Job description
At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, 80,000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.
Could you be the full-time Project Cyber Security Manager in Morocco/ Casablanca we’re looking for?
Your future role
Take on a new challenge and apply your Cyber Security Project’s Management expertise in a new cutting-edge field.
You’ll work alongside passionate, motivated and dedicated teammates.
You’ll analyze Project / Program security needs (including laws and local regulations), determine security objectives and main security risks strategy, plan security activities within development life cycle, estimate costs and duration, their impacts related to project program execution, Identify training needs
You’ll specifically take care of delivering Turnkey project, making sure it aligns with contractual requirements and customer expectations.
We’ll look to you to:
- Be responsible for Cost / Quality / Delay of Project Cybersecurity deliverables, as needed per Project context :
- Cybersecurity context, and Cybersecurity Risk Analysis, Cybersecurity Architecture
- definition and requirement allocation
- Cascading of requirement to suppliers, Manage Third Parties Risks,
- Application of Cybersecurity Assurance Level
- Definition of Cybersecurity Operating Procedures
- Evaluation of the Project/Program achieved Cybersecurity level
- Provide support during technical design meetings for cybersecurity activities
- Obtain agreement from Project/Program/Customer about on the set of security measures to be implemented
- Work with engineering team to ensure cybersecurity implementation & compliance
- Manage vulnerabilities and Cybersecurity issues and actions plan and manage Program / Project Cybersecurity related communication,
- In case of external Cybersecurity audit, manage the relationship with auditors Establish lessons learned
All about you
We value passion and attitude over experience. That’s why we don’t expect you to have every single skill. Instead, we’ve listed some that we think will help you succeed and grow in this role :
- University/ Engineer in degree level
- Experience with direct responsibility for hands on industrial systems, architecture, design, development
- Knowledge of main Cybersecurity standards and regulations, such as: ISO 2700X, IEC 62443, Law 05-20
- Experience related to Cybersecurity in general, deployment experience of security technologies.
- Cybersecurity certification such as: GICSP, CISSP, GSEC, CISM, QCD Management
- Experience in embedded or industrial systems (railway / aeronautics ...)
- Knowledge of main Cybersecurity standards and regulations, such as: ISO 2700X, 62443, NIST, NIS
- Methods of Cybersecurity risk analysis: For ex – Ebios 2010 – EBIOS RM – 27005
Things you’ll enjoy
Join us on a life-long transformative journey – the rail industry is here to stay, so you can grow and develop new skills and experiences throughout your career. You’ll also:
- Enjoy stability, challenges and a long-term career free from boring daily routines
- Collaborate with transverse teams and helpful colleagues
- Contribute to innovative projects
- Steer your career in whatever direction you choose across functions and countries
- Benefit from our investment in your development, through award-winning learning
- Benefit from a fair and dynamic reward package that recognises your performance and
- potential, plus comprehensive and competitive social coverage.
You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!
Important to note
As a global business, we’re an equal-opportunity employer that celebrates diversity across the 70+ countries we operate in. We’re committed to creating an inclusive workplace for everyone
وصف الوظيفة
في ألتسم، نفهم شبكات النقل وما يحرك الناس. من القطارات عالية السرعة والمترو والقطارات الأحادية والترافع، إلى الأنظمة الشاملة والخدمات والبنية التحتية والإشارات والتنقل الرقمي، نقدم لعملائنا المتنوعين أوسع مجموعة من المنتجات في الصناعة. كل يوم، يقود 80,000 زميل الطريق نحو تنقل أنظف وأكثر ذكاءً في جميع أنحاء العالم، مع ربط المدن بينما نقلل من الكربون ونستبدل السيارات.
هل يمكنك أن تكون مدير أمان المشروع بدوام كامل في المغرب/الدار البيضاء الذي نبحث عنه؟
دورك المستقبلي
تقبل تحديًا جديدًا وطبق خبرتك في إدارة مشاريع الأمن السيبراني في مجال حديث ومتطور.
ستعمل بجانب زملاء متحمسين ودائمين الالتزام ومتفانين.
