TLV-GL Cyber Design Manager
📍 Job Overview
Job Title: TLV-GL Cyber Design Manager
Company: Alstom
Location: Tel-Aviv, Israel
Job Type: Full-Time
Category: Cybersecurity Operations / GTM Security Management
Date Posted: 2026-09-16
Experience Level: 10+ Years
Remote Status: On-site
🚀 Role Summary
-
Lead and manage comprehensive cybersecurity initiatives across Alstom's projects and programs, ensuring robust security posture throughout the entire lifecycle.
-
Define, implement, and oversee security strategies, risk management frameworks, and architectural designs for both IT and OT environments.
-
Drive compliance with international and local cybersecurity regulations, standards, and Alstom's ethical code of conduct.
-
Manage project cybersecurity deliverables, including cost, quality, and schedule, while fostering a culture of security awareness and best practices within cross-functional teams.
-
Act as a key liaison for cybersecurity matters with internal stakeholders, third-party suppliers, and external auditors.
📝 Enhancement Note: This role is positioned as a critical management function within Alstom's project execution framework, focusing on the integration of cybersecurity from initial design through operational phases. The emphasis on IT/OT convergence and regulatory compliance specific to the transportation sector indicates a need for a candidate with a deep understanding of industrial cybersecurity and its application within a complex, regulated industry.
📈 Primary Responsibilities
-
Conduct thorough analysis of project and program security needs, considering legal and local regulatory requirements to establish clear security objectives and risk mitigation strategies.
-
Develop comprehensive cybersecurity plans for the development lifecycle, including accurate estimations of costs, durations, and resource allocation, identifying any necessary training for the team.
-
Take full responsibility for the Cost, Quality, and Delay (QCD) of project/program cybersecurity deliverables, which may include:
- Defining the cybersecurity context and conducting detailed cybersecurity risk analyses.
- Establishing the cybersecurity architecture and allocating security requirements across system components.
- Cascading security requirements to suppliers and effectively managing third-party cybersecurity risks.
- Developing and implementing robust cybersecurity operating procedures.
- Evaluating and validating the achieved cybersecurity level of the project or program.
-
Provide expert technical guidance and support during design meetings, ensuring cybersecurity considerations are integrated effectively.
-
Secure formal agreement from project stakeholders and customers on the proposed set of security measures to be implemented.
-
Proactively manage cybersecurity vulnerabilities and incidents, developing and executing action plans for resolution and mitigation.
-
Maintain clear and consistent communication regarding cybersecurity status and activities to program and project teams.
-
Prepare and deliver regular reports on the cybersecurity status of programs and projects to relevant stakeholders.
-
Manage the relationship with external cybersecurity auditors, facilitating audits and ensuring timely remediation of findings.
-
Establish and document lessons learned from cybersecurity activities to drive continuous improvement in future projects.
-
Champion and uphold Alstom's Code of Ethics, ensuring all cybersecurity activities are conducted with the highest standards of ethical conduct and integrity.
📝 Enhancement Note: The responsibilities highlight a dual focus on strategic security planning and hands-on management of cybersecurity deliverables within project constraints. The emphasis on QCD (Quality, Cost, Delay) management indicates the need for strong project management skills alongside technical cybersecurity expertise. The requirement to manage third-party risks and obtain customer agreement underscores the importance of stakeholder management and negotiation skills.
🎓 Skills & Qualifications
Education:
-
Mandatory: University or Engineering degree level.
-
Desirable: Cybersecurity certifications such as GICSP, CISSP, GSEC, CISM.
Experience:
-
Mandatory:
- Minimum of seven (7) years of experience in managing Information Security within national and international projects. This includes direct responsibility for hands-on architecture, design, and development.
- Proven experience in cybersecurity deployment and management of security technologies.
- Demonstrated experience in QCD (Quality, Cost, Delay) management.
-
Desirable:
-
Familiarity with Alstom's Products & Solution Portfolio.
-
Experience in embedded or industrial systems, particularly within the railway or aeronautics sectors. Required Skills:
-
-
Israeli Citizenship.
-
Possession of one of the following valid certificates: CISO, CISSP, CISM, or equivalent.
-
Extensive knowledge in the protection of both IT (Information Technology) and OT (Operational Technology) infrastructures and systems.
