Program Cybersecurity Manager

9 Months ago • 8 Years +

About the job

About the job

Req ID: 449391

We create smart innovations to meet the mobility challenges of today and tomorrow. We design and manufacture a complete range of transportation systems, from high-speed trains to electric buses and driverless trains, as well as infrastructure, signalling and digital mobility solutions. Joining us means joining a truly global community of more than 70000 people dedicated to solving real-world mobility challenges and achieving international projects with sustainable local impact.

Purpose of the Job

Organize and manage Cybersecurity activities of Alstom Product/Solution

WHAT ARE MY RESPONSIBILITIES?

The Program Cybersecurity Manager is the point of contact of the Program for cybersecurity related subjects. He is in charge of the following activities:

  • Analyse Program security needs (including laws and local regulations), determine security objectives and main security risks strategy
  • Analyse cybersecurity features to be developed based on product design directives (IEC 62443) and Alstom solution roadmap.
  • Obtain agreement from Program about on the set of security measures to be implemented
  • Plan security activities within development life cycle, estimate costs and duration, their impacts related to program execution.
  • Expert guidance to implementation team towards developing product cybersecurity features.
  • Is responsible for managing Cost / Quality / Delay of Program Cybersecurity deliverables, as below :
    • Cybersecurity Management Plan, Threat Modelling
    • Cybersecurity Architecture Definition and Requirement Allocation
    • Application of Cybersecurity Assurance Level
    • Cybersecurity evaluation plan and report
    • Cybersecurity Operating Procedures
    • Supplier capability assessment and COTS evaluation reports
    • Evaluation of the Program achieved Cybersecurity level
    • Provide support during technical design meetings for cybersecurity activities
    • Manage vulnerabilities and Cybersecurity issues and actions plan,
    • Manage Program Cybersecurity related communication,
    • Report on Program Cybersecurity status
    • In case of external Cybersecurity audit, manage the relationship with auditors Establish lessons learned

    WHAT DO I NEED TO QUALIFY FOR THIS JOB?

    Qualification-

    Mandatory:

    University/ Engineer in degree level

    Desirable:

    Cybersecurity certification such as: GICSP, CISSP, GSEC, CISM

    Skills Required

    • 8+ years total experience in information technology and security. Experience with direct responsibility for hands on architecture, design, development.
    • Knowledge in some product security areas like Data at Rest/Transit, Identity and Access Management, PKI, Hardening, Network protection and partitioning, Log/Event Management, Cryptography, IDS, etc.
    • Experience related to management of cybersecurity in general, deployment experience of security technologies.
    • Management of Quality, cost and delivery
    • Methods of Cybersecurity risk analysis, Threat Modelling.
    • Knowledge of some information security areas such as risk/vulnerability assessment, threats, recovery, risk & compliance reporting, identity management, intrusion detection/prevention, etc.
    • Knowledge of cybersecurity standards (ISO 2700X, IEC 62443, NIST, etc.) is desirable
    • Familiarity with security products and protocols.
    • Knowledge of industry best practices, methodologies, tools, etc. in the field of cybersecurity
    • Strong documentation (written) and presentation (verbal) skills
    • Ability to collaborate across traditional engineering functions.
    • Ability to communicate effectively with customers, vendors and internal stakeholders.
    • Cybersecurity certifications desirable (GICSP, CISSP, GSEC, CISM)
    • Dynamic, autonomous. Ability to work in a complex and cross functional environment.

    Language Skills: Proficient in English language

    • IT Skills: MS office tools (Word, Excel, PowerPoint)

    Measurement

    • No "NO GO" for Cybersecurity reasons in Gate Reviews
    • Quality of Cybersecurity deliverables, in time
    • Achievement of targeted level of Cybersecurity
    • Assessment findings: Low rework due to external or internal assessments
    • Vulnerability management is in place
    • Respect of Cybersecurity activities QCD commitment
    • Cybersecurity issues/incident resolution

    An agile, inclusive and responsible culture is the foundation of our company where diverse people are offered excellent opportunities to grow, learn and advance in their careers. We are committed to encouraging our employees to reach their full potential, while valuing and respecting them as individuals.

    Job Type: Experienced
    View Full Job Description

    Add your resume

    80%

    Upload your resume, increase your shortlisting chances by 80%

    About The Company

    Alstom commits to contribute to a low carbon future by developing and promoting innovative and sustainable transportation solutions that people enjoy riding. From high-speed trains, metros, monorails, trams, to turnkey systems, services, infrastructure, signalling and digital mobility, Alstom offers its diverse customers the broadest portfolio in the industry. With its presence in 63 countries and a talent base of over 80,000 people from 175 nationalities, the company focuses its design, innovation, and project management skills to where mobility solutions are needed most. 

    Bengaluru, Karnataka, India (On-Site)

    View All Jobs

    Get notified when new jobs are added by Alstom