Cyber Security Engineer

Alstom
Derby
1 week ago
Create job alert

Req ID:482961 

Location:Derby

Appointment Basis:Permanent 

Apply by:- 29/04/25

Excellent Salary + Benefits Include:Pension, Contributed Healthcare, Life Assurance, plus many flexible benefits.

At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, 80,000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars. 

Alstom is the UK & Ireland’s leading supplier of new trains and train services, and a leading signalling and rail infrastructure provider. Alstom have built, or are building, just under 40% of the UK mainline train fleet. We provide the widest range of smart solutions in the rail market, from innovative high-speed rolling stock, metros and trams to maintenance, modernisation, infrastructure and signalling. 

Your future role

Take on a new challenge and apply your cybersecurity expertise in the new field of Digital Mobility. You’ll report to the Regional Cybersecurity Director UKI/SPP and work within a close-knit and agile team that is part of the rail industry’s largest and most successful cybersecurity organisation.

Care to make a difference?

You'll be responsible for the delivery of cybersecurity objectives and deliverables to achieve security outcomes for customers that benefit the safety and resilience of the railway. Day-to-day, you’ll work closely with Project Cybersecurity Managers and teams across the business, including product cybersecurity specialists, quality, safety and engineering teams.

You’ll initially work on the Cork Area Commuter Rail project and will support other projects as the need arises. 

We’ll look to you for system and sub-system cybersecurity risk analyses, design, and assurance activities.

Specifically:

· Analysis of project security needs against applicable standards and regulations to identify target security levels and risk treatment strategies.

· Definition of cybersecurity architectures and design principles.

· Producing cybersecurity deliverables needed for project Gate Reviews.

· Cybersecurity evaluation.

· 3rd party management; and

· Providing support for cybersecurity activities during technical design meetings.


All about you

We understand that industrial cybersecurity is an emerging discipline, and we value passion and attitude over experience. We don’t expect you to have every single skill. Instead, we’ve listed some that we think will help you to succeed and grow in this role:

· Expertise (or a degree) in a relevant engineering or technical discipline.

· Experience or good understanding of industrial network security and/or embedded systems - perhaps gained in another industrial sector.

· Knowledge of IACS security standards and a working knowledge of information security standards such as ISO2700x, NIST etc.

· Familiarity with security risk management and IACS reference security architectures; and

· A relevant cybersecurity certification.


On a more personal level, you will also need to be:

· Adaptable and open to change: IACS cybersecurity processes and standards are new and may be subject to change; others are in development. You will need to remain current and embrace the changes that the topic is bringing.

· Self-motivated with a desire to learn.

· Able to work independently; and

· A strong team player, with effective interpersonal skills.


Things you’ll enjoy

Join us on a life-long transformative journey – the rail family is here to stay, so you can grow and develop new skills and experiences throughout your career.

You’ll also:

· Enjoy stability, challenges and a long-term career free from boring daily routines.

· Work with new security standards for rail signalling, such as IEC 62443, TS 50701 and IEC PT 63452.

· Utilise our Agile style of working to collaborate with transverse teams and helpful colleagues on innovative projects.

· Steer your career in whatever direction you choose across functions and countries.

· Benefit from our investment in your development, through award-winning learning and our Cybersecurity Academy.

· Progress towards other senior cybersecurity roles: , Project Cybersecurity Manager, Delivery Head, Regional Cybersecurity Manager or Director; and

· Benefit from a fair and dynamic reward package that recognises your performance and potential, plus comprehensive and competitive benefits (pension, life ins., medical)

You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!

Important to note


Alstom is an equal opportunity employer committed to creating an inclusive working environment where all our employees are encouraged to reach their full potential, and individual differences are valued and respected. All qualified applicants are considered for employment without regard to race, colour, religion, gender, sexual orientation, gender identity, age, national origin, disability status, or any other characteristic protected by local law. 

As a 'Disability Confident' employer, we will interview all disabled job applicants who match the essential criteria of the job description or specification. We will consider flexible working requests for all roles unless operational requirements prevent otherwise.

Related Jobs

View all jobs

Cyber Security Engineer

Cyber Security Engineer

Cyber Security Engineer

Cyber Security Engineer

Cyber Security Engineer - Vehicle Security

Cyber Security Engineer - Defence Sector

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Contract vs Permanent Cybersecurity Jobs: Which Pays Better in 2025?

Cybersecurity has become one of the fastest-growing and most crucial fields in modern business. With high-profile breaches dominating headlines and the ongoing digital transformation exposing organisations to new threats, companies across the UK are competing to attract skilled cybersecurity professionals. Roles range from penetration testers (pen testers) and SOC (Security Operations Centre) analysts to compliance officers, cloud security architects, threat intelligence analysts, and CISOs (Chief Information Security Officers). As demand continues to surge, cybersecurity salaries have climbed accordingly, and businesses have turned to more flexible hiring practices. Alongside permanent employment, many professionals explore short-term day‑rate contracting or fixed-term contracts (FTCs), searching for the ideal balance of pay, job security, and growth opportunities. Which arrangement truly pays better in 2025—and which best aligns with your ambitions? In this article, we dive into the contract vs. permanent debate with a focus on cybersecurity roles. We will examine the current market, the structure of day‑rate vs. FTC vs. permanent positions, the pros and cons of each, and some hypothetical pay comparisons. By the end, you should have a clearer sense of which career path might suit your situation and goals—whether you are a seasoned specialist aiming for top rates, or an up-and-coming analyst seeking a stable environment to develop in.

Cyber Security Jobs for Non‑Technical Professionals: Where Do You Fit In?

Defence Needs More Than Hackers in Hoodies When headlines warn of ransomware crippling hospitals or deepfakes swaying elections, we picture hoodie‑clad hackers and elite penetration testers. Yet the reality of the UK’s cyber security sector is broader—and desperately short of talent. The Department for Science, Innovation & Technology (DSIT) estimates a shortfall of 11,200 cyber security professionals in 2024, while 43 % of advertised roles require governance, risk or communication skills rather than hands‑on technical exploits. Put plainly: if you can guide policy, manage projects, interpret regulations or inspire behaviour change, cyber security wants you. This guide highlights the fastest‑growing non‑technical roles, the transferable skills you already possess, and a concrete 90‑day plan to land a cyber security job—no packet sniffers required.

BAE Systems Cybersecurity Jobs in 2025: Your Complete UK Guide to Protecting Governments, Businesses and Critical Infrastructure

From securing the Royal Navy’s new Dreadnought submarines to foiling multimillion‑pound fraud rings, BAE Systems Digital Intelligence (DI)—formerly Detica—sits at the sharp end of global cyber defence. Head‑quartered in Guildford with hubs in Gloucester, Leeds and London, the 5,500‑strong DI business delivers threat‑intelligence platforms, secure‑by‑design software and 24/7 SOC services to government and commercial clients worldwide. With escalating ransomware, AI‑driven disinformation and complex supply‑chain threats, BAE plans to expand its UK cyber workforce by 20 % in 2025. Whether you’re a graduate passionate about reverse engineering, a DevSecOps engineer who loves IaC, or an incident‑response pro comfortable in high‑side environments, this guide explains how to land a BAE Systems cybersecurity job in 2025.