-
In-depth familiarity with up-to-date technologies and Information Security regulations pertinent to the transportation sector.
-
Familiarity with main Cybersecurity standards and regulations, including: ISO 2700X, IEC 62443, NIST, NIS, and French LPM.
-
Proficiency in cybersecurity risk analysis methodologies.
-
Strong understanding of architecture concepts and techniques for systems and networks.
-
Knowledge of operating systems and main techniques for evaluating system security.
-
Excellent problem-solving skills and the ability to work autonomously in a complex, dynamic environment.
-
Fluency in both English and Hebrew (read, write, and speak). Preferred Skills:
-
Engineering background is not mandatory but beneficial.
-
Knowledge of various cybersecurity solutions and domains.
-
Experience with Alstom's product portfolio and solutions.
-
Experience in embedded systems or industrial environments.
📝 Enhancement Note: The requirements are stringent, emphasizing a combination of advanced cybersecurity certifications, extensive practical experience in managing security for complex projects, and specific knowledge of IT/OT security within the transportation industry. The mandatory Israeli citizenship and security clearance are critical prerequisites for this role, indicating the sensitive nature of the projects involved. The desire for experience with Alstom's portfolio suggests an advantage for candidates familiar with the company's specific offerings.
📊 Process & Systems Portfolio Requirements
Portfolio Essentials:
-
Demonstrated experience in developing and managing cybersecurity architectures for complex systems, showcasing clear requirement allocation and integration strategies.
-
Case studies detailing successful cybersecurity risk analyses, including methodologies used, identified risks, and implemented mitigation strategies.
-
Examples of cybersecurity plans and project execution documentation, highlighting ability to manage Quality, Cost, and Delay (QCD) for security deliverables.
-
Documentation showcasing experience with third-party risk management and supplier security assessments.
-
Evidence of developing and implementing cybersecurity operating procedures and incident response plans. Process Documentation:
-
Workflows and documentation related to the lifecycle management of cybersecurity requirements, from initial definition to allocation and verification.
-
Process documentation for conducting and documenting cybersecurity risk assessments, including methodologies like threat modeling and vulnerability analysis.
-
Examples of security architecture diagrams and design documents that clearly articulate security controls and their placement within IT and OT environments.
-
Procedures for managing cybersecurity vulnerabilities and incidents, including tracking, prioritization, and remediation processes.
-
Documentation related to compliance activities, demonstrating adherence to standards such as ISO 27001, IEC 62443, NIST, and NIS.
📝 Enhancement Note: Candidates are expected to present a portfolio that substantiates their experience in managing cybersecurity across project lifecycles, with a strong emphasis on demonstrable process documentation. The portfolio should clearly illustrate their ability to integrate cybersecurity into system design, manage risks effectively, and ensure compliance with relevant standards, particularly within the context of industrial control systems (OT) and transportation infrastructure.
💵 Compensation & Benefits
Salary Range: Given the mandatory CISSP/CISM/CISO certification, 7+ years of experience in information security management, specific IT/OT security expertise, and the critical nature of the role within a global transportation company, the estimated salary range for a Cyber Design Manager in Tel-Aviv, Israel, would typically fall between ₪350,000 - ₪550,000 annually. This range is based on industry benchmarks for senior cybersecurity management roles in Israel, considering the high demand for specialized skills and the cost of living in the region.
Benefits:
-
Comprehensive health insurance package.
-
Pension plan contributions.
-
Paid time off, including vacation, sick leave, and public holidays.
-
Professional development opportunities, including training and certifications.
-
Potential for participation in Alstom's employee stock purchase plans or long-term incentive programs.
-
Access to Alstom's global mobility programs for international opportunities.
-
Reimbursement for professional memberships and conference attendance.
-
Potential for performance-based bonuses. Working Hours:
-
Standard working hours are typically 40 hours per week, Monday to Friday.
-
Flexibility may be required to address critical project deadlines or urgent security incidents, potentially involving work outside of standard hours.
📝 Enhancement Note: The salary estimation is based on market research for senior cybersecurity roles in Tel-Aviv, factoring in the required certifications and extensive experience. Benefits are standard for a large, multinational corporation like Alstom and are tailored to attract and retain high-caliber talent in specialized technical fields. The mention of potential work outside standard hours is typical for management roles with significant project responsibilities.
