Security Engineer
Hitachi
Location:Naples, Campania, ItalyJob ID: R0017214Date Posted:2023-06-08Company Name:HITACHI RAIL STS S.P.A.Profession (Job Category):OtherJob Schedule: Full timeRemote:NoJob Description:Hitachi Rail is looking for an enthusiastic self-motivated Security Engineer who thrives in a fast-paced environment. The successful candidate is comfortable performing a wide range of tasks from administrative to strategic. The position is based in Naples, Italy.Who We AreHitachi Rail is a fully integrated, global provider of rail solutions across rolling stock, signaling, service & maintenance, digital technology and turnkey. With a presence in 38 countries across three continents and over 13,000 employees, our mission is to contribute to society through the continuous development of superior rail transport solutions.MissionAssure the design and implementation of the Cybersecurity System in order to achieve the requirements in terms of compliance, schedule, quality and cost imposed by the different contracts either for the Tender and Projects.AccountabilitiesEnsure the identification, the management and the fulfillment of the contractual requirements and customer requestsAnalyze customer supplied system specifications, decomposing the statements within such specifications into software requirementsIdentify gaps between customer requirements and Hitachi standard software products or COTS productsDeveloping close working relationship with customer Cybersecurity representativesCreate requirement documents, including high level design documents, interface control design documents and detailed software requirements and specifications, and requirements traceability documents.Be the primary technical interface to the customer throughout the life cycle of the project and act as technical liaison relative to the software development effort with other departments within the company working on the same project.Contribute to the identification and resolution of the interfaces with the main subsystems (e.g. Signaling, TLC, DCS, SCADA, etc.) and security systems (e.g. SIEM)Interface with internal customers (project managers, construction managers, project engineers, and application engineers) and external stakeholders (customers, suppliers, subcontractors, local authorities, external assessor) to ensure consistent communication and system integration.Develop and execute security management plan and commissioning plan, including resourcing, logistics, and scheduling. Onsite lead for commissioning and acceptance testing.Coordinate work sequences, schedules, resources and punch list items.Collaborate with stakeholders to define and execute testing protocols to achieve commercial operation, based on contractual requirements.Oversee commissioning and acceptance testing of the entire plant in a safe manner, including controls and communication networks, power supplies, auxiliary systems like fire detection, ventilation, HMI.Provide local/remote technical support troubleshooting during commissioning, and operation as needed.Develop customer training and handoff material to internal and external O&M teams. Develop a train-the-trainer program to enable successful handoffs for safe operation of the plant.Create professional commissioning and testing reports for internal stakeholders and external customers.Drive continuous improvement on developing and capturing technical problem solving knowledge to enable other organizations to effectively resolve customer problems and inquiries.Ownership of administrative responsibilities including, but not limited to: service reports, issue logging/tracking, job safety analysis, quality compliance.Guarantee the preparation and approval of the Design:Conceptual DesignCyber Security Management PlanHigh Level Risk Assessment based on the methodologies described in the standards (NIST 800-53, IEC 62443 and ISO 27000)Detail Risk Assessment (DRA) and Threat and Vulnerability Risk Assessment (TVA)Security Case (in according to IEC 62443-4-1 and EN 50129:2018)for the security assurance and security procedures (for incident management, patch and vulnerability management, asset and configuration management, etc.)Security Report (include the VA and PT test results)Undertake Cybersecurity activities as defined in the design documentation, e.g. vulnerability assessmentGuarantee the continuous security monitoring of the System in accordance to the technology innovationSecurity Audits during the Project with the CustomerCompetenciesThe Cybersecurity engineer shall be able to:Act keeping in mind the impacts of his/her own work on the whole “Company system” and understanding the economic consequences of his/her activities both on client and organizational perspectives. Propose simple and efficient solutions to meet customer needs.Commit to understanding and delivering against customer requirements, keeping them informed about progress on a specific activity/project. Actively seek information to understand customer circumstances, problems, expectations and needs.Provide contributions in defining personal stretching goals. Focus on new or more effective ways of improving his/her own work and meeting targets. Commit to exceed expectations.Set stretching and realistic targets for him/herself and his/her team, improving performance and benchmarks against industry standards and competition. Recognize and celebrate the achievement of milestones and goals.Understand areas of improvement and define a personal development plan to follow whose progress is regularly checked. Welcome new assignments for personal development.Understand