At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, 80,000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.
Could you be the full-time Security Validation Manager in [LOCATION] we’re looking for?
Your future role
Take on a new challenge and apply your expertise in security validation and risk management in a cutting-edge field. You’ll work alongside collaborative and forward-thinking teammates.
You'll play a critical role in protecting Alstom’s solutions, services, and infrastructure by defining and executing security validations like audits and penetration tests. Day-to-day, you’ll work closely with teams across the business (e.g., IT, infrastructure, and application development teams), manage external suppliers, and maintain the lifecycle of the Azure environment used for validations, and much more.
You’ll specifically take care of onboarding and offboarding users in the Azure environment, maintaining virtual systems, and supporting risk assessments, but also designing actionable information security dashboards.
We’ll look to you for:
Defining and following up on individual security validations (audits and penetration tests) with external suppliers
Managing external suppliers and their deliverables
Maintaining the lifecycle of the Security Validations Azure environment, including onboarding/offboarding users and managing virtual systems
Supporting risk assessments and developing policies, standards, and guidelines
Analyzing test results and engaging stakeholders to implement remediation
Providing guidance on additional security controls to prevent vulnerabilities
Documenting tactics and procedures used for security assessments
Reproducing penetration testing results to verify remediation efforts
All about you
We value passion and attitude over experience. That’s why we don’t expect you to have every single skill. Instead, we’ve listed some that we think will help you succeed and grow in this role:
Degree in Computer Science, Cybersecurity, or a related field
Experience or understanding of security assessments, including penetration testing and configuration reviews
Knowledge of cloud environments such as Azure, AWS, and Oracle
Familiarity with managing virtual systems and pentesting tools
A relevant cybersecurity certification (e.g., CEH, CISSP, OSCP)
Strong analytical skills to interpret assessment reports and design actionable dashboards
Ability to manage external suppliers and collaborate with cross-functional teams
Things you’ll enjoy Join us on a life-long transformative journey – the rail industry is here to stay, so you can grow and develop new skills and experiences throughout your career. You’ll also:
Enjoy stability, challenges and a long-term career free from boring daily routines
Work with new security standards for rail signalling
Collaborate with transverse teams and helpful colleagues
Contribute to innovative projects
Utilise our flexible and inclusive working environment
Steer your career in whatever direction you choose across functions and countries
Benefit from our investment in your development, through award-winning learning
Progress towards more senior cybersecurity or management roles
Benefit from a fair and dynamic reward package that recognises your performance and potential, plus comprehensive and competitive social coverage (life, medical, pension)
You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!
Important to note
As a global business, we’re an equal-opportunity employer that celebrates diversity across the 63 countries we operate in. We’re committed to creating an inclusive workplace for everyone.
Job Segment: Computer Science, Risk Management, Database, Oracle, Information Security, Technology, Finance