About this role
Analyst Vulnerability Management at Alstom will help safeguard digital assets by identifying, assessing, and mitigating security risks. You’ll collaborate with infrastructure teams, application owners, and external partners to analyze threat intelligence, design security dashboards, and drive remediation.
What You'll Do
- Monitor new and emerging threats and vulnerabilities, verify applicability, and initiate remediation activities
- Schedule and manage penetration testing activities, analyze results, and engage stakeholders for remediation
- Analyze vendor assessment reports, resolve issues within SLAs, and remove false positives
- Design and deliver actionable information security dashboards and metrics
- Create awareness across the organization about good security practices and Secure SDLC programs
What We're Looking For
- Bachelor’s/Master’s degree in Engineering/Technology or a related field
- 6-8 years of relevant IT experience
- Professional certifications such as CISSP, CEH, GPEN, or OSCP
- Experience or understanding of threat modeling, systems hardening, and Secure SDLC programs
- Knowledge of penetration testing methodologies (OWASP, OSSTMM, PCIDSS) and tools like Qualys, Veracode, Nessus, and AppScan
- Familiarity with TCP/IP stack, OSI layers, middleware, and mobile technologies
- Strong analytical skills with demonstrated problem-solving ability
- Ability to develop custom scripts for vulnerability detection and response
- Experience in creating processes within a complex multivendor ecosystem
- Proven planning, prioritization, and organizational skills
- Professional and concise communication (written and verbal)
Things you’ll enjoy
- Stability, challenges, and a long-term career free from boring daily routines
- Work with new security standards for rail signalling
- Collaborate with transverse teams and helpful colleagues
- Contribute to innovative projects
- Utilise our flexible and inclusive working environment
- Steer your career in whatever direction you choose across functions and countries
- Benefit from our investment in your development, through award-winning learning
- Progress towards leadership roles or specialized cybersecurity expertise
- Benefit from a fair and dynamic reward package that recognizes your performance and potential, plus comprehensive and competitive social coverage (life, medical, pension)
Compensation & Benefits
- Comprehensive benefits package as described above, including social coverage (life, medical, pension)
- Flexible and inclusive working environment
- Investment in development through award-winning learning
- Long-term career opportunities across functions and countries