Key Notes
Operational-technology cyber security is delivered across rail and infrastructure lifecycles in this senior/principal engineering post. It covers governance, risk assessment, requirements and assurance from concept through operation. The permanent advert offers several UK offices alongside Cork and Dublin. At least three years of OT cyber-security experience, a relevant computing degree and IEC 62443 knowledge are essential.
What You'll Work On
- Deliver cybersecurity solutions and lifecycle governance for rail and infrastructure clients, creating the evidence required from concept through operational and maintenance phases.
- Support cyber-security strategy and planning, coordinating requirements with clients and adapting solutions to technical, cost and cross-discipline design constraints.
- Check that relevant cybersecurity standards are addressed and work with other disciplines and security engineers to resolve identified compliance or design issues.
- Support schedules and deliverables, review technical reports and contribute to expressions of interest and tenders alongside the Security and Software Assurance lead.
Why This Role Matters
- Rail and infrastructure systems gain cybersecurity governance and evidence across their lifecycle, helping projects address OT threats through defined requirements and risk-management activity.
- Engineering teams can resolve security issues in the wider system design when cybersecurity requirements and standards are coordinated with client needs and other disciplines.
What They Are Looking For
- Qualification: A cybersecurity, computer-science, computer-science engineering or similar BSc is essential.
- Experience: At least three years of OT cyber security and cyber-risk management, including complex-system threat and risk assessment, are essential.
- Technical: Essential knowledge includes IEC 62443, ISO 27005/NIST 800-82/800-53, zones/conduits, requirements, assurance and audit support.
- Technical: Independently defining cybersecurity strategy and planning, establishing OT governance and supporting supply-chain cybersecurity audits are essential.
- Preferred: NIS/NIS2, railway TS 50701 and frameworks such as EN 50126/9, IEC 62278, IEC 62425, ISO 15288 or ISO 12207 are desirable.