About the job
Req ID: 449391We create smart innovations to meet the mobility challenges of today and tomorrow. We design and manufacture a complete range of transportation systems, from high-speed trains to electric buses and driverless trains, as well as infrastructure, signalling and digital mobility solutions. Joining us means joining a truly global community of more than 70000 people dedicated to solving real-world mobility challenges and achieving international projects with sustainable local impact.
Purpose of the Job
Organize and manage Cybersecurity activities of Alstom Product/Solution
WHAT ARE MY RESPONSIBILITIES?
The Program Cybersecurity Manager is the point of contact of the Program for cybersecurity related subjects. He is in charge of the following activities:
- Cybersecurity Management Plan, Threat Modelling
- Cybersecurity Architecture Definition and Requirement Allocation
- Application of Cybersecurity Assurance Level
- Cybersecurity evaluation plan and report
- Cybersecurity Operating Procedures
- Supplier capability assessment and COTS evaluation reports
- Evaluation of the Program achieved Cybersecurity level
- Provide support during technical design meetings for cybersecurity activities
- Manage vulnerabilities and Cybersecurity issues and actions plan,
- Manage Program Cybersecurity related communication,
- Report on Program Cybersecurity status
- In case of external Cybersecurity audit, manage the relationship with auditors Establish lessons learned
Qualification-
Mandatory:
University/ Engineer in degree level
Desirable:
Cybersecurity certification such as: GICSP, CISSP, GSEC, CISM
Skills Required
- 8+ years total experience in information technology and security. Experience with direct responsibility for hands on architecture, design, development.
- Knowledge in some product security areas like Data at Rest/Transit, Identity and Access Management, PKI, Hardening, Network protection and partitioning, Log/Event Management, Cryptography, IDS, etc.
- Experience related to management of cybersecurity in general, deployment experience of security technologies.
- Management of Quality, cost and delivery
- Methods of Cybersecurity risk analysis, Threat Modelling.
- Knowledge of some information security areas such as risk/vulnerability assessment, threats, recovery, risk & compliance reporting, identity management, intrusion detection/prevention, etc.
- Knowledge of cybersecurity standards (ISO 2700X, IEC 62443, NIST, etc.) is desirable
- Familiarity with security products and protocols.
- Knowledge of industry best practices, methodologies, tools, etc. in the field of cybersecurity
- Strong documentation (written) and presentation (verbal) skills
- Ability to collaborate across traditional engineering functions.
- Ability to communicate effectively with customers, vendors and internal stakeholders.
- Cybersecurity certifications desirable (GICSP, CISSP, GSEC, CISM)
- Dynamic, autonomous. Ability to work in a complex and cross functional environment.
- IT Skills: MS office tools (Word, Excel, PowerPoint)
- No "NO GO" for Cybersecurity reasons in Gate Reviews
- Quality of Cybersecurity deliverables, in time
- Achievement of targeted level of Cybersecurity
- Assessment findings: Low rework due to external or internal assessments
- Vulnerability management is in place
- Respect of Cybersecurity activities QCD commitment
- Cybersecurity issues/incident resolution
Job Type: Experienced