- Company Name
- Viveris
- Job Title
- Ingénieur cybersécurité gouvernance - Ferroviaire H/F
- Job Description
-
**Job title:** Security Governance Engineer – Railway
**Role Summary:**
Design, implement, and manage security governance and architecture for embedded railway systems. Lead risk assessments, compliance, and third‑party management while coordinating with product and project teams to embed security requirements across the product lifecycle.
**Expectations:**
- Bachelor’s or Master’s (Bac+5) in Cybersecurity, Computer Science, Systems Engineering, or related field.
- 2‑4 years of experience in industrial, critical or defense sectors; railway exposure preferred.
- Fluency in written and spoken English.
- Strong analytical, autonomous, and coordination skills.
**Key Responsibilities:**
- Conduct risk analyses (EBIOS‑RM, ISO 27005); define context, assess risks, formalise treatment plans, and derive security requirements.
- Model and evolve security architecture: establish target models, principles, prioritise and allocate security requirements.
- Assess and certify compliance: gather, analyze test reports, consolidate internal status, synthesize findings against IEC 62443, TS 50701, GDPR, Cyber Resilience Act.
- Manage third‑party controls via shared services: verify input quality, challenge quotes and deliverables.
- Provide technical and functional support to offers/projects: contribute clause‑by‑clause security requirements, define solutions, guide implementation.
- Structure and lead governance activities: perform vigilance, capture best practices, report to management.
**Required Skills:**
- Risk assessment methodologies (EBIOS‑RM, ISO 27005).
- Knowledge of IEC 62443 series, TS 50701, GDPR, Cyber Resilience Act.
- Industrial OT/ICS architecture, supplier integration, remote‑access security.
- Configuration management (Git), requirements tracking, compliance tools.
- Strong written and verbal communication; English proficiency.
- Ability to coordinate cross‑functional teams and drive independent work.
**Required Education & Certifications:**
- Master’s or equivalent in Cybersecurity, Information Technology, Embedded Systems, or related discipline.
- Certifications preferred: CISSP, CISM, or equivalent security architecture certifications.