A

OT Cybersecurity Specialist

Alstom Montreal, Quebec, Canada

Software Development · 11-50 employees

Yesterday
security Mid (2-5 yrs) Full-time Canada
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will analyze program security needs, conduct risk assessments, and develop cybersecurity designs for critical transportation systems. Additionally, you will manage third-party cybersecurity requirements and oversee vulnerability management and incident resolution.

What they look for

OT Cybersecurity Risk assessment Vulnerability management Incident resolution Security architecture ISO 2700X IEC 62443 NIST Wireshark Nmap Nessus Metasploit Network security Firewalls Intrusion detection systems Encryption

Requirements

Candidates should have a bachelor's degree in engineering, computer science, or a related field along with experience in cybersecurity within OT or ICS environments. Familiarity with industry standards like ISO 2700X, IEC 62443, and NIST is required, while relevant certifications are preferred.

Benefits

Life insurance Medical insurance Pension plan Professional development Shuttle services

Full description

Req ID:525773

At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, more than 80 000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.

Could you be the full-time OT Cybersecurity Specialist in Saint-Bruno-de-Montarville, Canada, we’re looking for? Saint-Bruno is located on the South Shore of Montreal, and with an onsite presence of three days per week required, Alstom offers convenient shuttle services four times a day to make your commute easier!

Your future role

Take on a new challenge and apply your operational technology (OT) cybersecurity expertise in a cutting-edge field that impacts critical infrastructure and real-world operations. You’ll work alongside a passionate, collaborative, and highly specialized team of cybersecurity professionals.

You'll play a key role in shaping the cybersecurity framework of critical transportation systems, ensuring safety, resilience, and innovation in a rapidly evolving industry. Day-to-day, you’ll work closely with teams across the business (engineering, project management, and external auditors), manage cybersecurity risks and vulnerabilities, and contribute to the development and implementation of robust cybersecurity measures.

You’ll specifically take care of analyzing program security needs and conducting cybersecurity risk assessments, but also supporting third-party cybersecurity management and incident resolution.

We’ll look to you for:

• Analyzing program security needs and conducting cybersecurity risk assessments

• Developing and implementing cybersecurity designs, including security architecture principles and controls

• Evaluating the project’s achieved cybersecurity level

• Managing third-party cybersecurity requirements and risks

• Overseeing cybersecurity vulnerability management and incident resolution

• Providing support during technical design meetings for cybersecurity activities

• Optionally contributing to cybersecurity process and standard definitions, trend analysis, training and awareness programs, and peer review of cybersecurity deliverables

All about you

We value passion and attitude over experience. That’s why we don’t expect you to have every single skill. Instead, we’ve listed some that we think will help you succeed and grow in this role:

• Bachelor’s degree in engineering, electronics, computer science, or a related field

• Experience related to cybersecurity, with exposure to operational technology (OT) or industrial control systems (ICS) environments

• Cybersecurity certifications such as GICSP, CISSP, GSEC, CISM, or CEH (preferred but not required)

• Knowledge of standards and regulations such as ISO 2700X, IEC 62443, and NIST

• Experience in information technology and operational technology security

• Familiarity with methods of risk analysis (e.g., ISO 27005, Ebios) and security tools such as Wireshark, Nmap, Nessus, or Metasploit

• Understanding of network security, firewalls, intrusion detection systems, and encryption tools

• Experience with embedded or industrial systems (e.g., railway, aerospace) is an asset

• Strong interpersonal skills to collaborate with cross-functional teams, customers, and suppliers

Things you’ll enjoy

Join us on a life-long transformative journey – the rail industry is here to stay, so you can grow and develop new skills and experiences throughout your career. You’ll also:

• Enjoy stability, challenges, and a long-term career free from boring daily routines

• Work with cutting-edge cybersecurity standards and technologies to secure critical transportation systems

• Collaborate with transverse teams and helpful colleagues

• Contribute to innovative projects

• Utilise our inclusive, innovative, and forward-thinking working environment

• Steer your career in whatever direction you choose across functions and countries

• Benefit from our investment in your development, through award-winning learning

• Progress towards exciting career opportunities in cybersecurity and critical infrastructure protection

• Benefit from a fair and dynamic reward package that recognises your performance and potential, plus comprehensive and competitive social coverage (life, medical, pension)

You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!

Important to note

As a global business, we’re an equal-opportunity employer that celebrates diversity across the 63 countries we operate in. We’re committed to creating an inclusive workplace for everyone.

Similar roles