🎯 Team & Company Context
🏢 Company Culture
Industry: Transportation (specifically, rail technology and infrastructure). Alstom is a global leader in sustainable mobility, providing a broad range of solutions from high-speed trains to signaling and digital mobility services. This industry context means cybersecurity is paramount due to safety-critical systems and extensive regulatory oversight.
Company Size: Alstom is a large, global enterprise with over 80,000 employees worldwide. This scale implies robust corporate structures, established processes, and significant resources, but also potential for bureaucratic layers. For operations professionals, this means opportunities for large-scale impact and structured career paths, but also a need for adaptability within a large organization.
Founded: Alstom was founded in 1928. This long history suggests a company with deep industry experience, stability, and a strong legacy, which influences its culture and approach to innovation and risk management.
Team Structure:
-
The Cyber Design Manager will likely lead a specialized team of Cybersecurity Engineers, typically ranging from 1 to 5 individuals, reporting to a higher-level cybersecurity director or program manager.
-
This role involves functional animation of the team, meaning it includes technical guidance, task assignment, and performance oversight, rather than direct HR management for all team members.
-
Close collaboration is expected with Project Managers, System Architects, Engineering teams (both IT and OT), Procurement, and potentially external regulatory bodies. Methodology:
-
Alstom emphasizes a data-driven approach to cybersecurity, utilizing risk analysis and performance metrics to inform decisions and strategies.
-
Workflow planning and optimization are critical, especially given the project-based nature of the work and the need to integrate security seamlessly into development lifecycles.
-
Automation and efficiency practices are likely employed for tasks like vulnerability scanning, compliance checks, and incident reporting to manage the complexity and scale of operations.
Company Website: https://www.alstom.com/
📝 Enhancement Note: Alstom's position as a global leader in transportation technology underscores the critical importance of cybersecurity for safety, reliability, and regulatory compliance. The company's size and history suggest a structured environment with opportunities for significant impact and professional growth. The team structure indicates a leadership role with direct technical influence and cross-functional collaboration requirements.
📈 Career & Growth Analysis
Operations Career Level: This role is a senior-level management position within the cybersecurity domain, specifically focused on the design and integration phases of projects. It requires a blend of deep technical cybersecurity expertise, robust project management capabilities, and strategic leadership. The scope involves managing security for complex, potentially safety-critical systems in a regulated industry.
Reporting Structure: The Cyber Design Manager functionally animates a small team of Cybersecurity Engineers (1-5 individuals). They will report to a higher-level cybersecurity lead within a specific program or project, or potentially to a regional/divisional CISO, depending on the organizational structure. This position requires significant cross-functional collaboration with project management, engineering, and procurement.
Operations Impact: The operations managed by this role directly impact Alstom's ability to deliver secure, compliant, and reliable transportation solutions. Effective cybersecurity management is crucial for preventing disruptions, protecting sensitive data, ensuring passenger safety, and maintaining customer trust and regulatory approval. Successful execution of this role contributes directly to project success, risk mitigation, and Alstom's reputation as a secure provider.
Growth Opportunities:
-
Operations Skill Advancement: Potential to move into broader program-level cybersecurity leadership roles, managing larger teams and more complex portfolios, or specializing further in specific areas like OT security or embedded systems security.
-
Industry Specialization: Deepen expertise within the rail transportation sector, becoming a recognized authority on cybersecurity for rolling stock, signaling, and infrastructure.
-
Leadership Development: Opportunities to develop leadership skills through managing teams, mentoring junior engineers, and contributing to strategic cybersecurity initiatives at a corporate level. Potential progression to roles like Head of Cybersecurity for a specific business unit or region.
📝 Enhancement Note: This role offers a clear path for growth within specialized cybersecurity management, particularly in the high-demand field of industrial and transportation cybersecurity. The emphasis on project execution and cross-functional collaboration prepares individuals for broader leadership responsibilities within Alstom or the wider industry.
🌐 Work Environment
Office Type: This is an on-site role, implying the need for the manager to be physically present at Alstom's facilities in Tel-Aviv, Israel. The environment is likely a professional office setting within a corporate campus or dedicated business park.