ستقوم بتحليل احتياجات أمان المشروع/البرنامج (بما في ذلك القوانين والأنظمة المحلية) وتحديد أهداف الأمن واستراتيجيات المخاطر الرئيسية للأمن، وتخطيط أنشطة الأمن خلال دورة التطوير، وتقدير التكاليف والمدة وتأثيرها المرتبط بتنفيذ المشروع/البرنامج، وتحديد احتياجات التدريب
ستعتني بشكل خاص بتسليم مشروع Turnkey، والتأكد من توافقه مع المتطلبات التعاقدية وتوقعات العميل.
سنطلب منك:
- التحمل المسؤولية عن التكلفة/الجودة/التأخير في منتجات أمان المشروع حسب سياق المشروع:
- سياق الأمن السيبراني وتحليل مخاطر الأمن السيبراني والهندسة المعمارية للأمن السيبراني
- التعريف وتخصيص المتطلبات
- الت cascading من المتطلبات إلى الموردين، إدارة مخاطر الأطراف الثالثة،
- تطبيق مستوى ضمان الأمن السيبراني
- تعريف إجراءات التشغيل الأمني السيبراني
- تقييم المستوى الأمني المحقق في المشروع/البرنامج
- توفير الدعم أثناء اجتماعات التصميم الفنية لنشاطات الأمن السيبراني
- الحصول على اتفاق من المشروع/البرنامج/العميل حول مجموعة التدابير الأمنية المعتمدة
- العمل مع فريق الهندسة لضمان تنفيذ الأمن السيبراني والالتزام
- إدارة الثغرات وخطة الإجراءات الأمنية السيبرانية وإدارة الاتصالات المتعلقة بأمان البرنامج/المشروع
- في حالة وجود تدقيق خارجي للأمن السيبراني، إدارة العلاقة مع المدققين وتوثيق الدروس المستفادة
كل ما يخصك
نقيّم الشغف والموقف بدلاً من الخبرة فقط. لهذا لا نتوقع أن تمتلك كل مهارة على حدة. بدلاً من ذلك، أدرجنا بعض المهارات التي نعتقد أنها ستساعدك في النجاح والنمو في هذا الدور :
- درجة جامعية/هندسية في المستوى الجامعي
- خبرة بمسؤولية مباشرة عن أنظمة صناعية عملية، الهندسة المعمارية، التصميم، التطوير
- معرفة بمعايير وتنظيمات الأمن السيبراني الأساسية، مثل: ISO 2700X، IEC 62443، القانون 05-20
- خبرة مرتبطة بالأمن السيبراني بشكل عام، خبرة في نشر تقنيات الأمن
- شهادة في الأمن السيبراني مثل: GICSP، CISSP، GSEC، CISM، QCD Management
- خبرة في الأنظمة المدمجة أو الصناعية (سكة حديد/ طيران ...)
- معرفة بمعايير وتنظيمات الأمن السيبراني الرئيسية، مثل: ISO 2700X، 62443، NIST، NIS
- طرق تحليل مخاطر الأمن السيبراني: مثل Ebios 2010 – EBIOS RM – 27005
الأشياء التي ستستمتع بها
انضم إلينا في رحلة تحول مدى الحياة – صناعة السكك الحديدية موجودة لتبقى، لتتمكن من التطور وتطوير مهاراتك وخبراتك طوال مسيرتك المهنية. كما ستقوم أيضاً بـ:
- التمتع بالاستقرار والتحديات ومسار مهني طويل بلا روتين يومي ممل
- التعاون مع فرق عرضية وزملاء مساعدين
- المساهمة في مشاريع مبتكرة
- توجيه مسيرتك المهنية في أي اتجاه تختاره عبر الوظائف والدول
- الاستفادة من استثمارنا في تطويرك من خلال تعلم معتمد بجوائز
- الاستفادة من حزمة مكافآت عادلة وديناميكية تعترف بأدائك و
- إمكاناتك، بالإضافة إلى تغطية اجتماعية شاملة وتنافسية.
لا تحتاج إلى كونك من عشاق القطارات لتزدهر معنا. نضمن لك أنه عندما تركب أحد قطاراتنا مع أصدقائك أو عائلتك ستفخر بذلك. إذا كنت مستعدًا للتحدي، نود سماعك!
مهم للذكر
كشركة عالمية، نحن صاحب عمل يساوي الفرص ونحتفل بالتنوع عبر أكثر من 70 دولة نعمل فيها. نحن ملتزمون بخلق مكان عمل شاملاً للجميع