Cyber Security Architect

؜ - ؜Riyadh ؜ -

Job details

Req ID:‎437456


At Alstom, we understand transport networks and what moves people. From high-
speed trains, metros, monorails, and trams, to turnkey systems, services,
infrastructure, signalling and digital mobility, we offer our diverse
customers the broadest portfolio in the industry. Every day, more than ‎80 ‎000
colleagues lead the way to greener and smarter mobility worldwide, connecting
cities as we reduce carbon and replace cars.


OVERALL PURPOSE OF THE ROLE:


Responsible for designing, creating, and maintaining the cybersecurity aspects
of Alstom solutions


Network & Links:


Internal: Project/Program team (PM, Engineering, V&V, Safety, RAM, ..), Cyber
Engineers and CSP Leaders (as relevant), Cybersecurity Governance & Expertise,
Other Cybersecurity Architects
External: Customer representatives (as relevant), Supplier representatives (as
relevant), National authorities' representatives (as relevant).


RESPONSIBILITIES:


Key Accountabilities:




  • Responsible of Alstom solution security analysis and of the definition of its security requirements and architecture.



    • Understand the solution to be delivered and to be secured

    • Execute on the risk analysis and identify/ propose the he countermeasures to be put in place

    • Design and document reliable security architecture resilient against cyberthreats (CADRA)

    • Ensure update and upgrade delivered solution cybersecurity as needed

    • Guarantee the cybersecurity technical coverage vis-a-vis the contract




  • Lead and Contribute to activities such as:



    • Cybersecurity risks assessment

    • Cybersecurity requirement implementation

    • Cybersecurity evaluation of the developed solution(s)

    • Management of 3rd parties on Cybersecurity aspects

    • Cybersecurity Vulnerability Management




  • Provide technical guidance and supervision for the project team



    • Participate to Project Design Reviews

    • Support engineering team answer design and technical difficulties related to cybersecurity implementation,

    • be referent for management and third parties on cybersecurity architecture and technical implementation.

    • Ensure homogeneous cybersecurity implementation conform to Governance & Expertise policies.



  • Respond and support to any security-related incidents and provide post-event analysis

  • Ensure cyber trend watch (new threats, new techno, etc.) related to the delivered solution(s)


Key Job Authorities and Dimensions



  • Responsible for cybersecurity architecture at system and sub-system level

  • Cybersecurity Design Reviews

  • Ensure cybersecurity control implementation in design

  • Provide requested deliverable in time with adequate quality

  • Alignment with Alstom cybersecurity strategy and policies

  • Contribution to Peer Reviews


Performance measurements:



  • No "NO GO" for Cybersecurity reasons in Gate Reviews

  • Quality of Cybersecurity deliverables, in time

  • Achievement of Project/Program targeted level of Cybersecurity

  • Assessment findings : Low rework due to external or internal assessments

  • Vulnerability management is in place

  • Respect of Cybersecurity activities QCD commitment

  • Cybersecurity issues : quality of impact analysis, issue resolution


Qualifications & Skills:


EDUCATION



  • Engineering / University degree

  • Experience with direct responsibility for hands on architecture, design, development

  • Experience related to Cybersecurity in general, deployment experience of security technologies.

  • Extensive experience in IT/OT security and risk management with a focus on security, performance and reliability

  • Technical proficiency of Architecture concepts and techniques of systems and networks, operating systems and associated programming languages.

  • Experience in embedded or industrial systems (railway / aeronautics ...)

  • Experience in System Engineering


BEHAVIORAL COMPETENCIES:


You are an outstanding Team Player, with proven talent in organizing teams &
taking initiatives. You demonstrate excellent communication skills and able to
guide, influence and convince others in a matrix organization.


TECHNICAL COMPETENCIES & EXPERIENCE



  • Understanding of main cybersecurity standards and regulations, such as: ISA/IEC ‎62443, TS ‎50701, ISO 2700X, NIST,

  • Understanding of OT System architecture

  • Knowledge of cybersecurity risk assessment methodology: ISO ‎27005, IEC ‎62443

  • Knowledge of defense in depth techniques such as:

    • Network security architecture development and definition

    • Perimeter security controls such as firewalls, IDS/IPS, network access controls, and network segmentation

    • Various aspects of network security such as routers, switches, and VLAN security

    • Security concepts related to DNS, including routing, authentication, VPN, proxy services



  • Capacity to address high level (system) et low level (IT, Security technologies and Software design) and to design a cyber architecture (zoning, services, …).

