Description
Job Description Summary
The Product Security Lead has the mission to apply the Secure Development Lifecycle (SDL) process and the incident and vulnerability management process to Grid Automation products.
Job Description
Essential Responsibilities
Implement the secure development life cycle (SDL), including security assessment, threat modelling, requirements definition, security architecture and design, penetration testing and secure deployment guide.Participate in the development and delivery of competitive product cyber security solutions, to support targeted growth.Contribute in decisions related to technology choices and design, for alignment with the overall Grid Automation cyber security strategy and roadmap.Share best practices and lessons learned and continuously update the technical cyber security architecture, based on changing technologies, in collaboration with other product security leads, domain architects and experts.Recommend and participate in the design and implementation of standards, tools, and methodologies in the research and development community of GEV Grid Automation.Develop and conduct relevant security training for various internal audience, such as product managers, software engineers and technical support.Implement the cyber security vulnerability and incident process, including vulnerability assessment, solution definition (in collaboration with the development team), communication with external parties where applicable and drafting the security advisories.Knowledge of cyber asset protection regulations and standards affecting the utilities industry including NERC-CIP, NIST, IEC62443, IEC62351
Required Qualifications
Bachelor’s Degree from an accredited university in Engineering, Computer Science or Information TechnologyExtensive experience with cyber security, preferably in an Operational Technology (OT) environment.Experience with Telecom and Network Equipment (Routers, Switches, Firewalls)Experience with security technologies, such as LDAP, RADIUS, SSH, SFTP, HTTPS, SYSLOGEncryption, TLS, RSA and code signingExperience with vulnerability assessment tools and penetration testing methodologies.
Desired Characteristics
Symmetric and asymmetric cryptography and PKI infrastructureCyber security certification (ex.
ISC2, SANS, ISACA, CISSP)Experience with programing and scripting languages.Demonstrated knowledge and understanding of the TCP/IP network stack, communication protocols and applications, including Modbus, DNP3, IEC61850.Demonstrated experience with Linux, VxWorks and Windows operating systems including user account management, security / system hardening, device control, and patch management.Excellent customer service mind-setDemonstrated ability to lead programs / projects.
Ability to document, plan, market, and execute programs.
Established project management skills.Excellent oral and written communications skills in EnglishAbility to work effectively in a team and across functions, partnering with other teams in a worldwide environment
For candidates applying to a Canadian-based position, the pay range for this position is between $126,000 - $176,000 CAD.
The specific pay offered may be influenced by a variety of factors, including the candidate’s experience, education, and skill set.
Bonus eligibility: discretionary annual bonus.
This posting is for an existing vacancy.
Additional Information
Relocation Assistance Provided: Yes