Job Search and Career Advice Platform

Activez les alertes d’offres d’emploi par e-mail !

Information Security Director

Alstom

Saint-Ouen

Sur place

EUR 100 000 - 130 000

Plein temps

Hier
Soyez parmi les premiers à postuler

Générez un CV personnalisé en quelques minutes

Décrochez un entretien et gagnez plus. En savoir plus

Résumé du poste

A global mobility solutions provider in Saint-Ouen is seeking an experienced Information Security Director to lead its security initiatives. You will define and implement the security strategy, ensuring compliance with international standards and managing risks. The ideal candidate has over 15 years of experience in cybersecurity, strong leadership skills, and is fluent in English. This role offers an opportunity to impact security operations within a diverse environment.

Qualifications

  • 15+ years in cybersecurity roles.
  • Proven experience in managing global programs and teams.
  • Fluent in English.

Responsabilités

  • Define and maintain Alstom’s Information Security mission and strategy.
  • Ensure compliance with international standards and oversee risk management.
  • Lead global Information Security Operations and manage the Security team.

Connaissances

Security Architecture
Security Operations
Risk Management
Strategic thinking
Leadership
Communication
Stakeholder engagement

Formation

Master’s degree in Information Security, Computer Science, or related field
Description du poste

At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, more than 80 000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.

JOB TITLE & JOB CODE

Job Title (Job code): Information Security Director

PURPOSE OF THE JOB
  • The Information Security Director is responsible for defining, implementing, and continuously improving Alstom’s global security strategy across Digital Services.
  • This role ensures the Confidentiality, Integrity, and Availability of digital assets, and aligns security initiatives with business objectives and regulatory requirements.
  • This end‑to‑end strategic position encompasses the governance and identification of cybersecurity risks, the protection of Alstom digital assets, the detection of security events and the response to security incidents.
ORGANISATION
Organisation structure (job belongs to)

DIGITAL SERVICES

Reports directly to

Group Chief Information Security Officer

Other reporting to

“Dotted line reporting” Position title if any

Direct reports
  • Governance Risk and Compliance
  • Cybersecurity Projects/Programs
  • Cybersecurity Architecture & Solutions
  • Security into Projects
  • Identity and Access Management
  • Security Operations Center
  • Product Security Service Center
Network & Links
Internal
  • Business Process Solutions
  • Operations Center
  • IT Infrastructures
  • Data and AI
  • Digital Platforms
  • Business Lines
External
  • Service providers
  • Technology vendors
  • Regulatory bodies (e.g. ANSSI)
MAIN RESPONSIBILITIES
Strategic Leadership
  • Define and maintain Alstom’s Information Security mission, vision, strategy, and roadmap, in coordination with the Group CISO.
  • Align Information Security initiatives with Corporate objectives and Digital Transformation programs.
  • Contribute to global security governance and represent Information Security in executive committees.
Governance, Risk Management & Compliance
  • Maintain Alstom ISMS policies ensuring compliance with international standards (ISO 27001, NIS 2 and any applicable regulation).
  • Oversee Digital Services Cybersecurity Risk Management including Security Debt Management, Security Validation, and Third Parties Risk Management.
  • Improve Alstom Information Security awareness and culture.
  • Animate the global network of Security correspondents.
Projects/Programs/Crisis
  • Deliver Information Security project and program portfolio on time, on budget and on quality.
  • Lead the Information Security roadmap and budget management.
  • Ensure the Information Security Crisis processes and procedures are up to date and organization readiness.
Security into Projects
  • Oversee all Digital Services and Business led projects to ensuring compliance to Alstom ISMS requirements.
  • Perform projects risk assessments including Sensitivity assessment, Risk identification and recommendations with required measures.
Architecture & Solutions
  • Ensure Cybersecurity Solutions meet required efficiency and performance to mitigate the evolving threat landscape.
  • Supervise the design and deployment of secure architectures for IT and Industrial environments (labs and shopfloors).
  • Drive adoption of security patterns and standards across projects and platforms.
  • Manage the PKI Services.
Identity & Access Management (IAM)
  • Oversee and manage IAM for Mission and Business Critical Applications.
  • Manage the Alstom Identity and Access Governance solution (passport).
  • Manage the Alstom B2B IAM solution.
  • Oversee the Privilege Access Management including privilege access platform and PAM processes.
Security Operations
  • Lead global Information Security Operations, including SOC, VOC, Threat Intelligence and endpoint security.
  • Ensure robust security event detection, incident response and reaction.
  • Lead the Risk Based Vulnerability Management activities (RBVM).
  • Proactively identify threats relevant in Alstom environment.
  • Monitor KPIs and implement continuous improvement plans for security services.
Product Security Service Center
  • Deliver Vulnerability Assessment and Pen Tests (VAPT) Services for Alstom Products and Projects.
  • Manage and maximize adoption of the Alstom Static Code Analysis solution (SCA).
  • Lead the global Product and Solution Incident Response Team (PSIRT).
  • Lead the NIDS competency center for Railway projects.
People & Stakeholder Management
  • Build and mentor a high-performing Security team across multiple geographies.
  • Foster collaboration with IT domains, transverse functions, and business stakeholders.
  • Promote cybersecurity awareness and training programs across the organization.
MAIN REQUIRED COMPETENCES
Educational Requirements

Master’s degree in Information Security, Computer Science, or related field

Fluent in English

Experience

15+ years in cybersecurity roles

Proven experience in managing global programs and teams

Competencies & Skills
  • Security Architecture
  • Security Operations
  • Risk Management
  • Familiarity with ISO 27001 and NIST frameworks
  • Soft Skills: Strategic thinking, leadership, communication, stakeholder engagement

You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!

Important to note

As a global business, we’re an equal‑opportunity employer that celebrates diversity across the 63 countries we operate in. We’re committed to creating an inclusive workplace for everyone.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez un fichier PDF, DOC, DOCX, ODT ou PAGES jusqu’à 5 Mo.