Pour les employeurs
Information Security Lead Expert


AXA Group
il y a 4 jours
Date de publication
il y a 4 jours
S/O
Niveau d'expérience
S/O
Temps pleinType de contrat
Temps plein
Description

About AXA

As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you'll feel like you belong, are included and can thrive. You'll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.

About AXA Group Operations

AXA is becoming a sustainable tech-led company, and at AXA Group Operations (GO), we are one of the major catalysts for this transformation.

We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.

We are present across 13 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.

At AXA GO, we want to be recognized in three fields of action:

• State-of-the-art Data Technology to drive customer experience.

• State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks.

• High-Performing Global Team for stronger partnerships with AXA entities.

Job position pitch

The Information Security Lead Expert leads the development and implementation of the end-to-end strategic approach to Information Security.

Where will you be in the organization?

The division (Group Security)

You will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).

Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand, and people. To achieve this, we have gathered our three security disciplines: Information Security, Operational Resilience and Physical Security.

Our main missions:

• Monitor the Security Threat Landscape.

• Define and oversee Security Standards and Strategy implementation across the Group.

• Drive local security objectives with C-Level executive (COO, CIO, CTO, CFO...) of AXA entities.

• Ensure the security of AXA GO as an entity, and of AXA GO as a Service Provider.

• Provide centralized security services and products to AXA entities.

Group Security division is divided in 4 main blocks:

• Corporate functions (Group Mandate): Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and Awarene

• Cyber Defense (Group Security services and products provider)

• GO Security (Security of AXA GO as an entity, and of AXA GO as a Service Provider)

• Corporate Chief Security Officers (Oversight of entities' security): Corporate Centre, European Markets, International Market

The department (GO Security)

GO Security department mandate, as part of Group Security division, is to secure AXA GO as an entity, and secure AXA GO Products delivered by AXA GO as a Service Provider to other entities of AXA.

GO Security department is divided in 5 teams:

• GO Security Oversight

• GO Security Engineering CoE

• GO Security Technical Design & Technical Assurance

• GO Product Security Office

• GO Security Operational Excellence

The team (GO Security Oversight)

GO Security Oversight team is responsible of

o Protecting the organization's information, technology & physical assets from external and internal threats, such as cyberattacks, data breaches, and malicious insiders.

o Developing and implementing GO Security security policies, aligned with the Group Security instructions and regulatory requirements.

o Managing risks related to AXA GO as an entity, with support from Security Engineering CoE team, and report relevant risks in AXA GO Security Risk Committees.

o Overseeing the planification and execution of the yearly security testing campaign across AXA GO

o Developing and implementing security awareness and training programs to ensure AXA GO employees understand their roles and responsibilities in maintaining a secure environment.

o Ensuring compliance with Group Security instructions and regulatory requirements, supervising primary assurance on AXA GO as an entity, supporting Primary Assurance activities for AXA GO as a Service Provider, and reporting to Group Security with adequate level of data accuracy.

o Developing and maintaining business continuity policies, Business Continuity plans and exercises to ensure AXA GO can respond effectively to incidents and maintain business operations in the event of a disaster.

o Overseeing physical security of AXA GO sites (offices, data centers) and people (travels, events).

o Prioritizing/managing the remediation of audit issues owned by GO Security Oversight.

About the job

Main missions

Reporting to GO Security Oversight Executive Manager, the Information Security Lead Expert leads the development and implementation of the end-to-end strategic approach to Information Security.

Your responsibilities include:

  • Support the GO Security Oversight Executive Manager in achieving GO Security Oversight team's objectives.

Manage the delivery/update of GO Security Policies:

    • Plan the yearly development / update of GO Security Policies, in alignment with Group Security Instructions, Security risks assessments (entity, product) and feedbacks issued from internal and interested parties. GO Security Policies will comply with global laws/regulations and industry best practices, while balancing the requirements of an agile workforce and a secure environment.
    • Lead and coordinate different teams to write/update Security policies, with the aim of getting validated Security Policies delivered by GO.
    • Organize and facilitate information security policy stakeholder meetings to align policy and control objectives to the organization, in synchronization with synchronized with Information Security control framework.
    • Communicate new/updated policies and spread general awareness about policy set among employees.
    • Plan, coordinate, and execute security policies presentations to main operational teams.
    • Gather and maintain artifacts to prepare for audits.

