cybersecurity engineer
генерация резюме под вакансию
сопроводительное письмо
описание
GE Vernova provides portfolio-based system solutions for cybersecurity in operational technology and plant-adjacent IT, supporting industrial projects from proposal preparation through customer commissioning.
задачи
- Support projects on cybersecurity from the proposal phase through customer implementation;
- Assess cybersecurity requirements for critical infrastructure, including power plants and railway operations, and develop measures to meet them;
- Process technical security questionnaires, including RFI/RFQ;
- Design and adapt system architectures according to customer specifications;
- Define configurations for PCs, switches, firewalls, PLCs, and monitoring stations across projects;
- Prepare and support certification of procedures and standard system architectures according to IEC 62443-3;
- Assess and implement legal and normative requirements, including the Cyber Resilience Act, NIS2 Directive, and ISO/IEC 27001;
- Advise development departments on Security by Design and Secure Development Lifecycle;
- Plan, monitor, conduct, and evaluate testing activities;
- Support security incident response;
- Coordinate continuously with the development of automation components and support testing of automation systems;
- Help define and maintain processes for creating and managing Software Bill of Materials;
- Plan, conduct, and participate in technical cybersecurity meetings with customers, classification societies, and suppliers;
- Develop and deliver a company-wide cybersecurity training concept;
- Create cybersecurity guidelines, best practices, and technical policies for industrial plants and coordinate them with colleagues in the USA, UK, France, and India;
- Promote a sustainable security culture within the company;
- Travel nationally and internationally for technical meetings, site visits, and customer visits.
требования
- University degree in Industrial IT, Cyber Security, IT with a cybersecurity specialization, Automation & IT, or a comparable field;
- Strong knowledge of cybersecurity and industrial IT/OT, especially IEC 62443, CRA, NIS2, and ISO 27001;
- Experience with threat modelling, security risk assessments, and security reviews;
- Knowledge of vulnerability management and CVEs, CVSS, and security advisories;
- Experience with Software Bill of Materials and open-source compliance;
- Experience in interdisciplinary development projects;
- Strong customer orientation and communication skills;
- Very good German and English skills;
- Structured and solution-oriented working style;
- High initiative and sense of responsibility;
- Strong moderation and presentation skills.
условия
- 35-Hour workweek and 30 days of vacation;
- Flexible working time arrangements;
- On-site cafeteria;
- Welcome Days in a global company;
- No relocation assistance is provided.
навыки
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.