招聘
Job Description Summary
- As a key member of a global and matrixed design team, Sr Product Security Analyst is responsible for
- Cyber security analysis of controllers, systems architectures for cyber security requirements.
- Lead the software and hardware penetration testing activates
- Work in Collaboration with development teams to improve SDLC process, OSS/SAST/DAST scans.
- Streamline SBOM generation.
- Lead the cyber security testing for GE Vernova Power Conversion products and analyze the reports and suggest remediation strategy.
- Identify Product vulnerabilities; rate and report to development team.
Job Description Essential Responsibilities:
Lead reviews, suggest architectural changes, conduct tests to ensure systems, controllers, meet Cyber security requirements. Collaborates with a team of controls and system engineers developing operational software for various subsystems. The position requires a clear understanding of OT System, and conversant with all Cyber security requirements.
This role requires strong cooperation with system and subsystem teams necessary for command and control of the systems involved. The Security Analyst should be comfortable making design decisions in a sometimes-uncertain context, crafting innovative solutions, and demonstrating rigorous and decisive leadership. Work with multiple teams in different location to deliver Cyber secure software to meet customer requirements.
Roles and Responsibilities
You are a skilled Security Analyst who enjoys security work and is an expert in systems security, product / OT security and application security. In this role, you will be working with product managers, independent researchers, and in-house researchers to identify, rate, report and manage product vulnerabilities and incidents.
In this role, you will:
- Be responsible for providing technical leadership and defining, developing security within software in a fast-paced and agile development environment using the latest secure software development technologies and infrastructure.
- Work with Cyber Security Leaders and SMEs to understand product requirements.
- Hands on experience with penetration testing for software applications, Systems, Web Application, mobile application, controllers.
- Work on Cybersecurity tools like Wireshark, NESSUS and Burp Suite
- Experienced in different phases of Software Development Life cycle (SDLC) including Design, Implementation and Testing during the development of software applications.
- Assist security champions in completing Threat Modelling and Architecture Risk Analysis on product features.
- Perform Security Code Reviews, Vulnerability Analysis and research on application code.
- Coach and mentor developers to implement cryptography solutions securely (PKI, Code Signing, Stored Secrets, et cetera)
- Provide guidance and advice on writing secure code that meets standards and delivers desired functionality, using the technology selected for the project.
- Research new application security technologies and implement them to improve application security.
- Maintaining a backlog of security-related tools that will improve the maintainability and security of our code and the pace of development.
- Promote best practices based on OWASP Top 10, SANS Top 25, and the GE Vernova SDLC.
Education/Qualification
- Bachelor /master's degree in IT/computer science or relevant engineering or equivalent knowledge / experience with 6+ Years of Experience
- Strong understanding of fundamentals in networking, ethical hacking, cryptography, penetration testing, vulnerability analysis, risk assessment, threat modelling, cybersecurity standards like ISO 27000 and ISA/IEC 62443.
- Database RDBMS, My
SQL NoSQL databases:
- Software component: MS Visual Studio, MS Office, MS Visio, GitHub
- Linux and Windows OS
- Hands on experience with Enterprise Application and Web Application servers like Tomcat, and WLP.
Certifications like CEH, Offensive Security, PNPT will be an added advantage.
Additional Information Relocation Assistance Provided:
Yes
总浏览量
0
申请点击数
0
模拟申请者数
0
收藏
0
相似职位
关于GE Vernova

GE Vernova
PublicGE Vernova, Inc. is an energy equipment manufacturing and services company headquartered in Cambridge, Massachusetts.
10,001+
员工数
Boston
总部位置
$16B
企业估值
评价
3.6
10条评价
工作生活平衡
2.8
薪酬
4.2
企业文化
3.9
职业发展
2.9
管理层
2.7
65%
推荐给朋友
优点
Good benefits and compensation
Supportive team culture and diversity
Professional development opportunities
缺点
Heavy workload and frequent overtime
Limited growth and advancement opportunities
Poor management and lack of support
薪资范围
143个数据点
Junior/L3
Junior/L3 · Business Analyst
0份报告
$92,460
年薪总额
基本工资
-
股票
-
奖金
-
$78,591
$106,329
面试经验
4次面试
难度
3.3
/ 5
时长
14-28周
体验
正面 0%
中性 75%
负面 25%
面试流程
1
Application Review
2
HR Screen
3
Technical Phone Screen
4
Hiring Manager Interview
5
Final Technical Round
6
Offer
常见问题
Technical Knowledge
Behavioral/STAR
Past Experience
Coding/Algorithm
新闻动态
Ge Vernova New Issue Day (mAOlknKMrQ) - fathomjournal.org
fathomjournal.org
News
·
2d ago
GE Vernova Gets Another Price Target Hike. Wall Street Is Chasing the Stock. - Barron's
Barron's
News
·
2d ago
GE Vernova Stock Is Up 243% in 1 Year: Here’s What Could Drive the Next Move - TIKR.com
TIKR.com
News
·
2d ago
What Drove GE Vernova’s 2x Surge? - Forbes
Forbes
News
·
2d ago


