Industrial Cyber Security analyst

Apply now »

Date: 15-Jul-2021

Location: Bengaluru, KA, India

Company: Alstom

Req ID:107489 

We create smart innovations to meet the mobility challenges of today and tomorrow. We design and manufacture a complete range of transportation systems, from high-speed trains to electric buses and driverless trains, as well as infrastructure, signalling and digital mobility solutions. Joining us means joining a truly global community of more than 75 000 people dedicated to solving real-world mobility challenges and achieving international projects with sustainable local impact.  

Reporting directly to the Head of Information Security Architecture and Standards, the Industrial Cyber Security analyst supports Industrial Cyber Security architect to define some security architecture patterns and contributes to design the appropriate security mechanisms and tools to be implemented within the Alstom Information System, especially on LABs (development and test environment for Alstom products) & Shop floors (factories).

He is part of a team of security architects & analyst who define and support security solutions, standards and rules to be implemented to enforce the Security Policy in all Infrastructure and Business projects.

Main responsabilities

  • The Industrial Cyber Security Analyst is technical support of Industrial Cyber Security architect for industrial environments with the missions to
    • Manage Security studies and standards
    • Assess & validate Architecture, against Security Policy
    • Integrate of Security into standard designs
    • Support level 3/4 – expertise – for security solutions
    • Manage & budget support on Security projects

 

  • The Industrial Cyber Security Analyst follows and validates the security aspects in some Alstom’s IT projects
    • ISSCQ – produce all Information System Security and Compliance Questionnaire at the initial phase of all projects
    • Risk analysis – perform risk analysis and identify mitigation plan when relevant
    • Security Insurance Plan –make sure that all IT partners/providers respect the security policy when they deliver services (e.g. Cloud or SaaS provider)
    • Security Acceptance –make the right decision considering the residual risk and the asset value
    • ISS Run Q&A and industrialization

 

 

Qualification & Competencies - Expected Level

 

Initial Background: an IT leader having total of 5 years of experience in Industrial Cyber Security.

 

Languages: English

Mandatory experiences:

  • Knowledge of ISO 27002 and ISO 27005
  • Knowledge of ISA/IEC 62443, certification is a plus
  • Excellent written/verbal/communication in English mandatory, listening and facilitation skills
  • Able to identify and document specific security issues, propose resolution options, and interpret matters from the perspective of involved stakeholders
  • Able to analyze technical risks and vulnerabilities and to design the appropriate architecture for Industrial environment
  • Good understanding of OT environments
  • Good understanding of security tools and mechanisms (IDS/IPS, antivirus, anti-malware, authentication mechanisms, IAM, PKI, encryption, DevSecOps etc.)

An agile, inclusive and responsible culture is the foundation of our company where diverse people are offered excellent opportunities to grow, learn and advance in their careers.  We are committed to encouraging our employees to reach their full potential, while valuing and respecting them as individuals.   

 

 

Job Type:​Experienced​


Job Segment: Information Security, Technical Support, Technology