About this role
# Job Description Summary
The Product Security Lead has the mission to apply the Secure Development Lifecycle (SDL) process and the incident and vulnerability management process to Grid Automation products.#LI-ML2
Job Description
Essential Responsibilities
- Implement the secure development life cycle (SDL), including security assessment, threat modelling, requirements definition, security architecture and design, penetration testing and secure deployment guide.
- Participate in the development and delivery of competitive product cyber security solutions, to support targeted growth.
- Contribute in decisions related to technology choices and design, for alignment with the overall Grid Automation cyber security strategy and roadmap.
- Share best practices and lessons learned and continuously update the technical cyber security architecture, based on changing technologies, in collaboration with other product security leads, domain architects and experts.
- Recommend and participate in the design and implementation of standards, tools, and methodologies in the research and development community of GEV Grid Automation.
- Develop and conduct relevant security training for various internal audience, such as product managers, software engineers and technical support.
- Implement the cyber security vulnerability and incident process, including vulnerability assessment, solution definition (in collaboration with the development team), communication with external parties where applicable and drafting the security advisories.
- Knowledge of cyber asset protection regulations and standards affecting the utilities industry including NERC-CIP, NIST, IEC62443, IEC62351
Required Qualifications
- Bachelor’s Degree from an accredited university in Engineering, Computer Science or Information Technology
- Extensive experience with cyber security, preferably in an Operational Technology (OT) environment.
- Experience with Telecom and Network Equipment (Routers, Switches, Firewalls)
- Experience with security technologies, such as
- LDAP, RADIUS, SSH, SFTP, HTTPS, SYSLOG
- Encryption, TLS, RSA and code signing
- Experience with vulnerability assessment tools and penetration testing methodologies.
Desired Characteristics
- Symmetric and asymmetric cryptography and PKI infrastructure
- Cyber security certification (ex. ISC2, SANS, ISACA, CISSP)
- Experience with programing and scripting languages.
- Demonstrated knowledge and understanding of the TCP/IP network stack, communication protocols and applications, including Modbus, DNP3, IEC61850.
- Demonstrated experience with Linux, VxWorks and Windows operating systems including user account management, security / system hardening, device control, and patch management.
- Excellent customer service mind-set
- D emonstrated ability to lead programs / projects. Ability to document, plan, market, and execute programs. Established project management skills.
- Excellent oral and written communications skills in English
- Ability to work effectively in a team and across functions, partnering with other teams in a worldwide environment
For candidates applying to a Canadian-based position, the pay range for this position is between $126,000 - $176,000 CAD. The specific pay offered may be influenced by a variety of factors, including the candidate’s experience, education, and skill set.
Bonus eligibility: discretionary annual bonus.
This posting is for an existing vacancy.
Additional Information
Relocation Assistance Provided: Yes