At a Glance
- Tasks: Lead cyber security initiatives in the rail sector and support cross-domain projects.
- Company: Join a global leader in transport cyber security with a collaborative culture.
- Benefits: Flexible working, generous holiday allowance, and opportunities for professional growth.
- Other info: Dynamic role with opportunities to mentor and collaborate across global teams.
- Why this job: Make a real impact on rail safety and security while developing your expertise.
- Qualifications: Experience in rail cyber security and strong communication skills required.
The predicted salary is between 70000 - 90000 € per year.
We are seeking a highly skilled Cyber Security Rail Lead to join our Global Transport practice. This role is pivotal in strengthening and expanding our cyber security capability within the global rail ecosystem, while also supporting cross-domain engagements in maritime, automotive, and aviation as needed.
The ideal candidate will bring deep knowledge of operational technology (OT), rail systems, relevant international cyber security standards (including IEC 62443, TS 50701, IEC 63452), penetration testing methodologies, and the broader transport ecosystem. In addition to technical leadership, the individual will play a key role in supporting business development, building client trust, and elevating NCC Group’s profile within the rail sector. This is a client‑facing role requiring strong collaboration, communication and leadership skills.
Key Responsibilities- Technical Leadership (Rail Cyber Security)
- Serve as the subject matter expert (SME) for rail cyber security across global engagements.
- Lead, design, and deliver complex cyber security assessments across both operational technology (OT) and information technology (IT) environments.
- Apply deep knowledge of rail‑specific standards and frameworks, including:
- IEC 62443 (Industrial Cyber Security)
- TS 50701 (Railway Cyber Security)
- IEC 63452 (Railway Rolling Stock Cyber Security)
- Conduct or oversee penetration testing activities, vulnerability assessments, architecture reviews, risk assessment and threat modelling for rail clients.
- Provide expert interpretation of cyber security requirements for railway operators, manufacturers, and integrators.
- Ensure security recommendations are aligned with safety, operational continuity, and regulatory requirements across the rail ecosystem.
- Rail Domain Expertise
- Provide expert understanding of the rail ecosystem, including:
- Signalling systems
- Rolling stock
- Control centres
- Wayside and trackside equipment
- Rail operational processes and safety requirements
- Translate complex rail operations knowledge into training and mentorship for internal teams.
- Act as the internal thought leader on emerging rail threats, vulnerabilities, and industry trends.
- Business Development & Practice Growth
- Support the creation and growth of new rail opportunities globally.
- Build NCC Group’s market presence in the rail sector through:
- Thought leadership (whitepapers, webinars, industry events)
- Client engagements and pre‑sales support
- Partnerships with key rail OEMs, operators, and regulators
- Collaborate with engagement managers and leadership to define rail‑focused service offerings.
- Contribute to bids, proposals, and technical scoping activities for prospective customers.
- Cross‑Domain Support (Multi‑Modal Transport)
- Potentially support projects across maritime, automotive, and aviation domains as required, with team backing.
- Maintain awareness of common OT and safety‑critical technologies across transport sectors.
- Promote knowledge‑sharing across the wider Transport Cyber Security practice.
- Teamwork, Collaboration & Mentorship
- Provide mentoring, guidance, and technical leadership to consultants at various levels.
- Work closely with colleagues across global teams to deliver integrated and high‑quality engagements.
- Promote a collaborative, supportive, and inclusive team culture.
- Client Engagement & Delivery Excellence
- Act as a trusted advisor to clients, providing clear, actionable cyber security recommendations.
- Communicate complex concepts in a clear, professional, and client‑friendly manner.
- Ensure high‑quality deliverables and maintain strong client satisfaction throughout engagements.
- Technical Experience
- Proven experience in rail cyber security, ideally within operators, OEMs, integrators, or a cyber consultancy.
- Strong experience working with and applying:
- IEC 62443 (critical infrastructure cyber security)
- TS 50701 (railway cyber security framework)
- IEC 63452 (rolling stock cyber security)
- Strong understanding of OT systems and technologies, including SCADA, industrial control systems (ICS), and safety‑critical environments.
