Product Security Analyst
GE Vernova
Date: 2 weeks ago
City: Chennai, Tamil Nadu
Contract type: Full time
Job Description Summary
As a Product Security Analyst, you will be responsible for the day-to-day execution of product cybersecurity compliance and vulnerability management for GE Vernova’s Power Conversion and Storage (PCS) business lines Operational Technology (OT) portfolio. You will apply your technical domain expertise to ensure products align with industry standards and regulations. This role requires independent initiative to manage project tasks, conduct vulnerability assessments, and partner with cross-functional teams to maintain a robust security posture across our product lifecycle.
Job Description
Roles and Responsibilities:
Compliance & Regulatory Execution
Experience with Industrial Control Systems (ICS) or OT security in an energy or manufacturing environment.
Proficiency in scripting (e.g., Python, PowerShell) for automating security tasks or report generation.
Ability to work independently with minimal supervision on technical project tasks.
Certifications: CEH, Security+ will be an added advantage.
Additional Information
Relocation Assistance Provided: Yes
As a Product Security Analyst, you will be responsible for the day-to-day execution of product cybersecurity compliance and vulnerability management for GE Vernova’s Power Conversion and Storage (PCS) business lines Operational Technology (OT) portfolio. You will apply your technical domain expertise to ensure products align with industry standards and regulations. This role requires independent initiative to manage project tasks, conduct vulnerability assessments, and partner with cross-functional teams to maintain a robust security posture across our product lifecycle.
Job Description
Roles and Responsibilities:
Compliance & Regulatory Execution
- Program Implementation: Execute cybersecurity policies and procedures aligned with industry standards (IEC 62443, NERC CIP, ISO 27001, NIST).
- Certification Support: Serve as a key contributor to product certification cycles, ensuring technical documentation meets the requirements of IEC 62443 or similar standards.
- Gap Assessment: Conduct regular product gap assessments, identifying and documenting misalignments between current technical implementations and regulatory requirements.
- Audit Liaison: Manage evidence collection and documentation for external audits, ensuring timely responses to auditor inquiries.
- Operational Ownership: Manage the end-to-end vulnerability lifecycle—scanning, prioritizing, tracking, and coordinating remediation efforts for identified security weaknesses.
- SDLC Integration: Collaborate directly with development teams to improve the Secure Development Lifecycle (SDLC) process.
- Tooling Execution: Manage and optimize Open Source Software (OSS), Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST) scans to proactively identify vulnerabilities.
- SBOM Management: Streamline the generation, maintenance, and transparency of Software Bill of Materials (SBOM) to ensure supply chain security.
- Technical Analysis: Perform root-cause analysis on security findings; develop and test remediation plans for moderate-complexity issues.
- Risk Management: Perform risk assessments on product components, translating technical findings into actionable risk-reduction strategies for engineering stakeholders.
- Project Delivery: Manage assigned workstreams within larger program plans, ensuring tasks are completed on schedule and meet quality standards.
- Design Integration: Participate in technical design reviews, actively championing "secure by design" principles and providing security guidance to software/systems engineers.
- Process Efficiency: Proactively identify bottlenecks in current security processes and suggest improvements to increase the effectiveness of vulnerability management and compliance workflows.
- Technical Guidance: Act as a technical resource for junior staff or interns; document findings to share knowledge across the broader security team.
- Stakeholder Engagement: Communicate security requirements and remediation priorities clearly to cross-functional teams, including product management and engineering.
- Professional Development: Stay current on evolving OT threats and regulatory updates, applying new knowledge to refine product security practices.
- Bachelor’s/Master’s in Electronics, Electrical, Cybersecurity, Information Technology, Computer Science, or a related technical field.
- 3–5 years of professional experience in cybersecurity compliance, vulnerability management, or a related technical engineering role.
- Demonstrated experience working with cybersecurity frameworks (e.g., NIST, ISO 27001) and familiarity with OT-specific standards (e.g., IEC 62443, NERC CIP).
- Experience with vulnerability scanning and management tools (e.g., Nessus, Qualys, Tenable).
Experience with Industrial Control Systems (ICS) or OT security in an energy or manufacturing environment.
Proficiency in scripting (e.g., Python, PowerShell) for automating security tasks or report generation.
Ability to work independently with minimal supervision on technical project tasks.
Certifications: CEH, Security+ will be an added advantage.
Additional Information
Relocation Assistance Provided: Yes
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Workday Finance Consultant
Cognizant,
Chennai, Tamil Nadu
5 days ago
Job SummaryWe are seeking an experienced Architect with 6 to 8 years of experience in Workday and Workday Financial Management. The role involves designing and implementing solutions that align with business objectives. The position is hybrid allowing flexibility in work location and operates during the day shift. No travel is required.ResponsibilitiesDesign and implement Workday solutions that meet business requirements and...
Guidewire Architect
CGI,
Chennai, Tamil Nadu
1 week ago
Position DescriptionCompany Profile:Founded in 1976, CGI is among the largest independent IT and business consulting services firms in the world. With 94,000 consultants and professionals across the globe, CGI delivers an end-to-end portfolio of capabilities, from strategic IT and business consulting to systems integration, managed IT and business process services and intellectual property solutions. CGI works with clients through a...
Senior Manager Project Pursuits
Emerson,
Chennai, Tamil Nadu
2 weeks ago
Job DescriptionPosition Summary:If you are a Project Pursuit professional Iooking for an opportunity to grow your career, Emerson has an exciting opportunity for you! Based in Delhi, Bengaluru, Mumbai, or Chennai, India, you will play a pivotal role in shaping early-stage project success by engaging with Global Engineering Centers (GECs) and Engineering, Procurement, and Construction (EPC) organizations. This role focuses...