Office Location(s): Tel-Aviv, Israel. This location offers access to a vibrant tech ecosystem and a skilled talent pool. The specific office location will be within Alstom's Israeli operational base, likely facilitating direct interaction with project teams and local stakeholders.
Workspace Context:
-
The workspace is expected to be collaborative, requiring close interaction with project managers, system architects, engineering teams, and potentially external partners.
-
Access to necessary cybersecurity tools, software, and Alstom's internal IT/OT infrastructure will be provided to support design, analysis, and management activities.
-
Opportunities for regular team meetings, design reviews, and cross-functional problem-solving sessions will be integral to the daily work.
Work Schedule: The role adheres to a standard 40-hour work week, typically Monday to Friday. However, given the nature of cybersecurity management for ongoing projects and potential for security incidents, there may be an expectation of flexibility, including occasional work outside of standard hours to address urgent matters or meet critical project deadlines.
📝 Enhancement Note: The on-site requirement in Tel-Aviv suggests a hands-on management role deeply embedded within Alstom's project execution teams. The workspace context emphasizes collaboration and the provision of necessary technical resources, while the work schedule acknowledges the demanding nature of cybersecurity leadership in a project-driven environment.
📄 Application & Portfolio Review Process
Interview Process:
-
Initial Screening: A review of your application, focusing on mandatory certifications (CISO, CISSP, CISM), 7+ years of experience, Israeli citizenship, and fluency in English/Hebrew.
-
Technical Interview(s): In-depth discussions covering cybersecurity principles, IT/OT security, risk analysis methodologies (ISO 27001, IEC 62443, NIST), architecture design, and experience with relevant security standards. Expect scenario-based questions related to project security challenges.
-
Portfolio Review: Presentation of your professional portfolio, highlighting specific case studies of cybersecurity project management, risk mitigation strategies, architecture designs, and QCD management for security deliverables.
-
Management & Cultural Fit Interview: Assessment of leadership style, team management approach (functional animation), stakeholder communication skills, problem-solving abilities, and alignment with Alstom's ethical code and values.
-
Final Interview: Likely with senior management or a program director to discuss strategic alignment and final approval.
Portfolio Review Tips:
-
Quantify Achievements: For each project in your portfolio, clearly articulate the scope, your role, the specific cybersecurity challenges, the solutions implemented, and the measurable outcomes (e.g., reduction in vulnerabilities, compliance achieved, cost savings, on-time delivery).
-
Showcase Process: Detail the processes you followed for risk assessment, architecture design, requirement allocation, and third-party risk management. Use diagrams where appropriate.
-
Highlight QCD: Demonstrate your ability to manage Quality, Cost, and Delay for cybersecurity deliverables. Provide examples of how you balanced these factors.
-
Tailor to Alstom: Research Alstom's projects and products, especially in the transportation sector. Frame your experience and portfolio examples to align with their needs and challenges.
-
Be Prepared for Technical Depth: Be ready to discuss specific security technologies, standards (ISO 27001, IEC 62443, NIST), and methodologies in detail.
Challenge Preparation:
-
Scenario-Based Problem Solving: Prepare for hypothetical scenarios related to managing cybersecurity on a complex rail project, such as dealing with a critical vulnerability discovered late in the project, managing a demanding supplier, or negotiating security requirements with a client.
-
Risk Analysis Exercise: Be ready to walk through your process for conducting a cybersecurity risk analysis for a new system or component.
-
Architecture Design Discussion: Prepare to discuss your approach to designing secure architectures for integrated IT/OT systems, considering specific threats and regulatory requirements in the transportation sector.
📝 Enhancement Note: The interview process is designed to thoroughly assess technical expertise, project management acumen, and leadership capabilities. A strong, well-documented portfolio showcasing practical application of cybersecurity principles in complex project environments is crucial. Candidates should be prepared for detailed technical discussions and scenario-based problem-solving relevant to industrial and transportation cybersecurity.
🛠 Tools & Technology Stack
Primary Tools:
-
Cybersecurity Management Platforms: Tools for vulnerability scanning (e.g., Nessus, Qualys), security information and event management (SIEM) systems (e.g., Splunk, LogRhythm), and endpoint detection and response (EDR) solutions.
