.Cybersecurity EngineerDate: 30 Jul 2024Location: Madrid, MD, ESCompany: AlstomAt Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, 80,000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.Could you be the full-time Cybersecurity Engineer in Madrid we're looking for?Your future roleTake on a new challenge and apply your Cybersecurity expertise in a new cutting-edge field. You will work alongside young and proactive teammates.You will execute cybersecurity activities during project, tender or program execution. Day-to-day, you'll work closely with teams across the business (Engineering), perform and then maintain Cybersecurity Risk Analysis and much more.You'll specifically take care of developing and documenting risk mitigation action plans, including recommendations to reduce information security risk, but also perform the interviews for risk analysis of different sub-systems engineers.We'll look to you for:Audit the application of the mitigation plan for every stakeholder.Define Cybersecurity Architecture & Design principles including in particular:Proposition of the technical solution for implementation in line with cybersecurity design directives. One main outcome is the identification of possible candidate cybersecurity architectures.Define and maintain cybersecurity architecture with the identification of the zone, Security Level Target and Cybersecurity Functions.Support implementation of cybersecurity through active contribution in Author-Reader cycles of design documents.All about youWe value passion and attitude over experience. That's why we don't expect you to have every single skill. Instead, we've listed some that we think will help you succeed and grow in this role:Master's degree in Engineering/Technology or related field.Strong interest in Cybersecurity, experience related to Cybersecurity or hacking in general.Main standards and regulations, such as: ISO 2700X, 62443, NIST, NIS, French LPM.Knowledge of the security market and its key players.Knowledge of some security solutions and areas, such as: BRP / DRP, GRC, IAM, DLP, PKI, SOC.Technical proficiency in at least 2 of the following fields: Methods of risk analysis (ISO 27005, Ebios, etc.), Architecture concepts and techniques of systems and networks, operating systems and associated programming languages, Knowledge of the main techniques for evaluating systems security, Knowledge of tools such as Wireshark, Nmap, OpenVAS, Nexpose, Metasploit, Nessus, BURP, Encryption issues and tools (e.G. Truecrypt, OpenSSL), Low level filtering (Firewall owners, Iptables, OpenVPN), Intrusion testing techniques.Desirable: Cybersecurity certification such as: GICSP, CISSP, GSEC, CISM, CISA, CEH