Manage the Security awareness inside GO

o Ensure that GO Security awareness strategy is aligned with Group Security Awareness Strategy

o Deliver an annual awareness strategy plan for AXA GO

o Execute and communicate continuously all related actions defined in the GO awareness strategy plan to all AXA GO employees as GO Security Policies, GO newsletters, news in ONE, videos, webinars, eLearning modules in YES LEARNING or LinkedIn, security events like Security Month in October, Phishing awareness, ...

o Monitor continuously any awareness actions that can be tracked.

Manage the Internal Security requests:

o Answer requests within the GO Security mailbox

o Handle DLP alerts/incidents from GO employee

Manage the GO Security / Security Desk

o Execute first criticality assessment of new assets in the GO project management process with involvement of Information Security / Physical Security / Operational Resilience / Security Architecture / Data Privacy / Operational Risk teams,

o Deliver evidences collection for primary assurance purpose (entities requests)

Manage GO as an entity security risks

o Manage security risks related to AXA GO as an entity, with support from GO Security Engineering Center team, and report relevant risks in AXA GO Security & Information Risk Committee.

o Update AXA GO Most Valuable Data list on a yearly basi

Oversight of the CyberDefense / Pentest execution team

o Ensuring right funding is allocated for continuous pentesting

o Prioritizing assets to be pentested in continuous pentesting (DAST included)

o Monitoring campaign of pentest

o Confirm criticality of vulnerabilities raised during pentesting activity

o Ensuring the remediation of issues detected in pentest

o Reporting to Group Security

o Performing primary assurance on pentesting /remediation

Automate Internet Facing compliance with Group standards

o Ensure Digital Hub completeness & information accuracy by

§ Regularly review declared assets to check if they are still live & information provided is accurate

§ Search for undeclared assets

o Monitor AXA GO Bitsight score (all Internet Facing assets), & improve score by monitoring remediation on vulnerabilities detected

  • Manage S1/S2 Security Incidents & Critical/High/Medium Security Threats
    • Measuring impact on AXA GO
    • Coordinating with IT & Security teams remediation/mitigation if impact confirmed
    • Communicating towards entities on AXA GO remediation/mitigation plan progresses
    • On Medium Security Threats, measuring impact on AXA GO depending on volumes impacted
  • Contribute to the remediation of audit issues on Information Security perimeter

Qualifications

Expected skills & experience

We are looking for someone with the following experience and skills:

Experience

• University degree in Security Management, Information Security, IT or related field.

• Information Security and/or Information Technology industry certification (ISC2 CISSP, ISACA CISM or equivalent) strongly is necessary

• Experience > 10 years.

• Relevant experience as a team lead (> 5 years)

• Strong experience in Information Systems Security Management

• Strong experience in project management and multi-team coordination.

Technical skills

• Proficiency in information security technologies, including intrusion detection systems.

• Experience in managing security incident

• Familiarity with audit tools and the ability to examine technical evidence in depth.

Soft skills / transversal skills

• Ability to effectively operate in a decentralized and political corporate environment.

• Ability to function effectively in a matrix structure

• Strong communication skills to collaborate and interact with various stakeholder

• Excellent time management skills (tight deadlines).

• Ability to prioritize activities and to manage action plans, review progress and adjust where required.

• Good analytical skills and the ability to clearly identify key issues.

• Ability to recommend solutions relevant to the complexity, scope, risk and magnitude of problems impacting the service level.

• Strong program/project management.

• Fluency in English is a necessity

• Fluency in French is an advantage

About AXA

As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working with 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of

respect, for each other, for our customers and the communities around us. Join AXA and you'll feel like you belong, are included and can thrive. You'll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.

AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.

We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.

We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.

At AXA Group Operations, we want to be recognized in three fields of action:

  • State-of-the-art Data Technology to drive customer experience
  • State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
  • High-Performing Global Team for stronger partnerships with AXA entities
Balises associées
-
RÉSUMÉ DE L' OFFRE
Information Security Lead Expert
AXA Group
Paris
il y a 4 jours
S/O
Temps plein

Information Security Lead Expert