markets and industrial trends and their changes and how they may impact the Company/the Group. Keep him/herself updated on products, services, markets and clients in order to plan activities.Adapt to different cultures and international environments establishing relationships that create business benefit.Accommodate for cultural differences to improve effectiveness and adapt leadership style depending on the situation (adherence to the team’s expectations).Compare him/herself and his/her team against the international best practices. Encourage the contribution of different people with different experiences and backgrounds in order to optimize outcomes. Pursue opportunities to learn about other cultures using an open-minded approach.Seek opportunities to expand and leverage knowledge across organizational boundaries. Draw upon multiple and diverse sources for ideas and inspiration. Examine and evaluate potential solutions before accepting any.Review performance and learn from mistakes. Be aware of technological/organizational developments that could provide innovative solutions to improve performance and add value. Target important innovation areas and develop solutions addressing meaningful work issues.Follow up the supplier of the cybersecurity technologies. Review the technical documentation produced by the supplier before the submittal to the Customer.Analyze the comments and requests received by the Customer on the Design and the Commissioning phases.Participate to the Factory and Site acceptance tests with the Customer.Required Skills & KnowledgeTelecommunications System Architectures and SolutionsISO 27001 and 27005EN 50159NIST 800-53 and 800-82IEC 62443 familyBackbone Transmission Systems and ElementsIP Networking - Wired & WirelessSystem Integration knowledgeSIEM technology experienceFirewall Configuration and Management KnowledgeActive Directory and Radius Configuration Management (802.1x)Nessus Tool Professional experience for Vulnerability and Penetration TestsSCADA security and knowledge of the main SCADA architectures and communication protocolsCisco Certificate CCNA, CCNA Security or CCNP is preferable title.Experience of undertaking or managing vulnerability assessments and penetration testing activitiesExperience of Patch Management and Configuration ManagementDesired Skills & KnowledgeWireless Communication SystemsTrunked Mobile Radio SystemsPublic Carrier Systems and ServicesWiring Rules, cables, Codes and RegulationsNetwork Management SystemsKnowledge of the main organizational processes:Bidding & costs estimationFacilitation of Customer meetings and workshopsProject Plans & ProceduresProject progress and reportingInterface Plans and DefinitionsTechnical Documentation Development and WritingFactory Construction ProcessesSystem Integration & FAT ProcessesEquipment Installation ProcessesTest & Commissioning ProcessesQuality assuranceChange management processEducation & ExperienceAs minimum Bachelor’s , preferred master Degree in Telecom Engineering Degree or in descending order Computer/Information Science, Electronic EngineeringFrom 3 to 5 years of Cybersecurity System Engineering expertise.Cybersecurity qualifications or certification is preferredRailway experience is preferred but also experiences in other telecom sectors can be considered (e.g. Oil&Gas, power energy companies, telecom operators, etc.).LanguagesFluent in English.We thank all applicants for their interest; however, only those under consideration will be contacted. Join us at .It is our commitment at Hitachi Rail to create a diverse environment and we are proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.We would be delighted if you would be one of our followers!Have a glance at our LinkedIn page#LI-MP94SummaryLocation: Naples, Campania, Italy; Genoa, Ligura, ItalyType: Full time
- ...Ambiente collaborativo e innovativo Policy AGILE per work-life integration Responsabilità Architettura e design di Network Security basate su principi moderni, con focus su visibilità, controllo e Zero Trust Progettazione e valutazione di soluzioni SASE/SSE (...ConsigliatoOrario flessibile
30.000 € - 36.000 €
...RINA is currently recruiting for a Junior Cyber Security Engineer to join its office in GENOA OR ROME, within the Operating Engine Division. Mission Junior personnel could have less than 5 years of experience in the field, but a technical academic background...ConsigliatoImpiego permanenteOrario flessibile35.000 € - 45.000 €
...IT Security Engineer Per azienda operante nel settore del trasporto marittimo, siamo alla ricerca di un/una IT Security Engineer da inserire all'interno del team Cyber Security. Responsabilità principali Implementare e monitorare controlli di sicurezza per garantire...Consigliato- 7Layers S.r.l. è un'azienda dinamica e in forte crescita, operante nel settore Cyber Security. Siamo alla ricerca di un Senior Network Security Engineer che voglia unirsi al nostro team per contribuire a progetti innovativi e strategici, in un ambiente di lavoro altamente...ConsigliatoRemoto
- p7Layers S.r.l. cerca un Senior Network Security Engineer per rafforzare un team altamente specializzato nel cybersecurity, in Genova. /ppIl ruolo è cruciale per garantire la sicurezza e l'efficienza delle infrastrutture di rete. Giocherai un ruolo chiave nella gestione...Consigliato
- ...ensuring compliance with contracts and standards. You'll collaborate with customers and internal teams to translate requirements into secure, verifiable solutions across subsystems. You'll drive security planning, testing, and commissioning to enable safe operation of...