  • Knowledge of recognized techniques for evaluating systems security and Intrusion testing techniques.

  • Understanding of third-party auditing and risk assessment

  • Ability to interact with a broad cross-section of personnel to explain and enforce security measures

  • Dynamic, autonomous. Creativity and ability to work in a complex environment.

  • Team spirit approach

  • Organized & reactive;

  • Strong communication skills;

  • Persuasive, resilient & committed.

  • Speak, read and write English.


You don't need to be a train enthusiast to thrive with us. We guarantee that
when you step onto one of our trains with your friends or family, you'll be
proud. If you're up for the challenge, we'd love to hear from you!


Important to note
As a global business, we're an equal-opportunity employer that celebrates
diversity across the ‎63 countries we operate in. We're committed to creating
an inclusive workplace for everyone.


Job Segment: Embedded, Testing, Risk Management, Technology, Finance

Job Summary

  • Advertiser: ALSTOM
  • Announcement date: 14/10/2023
  • Type of employment: -
  • Experience level: -
  • Educational level: -
  • Job location: Riyadh
  • Salary: -
  • Phone number: -

More jobs like this

Riyadh
01/05/2022

Where applicable, confirmation that you meet customer requirements for facility access which may include proof of vaccination and/or attestation and testing, unless an accommodation has been approved. **Secure our Nation, Ignite your Future** Become an integral part of a diverse team while working …

Riyadh
21/06/2023

Challenging Today. Reinventing Tomorrow. _We're invested in you and your success. Everything we do is more than just a project. It's our challenge as human beings, too. That's why we bring a thoughtful and collaborative approach to every one of our partnerships._ _At Jacobs, we challenge the status…

Riyadh, منطقة الرياض
23/06/2022

• تطبيق سياسات الامن السيبراني لتحقيق أهداف النظام الأمني • ربط بيانات الحوادث السيبرانيه لتحديد نقاط الضعف • تحليل الملفات من المصادر المتعددة لتحديد التهديدات المحتملة لأمن الشبكة • تحليل اتجاهات الدفاع السيبراني والإبلاغ عنها للجهات المعنية • تقييم ومراقبة تطبيق الشركة لنظام الأمن السيبر…

Kuwait City
30/07/2023

Overview: GovCIO is currently hiring for a Cyber Security. This position will be located in ASAB, Kuwait, SAB, KSA and UDAB, UAE. Position is an onsite position. Responsibilities: Correlates threat data from various sources to establish the identity and modus operandi of hackers active in client's …

Riyadh
08/11/2022

**1\. JOB DETAILS:** **Position Title:** **Manager: Cyber Security Operations** **Broad Band:** **M12: Management** **Reports to:** **Director: Cyber Security** **Department & Function: ****Ma 'aden Cyber Security ** **Talent Pipeline Layer:** **Managing Others (MO)** **2\. OVERALL JOB PURPOSE…

Riyadh
05/08/2022

Responsible for identifying, prioritize and respond to cybersecurity risks for the organization to protect its information assets and technology in accordance with the organization's policies and procedures, as well as relevant laws and regulations of National Cybersecurity Authority and other rela…

Riyadh
06/12/2022

**About this opportunity!** We are looking for a Telecom Cyber Security Officer to provide support and advice regarding network security and security risk management within a defined operational scope in line with customer security policies. Establish and execute unit security plans for the unit…

Riyadh
06/02/2023

**Title: Cloud Security Architect** **Location: Riyadh, Saudi Arabia** **About Accenture** Accenture is a leading global professional services company that helps the world 's leading businesses, governments and other organizations build their digital core, optimize their operations, accelerat…

Dubai
26/05/2022

**Industry:** Centralised exchange **Job Type:** Full Time **Job Location:** Dubai **Salary range:** $3000 - $4000 **Payment in Crypto:** Yes Bistox is a pioneering cryptocurrency exchange that combines the power of blockchain technology, FinTech advancements and leading-edge trading tools…

Cairo
30/04/2022

Purpose: A cybersecurity consultant contributes and participates in cybersecurity consultation engagements with customers; conducting first-grade assessments and producing technical analysis, and recommendations' research. They have in-depth technical knowledge in one or more cybersecurity domains.…

اللغة: العربيّة