$ cat jobs/principal-product-security-incident-responder-ge-vernova-278ad07e6625.json
Principal Product Security Incident Responder
Job Description Summary GE Vernova is seeking an experienced Product Security Incident Response Team Principal to lead PSIRT efforts across the business, reporting directly to the VP of Product Cybersecurity. This role manages externally identified product vulnerabilities and incidents across GE Vernova's business units, coordinates remediation and disclosure across multiple product lines, and runs the company's CVE Numbering Authority (CNA) program. The PSIRT Leader ensures compliance with EU CRA and other applicable regulatory reporting obligations, partners with the CISO's CERT and business unit security teams, and may coordinate with law enforcement and E-ISAC as circumstances require. An AI-forward approach is a core expectation. This leader will deploy AI-powered tooling to accelerate triage, automate vulnerability scoring, and scale PSIRT capacity to meet the growing volume of incidents driven by the rapid advancement of AI frontier models-including large language models and autonomous agentic systems-which are expanding the OT attack surface, accelerating exploit development, and lowering the barrier for adversaries targeting critical infrastructure. Job Description Key Responsibilities: Vulnerability Management & Coordinated Disclosure Operate the GE Vernova PSIRT, maintaining the policies, processes, and tools to triage, track, and resolve product vulnerabilities across all business units. Manage end-to-end Coordinated Vulnerability Disclosure (CVD), ensuring alignment with industry standards and mandatory EU CRA notification timelines (including ENISA/CSIRT reporting). Lead the CNA (CVE Numbering Authority) program, managing the assignment and lifecycle of CVE records to ensure timely, accurate public disclosures. Product Incident Response Lead responses to product-related cybersecurity incidents at customer sites, coordinating across engineering, legal, and customer-facing teams. Maintain and exercise incident response playbooks and communication templat