-
Risk Management Software: Platforms for conducting and tracking risk assessments, such as dedicated GRC (Governance, Risk, and Compliance) tools or specialized risk analysis software.
-
Architecture Design Tools: Software for creating system diagrams and security architecture blueprints (e.g., Microsoft Visio, Lucidchart, specialized security modeling tools).
-
Project Management Software: Tools for planning, tracking, and reporting on project tasks and timelines (e.g., Microsoft Project, Jira, Asana).
Analytics & Reporting:
-
Data Analysis Tools: Proficiency in tools that can process and analyze security logs and event data to identify trends and anomalies.
-
Reporting & Dashboarding Tools: Experience with tools like Tableau, Power BI, or custom reporting solutions to visualize cybersecurity metrics and present status updates to stakeholders.
CRM & Automation:
-
While not directly a CRM role, understanding how CRM systems interact with security protocols and data management might be beneficial.
-
Workflow Automation Tools: Familiarity with tools that can automate routine security tasks, compliance checks, or reporting processes to improve efficiency.
-
Integration Tools: Knowledge of how different security systems and project management tools integrate to provide a cohesive security overview.
📝 Enhancement Note: The role requires proficiency with a broad range of cybersecurity tools, from those used for direct threat detection and management to platforms supporting risk assessment, architecture design, and project oversight. Familiarity with tools that facilitate reporting and automation will be key to managing complex projects efficiently.
👥 Team Culture & Values
Operations Values:
-
Integrity & Ethics: Upholding Alstom's Code of Ethics is paramount, with a strong emphasis on honesty, transparency, and ethical decision-making in all cybersecurity activities.
-
Security First: A deep-seated commitment to prioritizing security in all designs, processes, and decisions, recognizing the safety-critical nature of Alstom's products.
-
Collaboration & Teamwork: Fostering a collaborative environment where engineers and project teams work together effectively to achieve shared security objectives.
-
Excellence & Continuous Improvement: Striving for the highest standards in cybersecurity delivery and actively seeking opportunities for process optimization and skill development.
-
Accountability: Taking ownership of cybersecurity deliverables and commitments, ensuring responsibility for Quality, Cost, and Delay.
Collaboration Style:
-
Cross-Functional Integration: Actively engaging with project managers, system architects, software/hardware engineers, and procurement teams to embed security seamlessly into the product development lifecycle.
-
Proactive Communication: Maintaining open and regular communication with all stakeholders, including customers and third-party suppliers, regarding security status, risks, and requirements.
-
Knowledge Sharing: Encouraging a culture of knowledge sharing within the cybersecurity team and across project teams to disseminate best practices and lessons learned.
-
Constructive Feedback: Providing and receiving constructive feedback to drive continuous improvement in security processes and system designs.
📝 Enhancement Note: Alstom likely fosters a culture that values integrity, a strong security-first mindset, and collaborative problem-solving, essential for a company operating in safety-critical industries. The emphasis on functional animation suggests a leadership style that empowers and guides technical teams towards achieving strategic security goals.
⚡ Challenges & Growth Opportunities
Challenges:
-
IT/OT Convergence Complexity: Managing cybersecurity risks at the intersection of traditional IT systems and Operational Technology (OT) in industrial environments, which have different security requirements and attack vectors.
-
Regulatory Landscape: Navigating and ensuring compliance with a complex and evolving landscape of international and local cybersecurity regulations specific to the transportation sector.
-
Third-Party Risk Management: Effectively assessing and mitigating security risks introduced by a diverse range of suppliers and partners involved in project delivery.
-
Resource Constraints: Balancing project timelines, budgets (QCD), and scope with the need for robust cybersecurity measures, potentially requiring innovative solutions and prioritization.
-
Talent Acquisition & Retention: Attracting and retaining highly skilled cybersecurity professionals in a competitive market, especially those with specialized IT/OT and transportation security expertise.
Learning & Development Opportunities:
-
Specialized Training: Access to advanced training programs and certifications in areas like industrial control system (ICS) security, embedded systems security, and specific regulatory compliance frameworks.
-
Industry Conferences: Opportunities to attend leading cybersecurity conferences (e.g., Black Hat, RSA Conference, SANS ICS Summit) to stay abreast of emerging threats and technologies.
