Confidential mandate
Rail Signalling Cyber-Safety Adviser — Passenger Mobility
Planned Hiring / New
Rail Signalling Cyber-Safety Adviser mandate in Warsaw, Poland · Passenger Rail
A Warsaw passenger-rail board seeks independent counsel to connect signalling cyber threats, degraded operation and safety assurance before approving a consequential network-modernisation programme over ten months.
The mandate
The board must decide whether a signalling-modernisation plan adequately separates safety integrity from cyber trust when interlockings, radio control, traffic management and maintenance laptops exchange data across supplier boundaries. Existing assurance considers random equipment failure and enterprise intrusion separately. The standing question is which adversarial conditions could create unsafe movement authority, loss of supervision or prolonged network restriction despite nominally safe component behaviour.
The adviser commits four days monthly, works remotely and attends quarterly two-day Warsaw sessions plus the scheduled Kraków control-centre and Berlin supplier reviews. One monthly challenge examines a safety case, architecture exception or degraded-mode exercise with accountable engineers. A serious signalling concern receives acknowledgement within six hours and a reasoned board view within twenty-four, without entering operational command.
The term runs ten months and may renew once for three months following a minuted review after the final network exercise. Renewal requires an unresolved board-level cyber-safety question, evidence of influence and reconfirmed supplier independence. Delayed procurement, certification or engineering delivery does not justify retaining a standing adviser beyond the agreed term.
The adviser has no line authority, train-control role, safety certification, architecture approval or executive responsibility. Dispatchers and infrastructure managers retain operational decisions; designated safety authorities accept risk, while the board approves capital and appetite. The adviser may recommend a restriction or additional test but cannot issue movement authority, change signalling data or direct incident response.
Conflicts include signalling suppliers, rolling-stock manufacturers, telecom operators, safety assessors, cybersecurity vendors and competing rail boards. All client roles, investments, referral economics and standards positions require disclosure before appointment. Any new work involving a shortlisted supplier or assessor requires written chair clearance while confidential topology and hazard information remains accessible.
Why the board wants this voice
Safety specialists understand fail-safe design while cybersecurity teams model malicious control, yet neither consistently challenges the combined case for directors. Supplier documentation also fragments responsibility at interfaces. Independent counsel can press for system-level evidence without displacing statutory safety and operating authority.
What you will own
- Challenge trust boundaries across interlocking, radio block control, traffic management, axle counting, maintenance access and operational telecommunications.
- Test whether cyber threat scenarios map to credible hazardous effects, safe states, detection paths and accountable operational responses.
- Press suppliers on secure configuration, diagnostic access, software provenance, vulnerability disclosure and long-life support obligations.
- Review degraded operations for throughput, dispatcher workload, communication loss, route protection and restoration under sustained attack.
- Shape board investment priorities around systemic safety exposure, supplier concentration, testability and recoverability rather than vulnerability totals.
- Observe exercises involving false occupancy, corrupted timetable data, unavailable control centre and compromised maintenance credentials.
- Equip the committee with cyber-safety assumptions, open evidence, authority boundaries and decisions required before modernisation gates.
Candidate qualifications
- Advised or led cybersecurity assurance for railway signalling, train control or comparably safety-critical transport infrastructure.
- Can evidence integration of malicious threat conditions into a formal hazard, safety-case or independent-assurance process.
- Challenged signalling and telecom suppliers on privileged maintenance, software provenance, vulnerability handling and configuration evidence.
- Evaluated degraded railway operation through dispatcher workload, route protection, capacity and recovery rather than technical availability alone.
- Counselled boards while preserving clear boundaries among operations, safety acceptance, cybersecurity assurance and supplier certification.
- Designed or observed rail cyber exercises whose findings materially changed architecture, operating rules or capital sequencing.
Non-negotiables
- Can fulfil remote response and every Warsaw, Kraków and Berlin assurance session.
- Will disclose supplier, assessor, operator, vendor and standards conflicts before accessing restricted rail information.
- Accepts no train-control, safety-certification, risk-acceptance or operational incident authority.
- Has board-level cyber-safety judgment grounded in signalling or another live safety-critical control system.
- 49 words maximum. Which current supplier or assessor relationship could conflict with this signalling review?
- 49 words maximum. Describe a malicious condition that changed a rail safety or degraded-operation case.
- 49 words maximum. What evidence would make you reject a supplier's secure-maintenance assurance?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.