Project Security Leader

Bangalore, IN

Alstom

Leading the way to greener and smarter mobility worldwide, Alstom develops and markets integrated systems that provide the sustainable foundations for the future of transportation.

View all jobs at Alstom

Apply now Apply later

Req ID:469871 

 

At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, more than 80 000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.

 

 

JOB TITLE & JOB CODE

Job Title (Job Code):      Security into Project Leader

 

PURPOSE OF THE JOB

Reporting directly to the Cybersecurity Director, the Security into Project Leader ensures that the “Security into Project” policy (ISM-WMS-020) is applied for any given IS&T project, or any Business managed digital initiative. The Security into Project Leader will lead a team of Specialists and Experts, in charge of ensuring that the Alstom ISMS policies requirements are met. The Security into Project team will ensure that the design patterns and standards are implemented applying the existing processes and procedures.

ORGANISATION

Organisation structure (job belongs to..)

Digital Services

 

Reports directly to:

Cybersecurity Director

 

Other reporting to:

Dotted line to the Head of Security Architecture

 

Direct reports:

6

Network & Links

Internal

  • Security Architecture, GRC and ISMS team
  • Digital Services Head, VPs and Directors and teams,
  • Architects, Project Managers and PMO,
  • Business teams

External

  • Service Providers and vendors

MAIN RESPONSABILITIES  

 

  • People and team management: recruitment, development, animation …
  • Performance management: KPI reporting and service improvement plan
  • Drive Security into Project policy adoption
  • Adapt to new digital operating models supporting and securing the business led digital initiatives (SaaS, …)
  • Contribute to Alstom ISMS improvement and patterns revision
  • Represent the team and explain decisions during committees (PRC, ASB, …)
  • Manage allocated budget: actual, forecast, …
  • Collaborate with all project stakeholders, and gain adequate support when needed
  • Create and animate a community of Champions in the different teams turning detractors to promotors
  • Support the team on the following activities :
    • Review and approve security deliverables: information system security questionnaires, architecture design documents, security checklist.
    • Perform Risk analysis and identify/propose mitigation plan
    • Make arbitrations evaluating and documenting the residual risk, and ensuring all the exceptions are tracked in the relevant register
    • Ensure that Security Inquiry for Partners (SIP) is validated and signed of for all eligible partners in the ecosystem
    • Ensure that Secure configurations are systematically applied for given projects or business initiatives
    • Security Acceptance – make the right decision considering the residual risk and the asset value.

 

Qualifications

Educational Requirements

Mandatory:

  • Bachelor's/Master's degree in Engineering/Technology

Desirable:

  • CISSP or CISM
  • Experience in Transport Industry is a plus

Experience

Mandatory:

  • 10 years of work experience in cybersecurity
  • 5 years in people or project management

Desirable:

 

General Competencies & Skills

 

  • Knowledges and understanding in Security Architecture / Infrastructure Architecture.
  • Excellent written/verbal/communication, listening and facilitation skills.
  • Able to identify and document specific security issues, propose resolution options, and interpret matters from the perspective of involved stakeholders.
  • Able to analyse technical risks and vulnerabilities and to design the appropriate network security pattern (firewalling, proxy, WAF, VPN, etc.).
  • Good understanding of security tools and mechanisms (IDS/IPS, antivirus, anti-malware, authentication mechanisms, IAM, PKI, encryption, etc.).
  • Good understanding of cloud solutions (Microsoft Azure/O365, security solutions in and for the cloud).
  • Knowledge of ISO 27002 and ISO 27005.
  • Fluency in EnglishIT

 

 

 

 

You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!

 

Important to note

As a global business, we’re an equal-opportunity employer that celebrates diversity across the 63  countries we operate in. We’re committed to creating an inclusive workplace for everyone.

 

 

Job Type:​Experienced​

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  3  1  0
Category: Leadership Jobs

Tags: Antivirus Azure CISM CISSP Cloud Encryption IAM IDS IPS ISMS ISO 27002 ISO 27005 Malware Network security PKI Risk analysis SaaS VPN Vulnerabilities

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.