-
Mentorship Programs: Participation in mentorship programs, both as a mentor to junior engineers and as a mentee to senior cybersecurity leaders within Alstom or the broader industry.
-
Cross-Functional Exposure: Gaining broader experience by working on diverse projects across different Alstom business units or product lines, enhancing understanding of various operational environments.
📝 Enhancement Note: The role presents significant challenges related to the unique demands of industrial cybersecurity within the transportation sector. However, these challenges are matched by substantial growth opportunities, particularly in developing specialized expertise and advancing into leadership roles within a global organization.
💡 Interview Preparation
Strategy Questions:
-
"Describe your approach to defining cybersecurity requirements for a new high-speed train signaling system, considering both IT and OT aspects, and how you would ensure compliance with IEC 62443 and local regulations." (Focus on process, standards, and risk-based approach)
-
"How would you manage a situation where a critical cybersecurity vulnerability is discovered in a component supplied by a third party, and the project is nearing its delivery deadline? What steps would you take to mitigate risk while managing QCD?" (Focus on problem-solving, stakeholder management, and QCD)
-
"Walk me through your methodology for conducting a cybersecurity risk assessment for a railway infrastructure project. What tools and techniques would you employ, and how would you prioritize identified risks?" (Focus on technical depth and practical application) Company & Culture Questions:
-
"What do you understand about Alstom's commitment to cybersecurity in the transportation industry, and how does that align with your professional values?" (Focus on research and cultural fit)
-
"How would you foster a strong cybersecurity culture within a project team that may not have deep security expertise?" (Focus on leadership and communication)
-
"Describe a time you had to influence stakeholders to adopt a security measure they initially resisted. What was your approach, and what was the outcome?" (Focus on influencing skills and collaboration) Portfolio Presentation Strategy:
-
Structure Your Narrative: For each case study, clearly outline the problem, your proposed solution, the execution process, and the quantifiable results. Use a consistent structure for all examples.
-
Visualize Your Work: Incorporate diagrams of security architectures, process flows, risk matrices, and dashboards to visually represent your contributions and the impact of your work.
-
Highlight QCD Management: Explicitly detail how you managed Quality, Cost, and Delay for your cybersecurity deliverables, providing concrete examples of trade-offs or efficiencies achieved.
-
Demonstrate Technical Acumen: Be prepared to dive deep into the technical aspects of your projects, explaining your choices of security technologies, standards, and methodologies.
-
Practice Your Delivery: Rehearse your presentation to ensure a smooth, confident, and concise delivery within the allotted time. Be ready to answer follow-up questions.
📝 Enhancement Note: Interview preparation should focus on demonstrating a strong understanding of industrial cybersecurity, project management skills (especially QCD), and leadership potential. Candidates need to articulate their experience using specific examples and be prepared to discuss their portfolio in detail, linking their past achievements to Alstom's current needs and challenges.
📌 Application Steps
To apply for this operations position:
-
Submit your application through the Alstom job portal using the provided link.
-
Customize Your Resume: Tailor your resume to highlight keywords and responsibilities mentioned in this job description, such as "Cybersecurity," "IT/OT Security," "Risk Analysis," "Project Management," "IEC 62443," "CISSP," and "QCD Management." Quantify your achievements with metrics where possible.
-
Prepare Your Portfolio: Compile a comprehensive portfolio that showcases your experience in cybersecurity project management, risk assessment, architecture design, and compliance. Include specific case studies, process documentation, and examples of QCD management for security deliverables.
-
Research Alstom: Thoroughly research Alstom's company profile, its products and services (especially in rail), its commitment to innovation and sustainability, and its approach to cybersecurity. Understand their position in the market and potential project types.
-
Practice Interview Responses: Prepare detailed answers to potential interview questions, focusing on scenario-based problems, technical challenges, and leadership scenarios relevant to the Cyber Design Manager role. Practice presenting your portfolio confidently.
⚠️ Important Notice: This enhanced job description includes AI-generated insights and operations industry-standard assumptions. All details should be verified directly with the hiring organization before making application decisions.
Application Requirements
Candidates must be Israeli citizens with at least seven years of experience in information security management for national and international projects. A relevant engineering degree and professional certifications such as CISO, CISSP, or CISM are mandatory, along with fluency in English and Hebrew.