Security Engineer
5 giorni fa
genoa, liguria, Italia
Hitachi
Tempo pieno
Gratuito con email o Google
Salva questo lavoro e mantieni la tua ricerca organizzata
Crea un account gratuito per salvare lavori, creare avvisi e tornare a questa inserzione dalla tua dashboard.
Gratuito con email o Google
Location:
Naples, Campania, ItalyJob ID: R Date Posted: Company Name:HITACHI RAIL STS S.
P.
A.
Profession (Job Category):OtherJob Schedule: Full timeRemote:NoJob Description:Hitachi Rail is looking for an enthusiastic self-motivated Security Engineer who thrives in a fast-paced environment. The successful candidate is comfortable performing a wide range of tasks from administrative to strategic. The position is based in Naples, Italy.
Who We AreHitachi Rail is a fully integrated, global provider of rail solutions across rolling stock, signaling, service & maintenance, digital technology and turnkey. With a presence in 38 countries across three continents and over 13,000 employees, our mission is to contribute to society through the continuous development of superior rail transport solutions.
MissionAssure the design and implementation of the Cybersecurity System in order to achieve the requirements in terms of compliance, schedule, quality and cost imposed by the different contracts either for the Tender and Projects.
AccountabilitiesEnsure the identification, the management and the fulfillment of the contractual requirements and customer requestsAnalyze customer supplied system specifications, decomposing the statements within such specifications into software requirementsIdentify gaps between customer requirements and Hitachi standard software products or COTS productsDeveloping close working relationship with customer Cybersecurity representativesCreate requirement documents, including high level design documents, interface control design documents and detailed software requirements and specifications, and requirements traceability documents.
Be the primary technical interface to the customer throughout the life cycle of the project and act as technical liaison relative to the software development effort with other departments within the company working on the same project.
Contribute to the identification and resolution of the interfaces with the main subsystems (e.g. Signaling, TLC, DCS, SCADA, etc.) and security systems (e.g. SIEM)Interface with internal customers (project managers, construction managers, project engineers, and application engineers) and external stakeholders (customers, suppliers, subcontractors, local authorities, external assessor) to ensure consistent communication and system integration.
Develop and execute security management plan and commissioning plan, including resourcing, logistics, and scheduling. Onsite lead for commissioning and acceptance testing.
Coordinate work sequences, schedules, resources and punch list items.
Collaborate with stakeholders to define and execute testing protocols to achieve commercial operation, based on contractual requirements.
Oversee commissioning and acceptance testing of the entire plant in a safe manner, including controls and communication networks, power supplies, auxiliary systems like fire detection, ventilation, HMI.
Provide local/remote technical support troubleshooting during commissioning, and operation as needed.
Develop customer training and handoff material to internal and external O&M teams. Develop a train-the-trainer program to enable successful handoffs for safe operation of the plant.
Create professional commissioning and testing reports for internal stakeholders and external customers.
Drive continuous improvement on developing and capturing technical problem solving knowledge to enable other organizations to effectively resolve customer problems and inquiries.
Ownership of administrative responsibilities including, but not limited to: service reports, issue logging/tracking, job safety analysis, quality compliance.
Guarantee the preparation and approval of the Design:Conceptual DesignCyber Security Management PlanHigh Level Risk Assessment based on the methodologies described in the standards (NIST 800-53, IEC 62443 and ISO 27000)Detail Risk Assessment (DRA) and Threat and Vulnerability Risk Assessment (TVA)Security Case (in according to IEC 62443-4-1 and EN 50129:2018)for the security assurance and security procedures (for incident management, patch and vulnerability management, asset and configuration management, etc.)Security Report (include the VA and PT test results)Undertake Cybersecurity activities as defined in the design documentation, e.g. vulnerability assessmentGuarantee the continuous security monitoring of the System in accordance to the technology innovationSecurity Audits during the Project with the CustomerCompetenciesThe Cybersecurity engineer shall be able to:Act keeping in mind the impacts of his/her own work on the whole “Company system” and understanding the economic consequences of his/her activities both on client and organizational perspectives. Propose simple and efficient solutions to meet customer needs.
Commit to understanding and delivering against customer requirements, keeping them informed about progress on a specific activity/project. Actively seek information to understand customer circumstances, problems,