- pIn strongCapgemini Engineering /strong, leader mondiale nei servizi di ingegneria, uniamo un team globale di talenti dell’ingegneria, scienza... ...documenti di analisi TARA, report di penetration testing e security assessment. /liliSupporto alla pianificazione delle attività...RemotoOrario flessibile
- ...RINA is seeking a Junior Cyber Security Engineer to join its Genoa or Rome office within the Operating Engine Division. The role requires a technical background with up to 5 years of experience and a Bachelor’s degree in Information Systems or Cyber Security. You will...
- Overview In questa posizione lavori all'interno della divisione ENG DIGITAL per proteggere le risorse digitali aziendali. Ti inserisci in un team SOC per analizzare e rispondere a incidenti di sicurezza, coordinandoti con il livello I e con i clienti. Potrai guidare...Smart working
- ...Overview In this role you will perform security testing across networks, mobile and web applications, and embedded/IoT products to identify vulnerabilities and simulate attacks. You will join Spike Reply's Cyber Security Team, serving national and international clients...Orario flessibile
- Overview In this role, you will implement physical design for Optical Network ASICs across cutting-edge nodes, focusing on power, performance, and area. You will work within a hardware/RTL team to translate designs into silicon and optimize flows for submicron processes...Lavoro ibridoOrario flessibile
- pLeonardo Worldwide Corporation cerca un Ingegnere Networking e Comunicazione per le sedi di Genova, Roma e Napoli. La posizione richiede competenze nella progettazione e implementazione di sistemi di rete e sicurezza in ambienti Cloud. /ppIl candidato ideale deve avere...Impiego permanente
- ...flows. Collaborate with ASIC synthesis, implementation and physical design teams for handoff and optimization. Mentor junior engineers and contribute to team knowledge sharing. Collaborate with systems, hardware, software and firmware teams across Nokia...Lavoro ibridoOrario flessibile
- ...Role: Cyber Security Analyst (Remote) Location: Remote (Work from Anywhere) Role Overview: We are hiring for one of our clients, seeking a Cyber Security Analyst to work on a Full-time basis. The role involves monitoring and analyzing security events to protect...Tempo pienoRemoto
- ...strongè alla ricerca di un/una: /ppbr / /ppbr / /ppstrongCyber Security Analyst /strong /ppbr / /ppbr / /ppIl/la candidat* ideale ha conseguito... .../ppstrongIl/la candidat* ideale deve conoscere le pratiche di Secure Coding, la gestione delle vulnerabilità e i framework di...Tempo pienoImpiego permanenteOrario flessibile
- ...intelligence work to protect OT/IoT environments. You'll work within the Security Research team to understand malicious behavior, craft... ...record of presenting at conferences Experience reverse engineering with IDA Pro, Ghidra, OllyDBG, x64dbg, radare2, or similar...Orario flessibile
- ...Leonardo Worldwide Corporation cerca un/a Infrastructure Engineer per le sedi di Roma, Genova e Napoli. La figura si occuperà della progettazione e ottimizzazione di sistemi on-premise, garantendo sicurezza e prestazioni. Richiesta laurea in ingegneria o discipline...Impiego permanenteLavoro ibrido
- ...Logistics , Naval and Infrastructure è alla ricerca di un/una: Cyber Security Analyst Il/la candidat* ideale ha conseguito una laurea in... ...Il/la candidat* ideale deve conoscere le pratiche di Secure Coding, la gestione delle vulnerabilità e i framework di sicurezza...Tempo pienoImpiego permanenteOrario flessibile
