> Markdown version of [/jobs/ext/2700411-principal-product-security-incident-responder-m-f](https://www.wearedevelopers.com/jobs/ext/2700411-principal-product-security-incident-responder-m-f). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Incident Responder (m/f) - **Company:** GE Vernova - **Location:** UK (Remote available) - **Experience:** Expert - **Salary:** £147,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Information Systems Security Architecture Professional, Software Vulnerability Management, Software Security, Mttr, Information Technology - **Published:** September 4, 2026 - **Apply:** https://dejobs.org/x/x/C83CFE27C2FC4778863AC2DC3743CE3F/job/ ## About the Role * Significant experience in cybersecurity, with deep expertise in PSIRT operations, vulnerability management, or product incident response in an industrial or energy context * Proven leadership of a PSIRT function, including hands-on management of coordinated vulnerability disclosure (CVD) and customer-facing security incidents * Experience engaging with law enforcement, government agencies, or national authorities on sensitive cybersecurity matters * Deep familiarity with CVE, CVSS (Common Vulnerability Scoring System), CWE (Common Weakness Enumeration), and standards including ISO/IEC 29147 and ISO/IEC 30111 Preferred * Direct experience with GE Vernova products or equivalent OT/industrial energy systems * Familiarity with IEC 62443 security standards and energy-sector ISACs (Information Sharing and Analysis Centers), including E-ISAC (Electricity Information Sharing and Analysis Center) * Experience building or scaling a PSIRT function from the ground up * Professional certifications such as CISSP (Certified Information Systems Security Professional), GCIH (GIAC Certified Incident Handler), or GICSP (Global Industrial Cyber Security Professional) Education A formal education and subsequent Bachelor's or Master's degree in Cybersecurity, Computer Science, Engineering, or a related discipline is nice to have, but we are most interested in your total experience and professional achievements. ## Description * Lead vulnerability management and coordinated disclosure - operate the GE Vernova PSIRT end-to-end: triage, tracking, remediation coordination, and public disclosure aligned to industry standards and mandatory EU Cyber Resilience Act (CRA) notification timelines, including reporting to ENISA (European Union Agency for Cybersecurity) and national CSIRTs (Computer Security Incident Response Teams). * Run the CNA program - manage the full lifecycle of CVE (Common Vulnerabilities and Exposures) records, ensuring timely and accurate public disclosures across all GE Vernova product lines. * Direct product-related incident response - lead responses to cybersecurity incidents at customer sites, coordinating across engineering, legal, and commercial teams; maintain and exercise incident response playbooks to ensure consistent, rapid resolution. * Deploy AI-powered tooling - automate vulnerability scoring, incident triage, and situational awareness to meet the growing volume of threats driven by large language models, autonomous agentic systems, and adversaries targeting operational technology (OT) environments. * Build cross-functional partnerships and governance - align PSIRT operations with the enterprise CERT (Computer Emergency Response Team) function; embed PSIRT liaisons across business units; define and report on key performance metrics such as Mean Time to Remediate (MTTR) and disclosure compliance for executive leadership and enterprise risk reviews. Who You Are You bring significant experience in PSIRT operations and vulnerability management, with a track record of leading coordinated disclosure programs in complex, regulated, or industrial environments. You are comfortable engaging government authorities and law enforcement on sensitive matters, and you understand how emerging AI capabilities are reshaping the threat landscape for critical infrastructure. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)