Hiring.Camp

Principal - Secure Procurement Leader

gevernova

·

Yesterday

Location
Remote, United States of America · Remote
Workplace
Remote
Type
Full-time
Department
Operations
Seniority
Lead
Education
Master
Visa
Not sponsored
Closing date
Today
Source
Workday

Description

Job Description Summary

The Opportunity

Critical energy infrastructure depends on the security of every component inside it. As GE Vernova's Secure Procurement Leader, you will own the program that ensures every third-party hardware, software, firmware, and service integrated into GE Vernova commercial products meets rigorous cybersecurity standards — before it ever reaches a customer.

This is a high-visibility, cross-functional role at the intersection of supply chain, product security, and regulatory compliance. You will set supplier security requirements, lead assessments and audits, embed cybersecurity obligations into procurement contracts, and advance Software Bill of Materials (SBOM) adoption across GE Vernova's global supplier base. Your work directly protects the reliability and security of the energy systems that power modern life.

Job Description

What You'll Do

  • Own and evolve the Secure Procurement Program end-to-end, defining supplier cybersecurity requirements, policies, and contractual obligations aligned with ISA/IEC (International Society of Automation / International Electrotechnical Commission) 62443-2-4 and 62443-2-1 standards.
  • Lead supplier assessments and audits, including questionnaire-based reviews, remote evaluations, and on-site assessments; track risk findings, remediation actions, and compliance status across the supplier base.
  • Embed security into procurement processes, integrating cybersecurity requirements into Requests for Proposals (RFPs), contracts, and supplier qualification workflows; maintain a cybersecurity-focused Approved Supplier List.
  • Drive SBOM adoption and open-source risk management, using Software Composition Analysis (SCA) tools to identify and mitigate open-source software risk; coordinate vulnerability response for supplier-provided components in the field.
  • Deliver intelligence and influence, producing executive-level supplier risk reporting, monitoring supply chain threats and emerging regulations, and representing GE Vernova in industry forums and standards bodies.
  • Build team capability, mentoring colleagues on secure procurement practices and ISA/IEC 62443 standards while partnering with product engineering, sourcing, legal, and Vulnerability Operations teams.


Who You Are

You bring deep expertise in supply chain cybersecurity within Operational Technology (OT) or Industrial Control Systems (ICS) environments, and you know how to translate technical risk into contractual and organizational action.

Required

  • Bachelor's degree in Cybersecurity, Engineering, Information Technology, or a related field — or equivalent professional experience
  • Significant years of experience in cybersecurity, supply chain security, product security, or third-party risk management within OT/ICS environments
  • Strong working knowledge of ISA/IEC 62443, with particular depth in the 62443-2-4 and 62443-2-1 standards
  • Demonstrated experience running supplier security assessment programs and managing remediation pipelines
  • Familiarity with SBOMs, SCA tools, and open-source software (OSS) risk management
  • Experience integrating cybersecurity requirements into procurement, sourcing, and contract processes
  • Working knowledge of relevant supply chain regulations and frameworks, including NERC CIP-013 (North American Electric Reliability Corporation Critical Infrastructure Protection), CMMC (Cybersecurity Maturity Model Certification), NIS2 (Network and Information Security Directive 2), EU Cyber Resilience Act, and NDAA (National Defense Authorization Act) Section 889

Preferred

  • Direct experience applying IEC 62443-2-4 in OT/ICS manufacturing environments
  • Experience using AI/ML tools for supplier risk monitoring or SBOM analysis
  • Background in firmware security, counterfeit component detection, or hardware supply chain integrity
  • Global supplier management experience across multiple regions or regulatory jurisdictions
  • Relevant certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), GICSP (Global Industrial Cyber Security Professional), CSSLP (Certified Secure Software Lifecycle Professional), or an ISA/IEC 62443 certification


Education


A formal education and subsequent Bachelor's or Master's degree in Cybersecurity, Engineering, or Information Technology is nice to have, but we are most interested in your total experience and professional achievements.