- ...Laurea STEM, ITS in ambito ICT o percorso equivalente Certificazioni in ambito cybersecurity, governance, risk management, cloud security o security architecture. Esperienza in contesti aziendali strutturati Familiarità con framework e standard di sicurezza...Impiego permanente
- ...liLaurea STEM, ITS in ambito ICT o percorso equivalente /li liCertificazioni in ambito cybersecurity, governance, risk management, cloud security o security architecture. /li liEsperienza in contesti aziendali strutturati /li liFamiliarità con framework e standard di...Impiego permanente
- ...progettare, sviluppare e portare in produzione soluzioni di Cyber Security per clienti leader di mercato. Lavorerai a stretto contatto... ..., includendo l'adozione sicura di AI. Userai strumenti di AI Engineering per costruire sistemi di detection, framework di security assessment...
- ...Supportare definizione e monitoraggio di piani strategici per l'applicazione dei requisiti ICT e Cybersecurity Progettare e utilizzare security dashboard con KPI/KRI per governance e monitoraggio della compliance Requisiti fondamentali Esperienza di almeno 3 anni in...Part-timeRemotoOrario flessibile
- Un'azienda sanitaria innovativa in Liguria cerca un professionista per gestire il programma di sicurezza informatica. Questa figura sarà responsabile della protezione delle informazioni e dell'infrastruttura aziendale, assicurando conformità e gestione del rischio. Il candidato...
- ...In Capgemini Engineering , leader mondiale nei servizi di ingegneria, uniamo un team globale di talenti dell’ingegneria, scienza e architettura... ...documenti di analisi TARA, report di penetration testing e security assessment. Supporto alla pianificazione delle attività di...Impiego permanenteRemotoOrario flessibile
- ...Requisiti fondamentali Esperienza lavorativa come Cloud Security Architect Esperienza con AWS, Azure o GCP Conoscenza dei... ...certificazione tra: Azure Administrator Associate, Azure Security Engineer Associate, AWS Solutions Architect Associate, AWS Security Specialty...
- ppIn bCapgemini Engineering /b, leader mondiale nei servizi di ingegneria, uniamo un team globale di talenti dell’ingegneria, scienza e... ...inclusi documenti di analisi TARA, report di penetration testing e security assessment. /li liSupporto alla pianificazione delle attività...Impiego permanenteRemotoOrario flessibile
50.000 € - 80.000 €
...Stiamo cercando un/una DevSecOps Engineer AI-focused Cosa cerchiamo Siamo una startup italiana innovativa in forte crescita e siamo... ..., secret management e policy enforcement Garantire il security hardening di infrastrutture cloud, container e ambienti di orchestrazione...- Next srl - Genova, azienda informatica con esperienza ultraventennale, cerca un venditore per espandere l’area commerciale a Genova. Gestirai l’intero processo di vendita: dal primo contatto alla chiusura, illustrando prodotti e servizi, proponendo soluzioni su misura...
- ...liRedazione di piani di compliance e definizione degli elementi per implementazione (cronoprogrammi) /li liProgettazione e utilizzo di security dashboard con KPI/KRI per la governance della compliance /li liDefinizione e monitoraggio dei KPI di cybersecurity /li /ul...Remoto
- .../HF) in Informatik oder Telekommunikation mit mindestens drei Jahren Berufspraxis im Bereich Netzwerk Services Engineering oder Networkautomation und Security /li liDiplomatisches Gespür, damit Entscheide, die von verschiedenen Instanzen getroffen werden müssen, auch von...Remoto