or an ISA/IEC 62443 certification are preferred.
• Must be legally authorized to work in the United States.
• Successful completion of a drug screening, if applicable.
• Comprehensive healthcare coverage, including medical, dental, vision, and prescription drug plans.
• Access to a Health Coach from GE Vernova, a 24/7 nurse-based resource.
• Employee Assistance Program offering 24/7 confidential assessment, counseling, and referral services.
• Participation in the GE Vernova Retirement Savings Plan.
• Tax-advantaged 401(k) savings plan with company matching contributions.
• Company contributions to retirement plans.
• Access to Fidelity resources and financial planning advisors.
• Tuition assistance available.
• Assistance with adoption expenses.
• Paid parental leave offered.
• Disability benefits provided.
• Life insurance coverage.
• 12 paid holidays each year.
• Flexible time off policy.
• Opportunities for professional development.
• Options for flexible work arrangements.
• Discretionary annual bonus potential.
• This position is remote.
Circular Action Alliance
Circular Action Alliance
Weekday (YC W21)
Westinghouse Electric Company
Get handpicked remote jobs straight to your inbox weekly.