Rail Cyber Security Lead

Fox-IT

Fox-IT

Posted on May 29, 2026
We are seeking a highly skilled Cyber Security Rail Lead to join our Global Transport practice. This role is pivotal in strengthening and expanding our cyber security capability within the global rail ecosystem, while also supporting cross-domain engagements in maritime, automotive, and aviation as needed.

The ideal candidate will bring deep knowledge of operational technology (OT), rail systems, relevant international cyber security standards (including IEC 62443, TS 50701, IEC 63452), penetration testing methodologies, and the broader transport ecosystem. In addition to technical leadership, the individual will play a key role in supporting business development, building client trust, and elevating NCC Group’s profile within the rail sector.

This is a client-facing role requiring strong collaboration, communication and leadership skills.

Application Deadline
May 31, 2026
Department
Cyber Services and Capabilities
Employment Type
Full Time
Location
GBR London
Workplace type
Hybrid
Reporting To
Gary Cannon

Key Responsibilities

1. Technical Leadership (Rail Cyber Security)
  • Serve as the subject matter expert (SME) for rail cyber security across global engagements.
  • Lead, design, and deliver complex cyber security assessments across both operational technology (OT) and information technology (IT) environments.
  • Apply deep knowledge of rail-specific standards and frameworks, including:
    • IEC 62443 (Industrial Cyber Security)
    • TS 50701 (Railway Cyber Security)
    • IEC 63452 (Railway Rolling Stock Cyber Security)
  • Conduct or oversee penetration testing activities, vulnerability assessments, architecture reviews, risk assessment and threat modelling for rail clients.
  • Provide expert interpretation of cyber security requirements for railway operators, manufacturers, and integrators.
  • Ensure security recommendations are aligned with safety, operational continuity, and regulatory requirements across the rail ecosystem.

2. Rail Domain Expertise
  • Provide expert understanding of the rail ecosystem, including:
    • Signalling systems
    • Rolling stock
    • Control centres
    • Wayside and trackside equipment
    • Rail operational processes and safety requirements
  • Translate complex rail operations knowledge into training and mentorship for internal teams.
  • Act as the internal thought leader on emerging rail threats, vulnerabilities, and industry trends.


3. Business Development & Practice Growth
  • Support the creation and growth of new rail opportunities globally.
  • Build NCC Group’s market presence in the rail sector through:
    • Thought leadership (whitepapers, webinars, industry events)
    • Client engagements and pre-sales support
    • Partnerships with key rail OEMs, operators, and regulators
  • Collaborate with engagement managers and leadership to define rail-focused service offerings.
  • Contribute to bids, proposals, and technical scoping activities for prospective customers.


4. Cross-Domain Support (Multi-Modal Transport)
  • Potentially support projects across maritime, automotive, and aviation domains as required, with team backing.
  • Maintain awareness of common OT and safety-critical technologies across transport sectors.
  • Promote knowledge-sharing across the wider Transport Cyber Security practice.


5. Teamwork, Collaboration & Mentorship
  • Provide mentoring, guidance, and technical leadership to consultants at various levels.
  • Work closely with colleagues across global teams to deliver integrated and high-quality engagements.
  • Promote a collaborative, supportive, and inclusive team culture.


6. Client Engagement & Delivery Excellence
  • Act as a trusted advisor to clients, providing clear, actionable cyber security recommendations.
  • Communicate complex concepts in a clear, professional, and client-friendly manner.
  • Ensure high-quality deliverables and maintain strong client satisfaction throughout engagements.

Skills, Knowledge and Expertise

Technical Experience
  • Proven experience in rail cyber security, ideally within operators, OEMs, integrators, or a cyber consultancy.
  • Strong experience working with and applying:
    • IEC 62443 (critical infrastructure cyber security)
    • TS 50701 (railway cyber security framework)
    • IEC 63452 (rolling stock cyber security)
  • Strong understanding of OT systems and technologies, including SCADA, industrial control systems (ICS), and safety-critical environments.
  • Practical experience in penetration testing or security assessment methodologies (not necessarily a full-time tester, but capable).
  • Experience with secure architecture review, threat modelling, and risk assessment in industrial or transport environments.

Domain Knowledge
  • In-depth understanding of the rail operational ecosystem, including signalling, rolling stock, safety systems, and regulatory standards.
  • Direct experience working within or for rail operators, system suppliers, or rail-integrated cyber projects.

Soft Skills & Professional Attributes
  • Excellent communication skills in both technical and non-technical contexts.
  • Strong client-facing experience and relationship management skills.
  • Ability to lead engagements and influence stakeholders at all levels.
  • Willingness to work collaboratively across geographies and disciplines.
  • Ability to teach and mentor others on rail systems and cyber security.


Desirable (Not Mandatory)
  • Recognised cyber certifications (e.g., CISSP, GICSP, ISA/IEC 62443 CyberSecurity Expert).
  • Experience contributing to industry standards or regulatory consultations.
  • Background in safety engineering or systems engineering in transport.

Benefits

  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave differs for SOC shift workers, please speak to your TA partner for more information).
  • Medicash & Critical Illness Scheme
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
  • Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.

About NCC Group

We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.

With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.

We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.

Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
We review every application received and will get in touch if your skills and experience match what we’re looking for. If you don’t hear back from us within 10 days, please don’t be too disappointed – we may keep your CV on our database for any future vacancies and we would encourage you to keep an eye on our career opportunities as there may be other suitable roles.

If you do not want us to retain your details, you can utilise the Manage Your Data tool provided by Pinpoint or contact us directly at: global.ta@nccgroup.com. All personal data is held in accordance with the NCC Group Privacy Notice.

We are committed to diversity and flexibility in the workplace. If you require any reasonable adjustments to support you during the application process, please tell us at any stage.

Please note that this role involves mandatory pre-employment background checks due to the nature of the work NCC Group does. To apply, you must be willing and able to undergo the vetting process.

Not quite right? Register your interest to be notified of any roles that come along that meet your criteria.

Register Your Interest