About this role
<p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">Req ID:479868 <br><br></span></p> <p class="paragraph" style="text-align:justify"><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, more than 80 000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.<br><br><span style="color:#2c3241;background-color:#ffffff">Could you be the full-time hybrid Project Program Cybersecurity Manager in Toronto, ON, CA we’re looking for?</span> <br><br></span></p><p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Your future role </strong></span><br><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Take on a new challenge and apply your cybersecurity and engineering expertise in a new cutting-edge field. You’ll work alongside innovative and collaborative teammates. You'll play a key role in shaping the cybersecurity framework of critical transportation systems, ensuring safety and resilience in a rapidly evolving industry. Day-to-day, you’ll work closely with teams across the business (engineering, project management, and external auditors), manage cybersecurity risks and vulnerabilities, and much more. </span><br><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">We’ll look to you for:</span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"> Analyzing Program security needs (including laws and regulations), determining security objectives and main security risks strategy</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Planning security activities within development life cycle, estimating costs and duration, their impacts related to program execution, Identifying training needs </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Responsible for Cost / Quality / Delay of Program Cybersecurity deliverables, as needed per Project / program context : </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Cybersecurity context, and Cybersecurity Risk Analysis </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Cybersecurity Architecture definition and requirement allocation </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Cascading of requirement to suppliers, Manage Third Parties Risks, </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Application of Cybersecurity Assurance Level </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Definition of Cybersecurity Operating Procedures </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Evaluation of the Project/Program achieved Cybersecurity level </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Providing support during technical design meetings for cybersecurity activities </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Obtaining agreement from Program/Customer about on the set of security measures to be implemented </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Managing vulnerabilities and Cybersecurity issues and actions plan, </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Managing Program Cybersecurity related communication, </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Reporting on Program Cybersecurity status </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">In case of external Cybersecurity audit, managing the relationship with auditors Establish lessons learned </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Promoting the Alstom Code of Ethics and adhering to the highest standards of ethical conduct </span><br><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"> </span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Performance measurements </strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">No "NO GO" for Cybersecurity reasons in Gate Reviews</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Quality of Cybersecurity deliverables, in time </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Achievement of Program targeted level of Cybersecurity </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Assessment findings: Low rework due to external or internal assessments </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Vulnerability management is in place </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Respect of Cybersecurity activities QCD commitment </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Cybersecurity issues/incident resolution </span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"> </span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>All about you<br></strong>We value passion and attitude over experience. That’s why we don’t expect you to have every single skill. Instead, we’ve listed some that we think will help you succeed and grow in this role: <br></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Experience with direct responsibility for hands on architecture, design, development (mandatory) </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Experience related to Cybersecurity in general, deployment experience of security technologies (mandatory) </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Experience with Project Management (mandatory) </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">8+ years of proven experience delivering safety critical systems (mandatory) </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">3-5 years of experience using standards including IEC-62443, CLC/TC 50701, APTA and other standards (mandatory) </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Experience performing cybersecurity analysis on Industrial Control Systems (mandatory)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Experience with conducting cyber certification for Industrial Control Systems in a lead role (mandatory) </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Experience in embedded or OT/ Industrial systems (railway/aeronautics) </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">P.Eng certified </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Experience performing cybersecurity analysis on passenger rail systems </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Experience with conducting cyber certification for rapid transit systems in a lead role </span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"> </span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Competencies & Skills </strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Engineering Background </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Knowledge of main Cybersecurity standards and regulations, such as: ISO 2700X, 62443, NIST, APTA </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Knowledge of some Cybersecurity solutions and areas </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Methods of Cybersecurity risk analysis </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Architecture concepts and techniques of systems and networks, operating systems and associated programming languages. </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Knowledge of the main techniques for evaluating systems security </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Certification in cybersecurity like CISSP/CISM/CEH/GICSP/CompTIA Security+ </span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"> </span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><strong>Things you’ll enjoy</strong> </span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Join us on a life-long transformative journey – the rail industry is here to stay, so you can grow and develop new skills and experiences throughout your career. You’ll also:</span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Collaborate with transverse teams and helpful colleagues , </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Work with cutting-edge cybersecurity standards and technologies to secure critical transportation systems, </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Utilise our inclusive, innovative, and forward-thinking working environment, </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Contribute to innovative projects, </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Benefit from our investment in your development, through award-winning learning, </span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:12.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:12.0pt">Benefit from a fair and dynamic reward package that recognises your performance and potential, plus comprehensive and competitive social coverage (life, medical, pension) </span></li> </ul> <p> </p><p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!<br><br></span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif"><strong>Important to note</strong></span></p> <p><span style="font-size:12.0pt;font-family:arial, helvetica, sans-serif">As a global business, we’re an equal-opportunity employer that celebrates diversity across the 63 countries we operate in. We’re committed to creating an inclusive workplace for everyone.</span></p>