Req ID:469135
At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, more than 80 000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.
Purpose of the Job
Organize and manage Cybersecurity activities during Project
WHAT ARE MY RESPONSIBILITIES?
The Project Cybersecurity Manager is the point of contact of the Project for cybersecurity related subjects.
Establish the project Cybersecurity Management Plan
Ensure that applicable security requirements, security rules (including laws and local regulations), security guidelines, security information, etc. are distributed to project stakeholders and ensure compliance.
Plan security activities and manage the definition of the most efficient system architecture related to cybersecurity requirements of the contract.
Obtain agreement from internal stakeholders about targeted maximum residual risks level, cybersecurity risks to be addressed (risk management) and security measures to be implemented.
Review of Cybersecurity Risk Analysis and Evaluation Report, evaluate project and business impacts of technical vulnerabilities identified as part of technological monitoring activities
Review deployment documents (Design, RAM, V&V) from a cybersecurity perspective
Define and follow-up action plans to close the cyber security issues
Ensure Cybersecurity awareness been propagated to Alstom team and suppliers
Organize the capture of experience feedback and the implementation of continuous improvement plans for Cybersecurity aspects
Member of the Change Control Board (CCB), in charge of evaluating Cybersecurity related impact of Change Request (CR) and following them up to closure
Responsible for Cost / Quality / Delay Deliverables Cybersecurity for allocated projects
To be the technical interface with the customer for the Cybersecurity domain
WHAT DO I NEED TO QUALIFY FOR THIS JOB?
Qualification-
Mandatory:
University/ Engineer in degree level
Desirable:
Cybersecurity certification such as: GICSP, CISSP, GSEC, CISM
Skills required
12+ years total experience in information technology and security. Experience with direct responsibility for hands on architecture, design, development.
Experience related to management of cybersecurity in general, deployment experience of security technologies.
Management of Quality, cost and delivery
Methods of Cybersecurity risk analysis
Knowledge of some information security areas such as risk/vulnerability assessment, threats, recovery, risk & compliance reporting, identity management, intrusion detection/prevention, etc.
Knowledge of cybersecurity standards (ISO 2700X, IEC 62443, NIST, etc.)
Familiarity with security products and protocols.
Knowledge of industry best practices, methodologies, tools, etc. in the field of cybersecurity
Strong documentation (written) and presentation (verbal) skills
Ability to collaborate across traditional engineering functions.
Ability to communicate effectively with customers, vendors and internal stakeholders.
Cybersecurity certifications desirable (GICSP, CISSP, GSEC, CISM)
Dynamic, autonomous. Ability to work in a complex and cross functional environment.
Language Skills: Proficient in English language
IT Skills: MS office tools (Word, Excel, PowerPoint)
Measurement
No "NO GO" for Cybersecurity reasons in Gate Reviews
Quality of Cybersecurity deliverables, in time
Achievement of Project targeted level of Cybersecurity
Assessment findings: Low rework due to external or internal assessments
Vulnerability management is in place
Respect of Cybersecurity activities QCD commitment
Cybersecurity issues/incident resolution
You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!
Important to note
As a global business, we’re an equal-opportunity employer that celebrates diversity across the 63 countries we operate in. We’re committed to creating an inclusive workplace for everyone.
Job Type:Experienced
Job Segment: Project Manager, Information Security, Risk Management, Manager, Technology, Finance, Management