- Practical experience in penetration testing or security assessment methodologies (not necessarily a full‑time tester, but capable).
- Experience with secure architecture review, threat modelling, and risk assessment in industrial or transport environments.
- Domain Knowledge
- In‑depth understanding of the rail operational ecosystem, including signalling, rolling stock, safety systems, and regulatory standards.
- Direct experience working within or for rail operators, system suppliers, or rail‑integrated cyber projects.
- Soft Skills & Professional Attributes
- Excellent communication skills in both technical and non‑technical contexts.
- Strong client‑facing experience and relationship management skills.
- Ability to lead engagements and influence stakeholders at all levels.
- Willingness to work collaboratively across geographies and disciplines.
- Ability to teach and mentor others on rail systems and cyber security.
- Desirable (Not Mandatory)
- Recognised cyber certifications (e.g., CISSP, GICSP, ISA/IEC 62443 CyberSecurity Expert).
- Experience contributing to industry standards or regulatory consultations.
- Background in safety engineering or systems engineering in transport.
- Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus...
Rail Cyber Security Lead employer: NCC Group
At NCC Group, we pride ourselves on being an exceptional employer, particularly for our Rail Cyber Security Lead role based in London. Our commitment to employee growth is evident through our supportive work culture that fosters collaboration and mentorship, alongside flexible working options and a generous holiday allowance. Join us to be part of a dynamic team that not only values your expertise but also empowers you to make a significant impact in the global rail ecosystem.
StudySmarter Expert Advice🤫
We think this is how you could land Rail Cyber Security Lead
✨Tip Number 1
Network like a pro! Get out there and connect with people in the rail cyber security field. Attend industry events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your expertise! Create a personal blog or LinkedIn posts discussing rail cyber security trends, challenges, or solutions. This not only showcases your knowledge but also helps you stand out to potential employers looking for thought leaders in the field.
✨Tip Number 3
Don’t just apply; engage! When you find a role that excites you, reach out to current employees or hiring managers on LinkedIn. Ask them about their experiences and express your enthusiasm for the position. It’s a great way to make a memorable impression.
✨Tip Number 4
Apply through our website! We’ve got a streamlined application process that makes it easy for you to showcase your skills. Plus, it shows you’re genuinely interested in joining our team. Let’s get you on board!
We think you need these skills to ace Rail Cyber Security Lead
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Rail Cyber Security Lead role. Highlight your experience with operational technology and relevant cyber security standards like IEC 62443 and TS 50701. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about rail cyber security and how you can contribute to our team. Be sure to mention any relevant projects or experiences that showcase your expertise.
Showcase Your Soft Skills:This role requires strong communication and leadership skills, so don’t forget to highlight these in your application. Share examples of how you've successfully collaborated with teams or mentored others in the past. We love a good team player!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you're keen on joining our awesome team at StudySmarter!
How to prepare for a job interview at NCC Group
✨Know Your Standards
Make sure you brush up on the key international cyber security standards relevant to the rail sector, like IEC 62443 and TS 50701. Being able to discuss these frameworks confidently will show that you’re not just familiar with them, but that you can apply them in real-world scenarios.
✨Showcase Your Technical Leadership
Prepare examples of how you've led cyber security assessments or projects in the past. Highlight your experience with operational technology (OT) and information technology (IT) environments, and be ready to explain how you’ve tackled complex challenges in these areas.
✨Demonstrate Client Engagement Skills
Since this role is client-facing, think about how you can convey complex cyber security concepts in a clear and professional manner. Practice explaining technical details in a way that’s accessible to non-technical stakeholders, as this will be crucial for building trust with clients.
✨Be Ready for Cross-Domain Questions
Given the potential for cross-domain support in maritime, automotive, and aviation, prepare to discuss your understanding of these sectors. Show that you’re adaptable and can apply your rail cyber security expertise to other transport domains when needed.