Why GE Vernova


GE Vernova employees rise to the challenge of building a world that works. We provide varied, competitive benefits designed to reward high performance and support your personal and family needs — including healthcare, financial programs, and flexibility options that adapt to how you live and work.


We invest in your growth. Whether through on-the-job learning, formal development programs, or exposure to some of the most complex supply chain security challenges in the energy sector, your career at GE Vernova will move forward

Additional Information

GE Vernova offers a great work environment, professional development, challenging careers, and competitive compensation. GE Vernova is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

GE Vernova will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable).

Relocation Assistance Provided: No

#LI-Remote - This is a remote position

Application Deadline: August 28, 2026

 

 

For candidates applying to a U.S. based position, the pay range for this position is between $147,000.00 and $245,000.00. The Company pays a geographic differential of 110%, 120% or 130% of salary in certain areas. The specific pay offered may be influenced by a variety of factors, including the candidate’s experience, education, and skill set.

 

 

Bonus eligibility: discretionary annual bonus.

 

 

This posting is expected to remain open for at least seven days after it was posted on August 14, 2026.

 

 

Available benefits include medical, dental, vision, and prescription drug coverage; access to Health Coach from GE Vernova, a 24/7 nurse-based resource; and access to the Employee Assistance Program, providing 24/7 confidential assessment, counseling and referral services. Retirement benefits include the GE Vernova Retirement Savings Plan, a tax-advantaged 401(k) savings opportunity with company matching contributions and company retirement contributions, as well as access to Fidelity resources and financial planning consultants. Other benefits include tuition assistance, adoption assistance, paid parental leave, disability benefits, life insurance, 12 paid holidays, and permissive time off.

 

 

GE Vernova Inc. or its affiliates (collectively or individually, “GE Vernova”) sponsor certain employee benefit plans or programs GE Vernova reserves the right to terminate, amend, suspend, replace, or modify its benefit plans and programs at any time and for any reason, in its sole discretion. No individual has a vested right to any benefit under a GE Vernova welfare benefit plan or program. This document does not create a contract of employment with any individual.

Skills

CybersecurityRisk ManagementComplianceProcurementCISSP

Similar Jobs

10

Principal Secure SDLC engineer

Hewlett Packard Enterprise (HP) · Bengaluru, Karnātaka, India · Onsite

5 months ago

Principal Secure SDLC engineer

Hewlett Packard Enterprise (HP) · Bengaluru, Karnātaka, India · Onsite

5 months ago

Principal Secure SDLC engineer

Hewlett Packard Enterprise (HP) · Bengaluru, Karnātaka, India · Onsite

5 months ago

Principal Engineer - Secure Network Services

Wells Fargo · 112265-NJ-MetroPark, Iselin, United States of America +4

5 days ago

Principal Consultant, Secure Microsoft 365 Collaboration and AI

Cruciallogics · Remote (Canada) +1 · Remote

10 months ago

Principal Software Engineer - Secure Communications

RTX · US-IN-FT WAYNE-150A ~ 1010 Production Rd ~ BLDG 150A, United States of America · Onsite

3 weeks ago

Principal Systems Engineer - Secure Systems (Active Clearance)

RTX · US-IA-CEDAR RAPIDS-137 ~ 855 35Th St NE ~ BLDG 137, United States of America · Onsite

4 months ago

Principal Systems Engineer - Secure TacCom (Active Clearance)

RTX · US-IA-CEDAR RAPIDS-137 ~ 855 35Th St NE ~ BLDG 137, United States of America · Onsite

4 months ago

Principal Systems Engineer - Secure Systems

RTX · US-IA-CEDAR RAPIDS-137 ~ 855 35Th St NE ~ BLDG 137, United States of America · Onsite

4 months ago

Principal, Design Verification Engineer, Secure Root of Trust

Marvell · US-CA - Santa Clara, United States of America

1 month ago