
Principal ā Secure Procurement Leader
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
⢠Take ownership of and enhance the Secure Procurement Program from start to finish.
⢠Establish supplier cybersecurity requirements, policies, and contractual obligations in accordance with ISA/IEC 62443-2-4 and 62443-2-1.
⢠Conduct supplier assessments and audits, including reviews based on questionnaires, remote evaluations, and on-site assessments.
⢠Monitor risk findings, remediation efforts, and compliance status throughout the supplier network.
⢠Incorporate cybersecurity requirements into RFPs, contracts, and supplier qualification processes.
⢠Maintain a list of approved suppliers with a focus on cybersecurity.
⢠Promote the adoption of SBOM and manage risks associated with open-source software.
⢠Utilize SCA tools to detect and mitigate risks related to open-source software.
⢠Coordinate responses to vulnerabilities for components supplied by vendors in the field.
⢠Generate executive-level reports on supplier risk.
⢠Keep track of supply chain threats and new regulatory developments.
⢠Represent GE Vernova in industry forums and standards-setting organizations.
⢠Provide mentorship to colleagues on secure procurement practices and ISA/IEC 62443 standards.
⢠Collaborate with product engineering, sourcing, legal, and Vulnerability Operations teams.
⢠Bachelor's degree in Cybersecurity, Engineering, Information Technology, or a related field ā or equivalent professional experience.
⢠Several years of experience in cybersecurity, supply chain security, product security, or third-party risk management within OT/ICS environments.
⢠Strong knowledge of ISA/IEC 62443, specifically the 62443-2-4 and 62443-2-1 standards.
⢠Proven experience in managing supplier security assessment programs and remediation processes.
⢠Familiarity with SBOMs, SCA tools, and the management of open-source software risks.
⢠Experience in integrating cybersecurity requirements into procurement, sourcing, and contracting processes.
⢠Working knowledge of NERC CIP-013, CMMC, NIS2, the EU Cyber Resilience Act, and NDAA Section 889.
⢠Legally authorized to work in the United States.
⢠Preferred: direct experience applying IEC 62443-2-4 in OT/ICS manufacturing settings.
⢠Preferred: experience with AI/ML tools for monitoring supplier risk or analyzing SBOMs.
⢠Preferred: background in firmware security, detection of counterfeit components, or hardware supply chain integrity.
⢠Preferred: experience in global supplier management across various regions or regulatory environments.
⢠Preferred: relevant certifications such as CISSP, CISM, GICSP, CSSLP, or an ISA/IEC 62443 certification.
⢠Any employment offer is contingent upon successful completion of a drug screening, if applicable.
⢠Healthcare coverage: medical, dental, vision, and prescription drug coverage.
⢠Access to a Health Coach from GE Vernova, available as a 24/7 nurse-based resource.
⢠Employee Assistance Program offering 24/7 confidential assessment, counseling, and referral services.
⢠GE Vernova Retirement Savings Plan.
⢠Tax-advantaged 401(k) savings option with company matching contributions.
⢠Company contributions to retirement plans.
⢠Fidelity resources and financial planning consultants available.
⢠Tuition assistance for continuing education.
⢠Adoption assistance support.
⢠Paid parental leave for new parents.
⢠Disability benefits for eligible employees.
⢠Life insurance coverage provided.
⢠12 paid holidays each year.
⢠Permissive time off policy.
⢠Opportunities for professional development.
⢠Flexible working options to suit employee needs.
⢠Discretionary annual bonus potential.
⢠Competitive compensation package offered.
Westinghouse Electric Company
Circular Action Alliance
Circular Action Alliance
Weekday (YC W21)
Get handpicked remote jobs straight to your inbox weekly.