Agile Security Risk Consultant
AXA
il y a 4 heures
Date de publicationil y a 4 heures
S/O
Niveau d'expérienceS/O
Temps pleinType de contrat
Temps pleinSystèmes d'information / RéseauxCatégorie d'emploi
Systèmes d'information / RéseauxAbout AXA
As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you'll feel like you belong, are included and can thrive. You'll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.
About the entity
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:
Where will you be in the organization?
The division
You will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).
Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience.
Our main missions:
AXA Group Security is divided in 4 main blocks :
About the job
Job purpose
The purpose of the role is to:
Main missions
Your missions as an Agile Security Risk Consultant are to :
Expected skills & experience
We are looking for someone with the following experience and skills:
Experience
Overall work experience in the field
Skills
What we offer
We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we're committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.
As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you'll feel like you belong, are included and can thrive. You'll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.
About the entity
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:
- State-of-the-art Data Technology to drive customer experience
- State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
- High-Performing Global Team for stronger partnerships with AXA entities
Where will you be in the organization?
The division
You will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).
Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience.
Our main missions:
- Monitor the Security Threat Landscape
- Define and oversee Security Standards and Strategy implementation across the Group
- Drive local security objectives with C-Level executive (COO, CIO, CTO, CFO...) of AXA entities
- Ensure the security of Group Operations as an entity
- Provide centralized security services and products to AXA entities
AXA Group Security is divided in 4 main blocks :
- Corporate functions (Group Mandate) : Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and Awareness
- CyberDefense (Group security services and products provider)
- Group Operations Security (Security of the hosting entity)
- Corporate Chief Security Officers (Oversight of entities' security) : Corporate Centre, European Markets, International Markets
About the job
Job purpose
The purpose of the role is to:
- Support Head of GO Security Engineering COE in ensuring that security is implemented by design in all projects, products, and services of GO: Security in IT Governance, Process and Methodologies and Roadmap, Oversight AXA GO Product to validate security integration
- Participate to the development and implementation of a consistent approach to all security topics within the scope, including Information Security, Operational Resilience, PS, H&S: merging security topics into security project management including in Agile frameworks
- Support the Communication and advisory to the different stakeholders of the projects regarding Security by design approach
- Support the Project team in the implementation of the cyber risk analysis and security assurance plan for projects or products evolution
- Contribute in the GO Security Engineering COE team in the design enhancement of the framework to support project and product owner in meeting the security requirements: Integration and support of security into Project Management Framework and SDLC
- Contribute in delivering the security oversight in products and projects in GO
- Interact with all relevant stakeholders of the projects or customers of GO to provide visibility on the level of security of GO Products
- Support alignment/coordination between the different line functions involve in the review of Products & Project oversight (Data Privacy, Internal Control, Operational risk, Legal...) as well other Security Stakeholders (Group Security, Cyberdefense, etc.)
Main missions
Your missions as an Agile Security Risk Consultant are to :
- Identify and analyze product/project risks, recommend appropriate mitigation options and document all components in clear, business-intelligible language
- Serve as an expert advisor in the GO Security COE team of GO in the implementation and maintenance of security
- Collaborate with and support the Group Security Practice and other stakeholders as necessary to ensure that security within GO is relevant, cost-effective and is delivered in accordance with the Group Security Strategy and Security by Design best practices
- Support the implementation of continuous improvement processes and activities (e.g. good practices, reporting, problem resolution) to ensure quality and relevance of security services
- Support the implementation of security strategy, policies, shared security services and action plans based on the Group Security Strategy
- Contribute to the maintenance in understanding of emerging technology, risks and industry trends. Assess the impact on the business environment and recommend appropriate mitigation actions or the prioritization of projects and investments
- Escalate the need to redirect any critical risk not properly addressed during the project lifecycle or suggest changes to the approach to mitigate critical risks and ensure legal, regulatory or commercial compliance
- Promote a culture of security and raise awareness
- Contribute to the continuous development and maintenance of an assurance framework to enforce consistency and effectiveness in the security by design approach
- Support the reporting process of information security, operational resilience and Physical Security & Safety for different levels of customers (top management, middle management and team)
- Provide Quality Assurance work on local security implementation
- Support the implementation of a coordinated responses to security audit and compliance issues
- Contribute to the governance organization and management of projects within the team (planning, framework, staffing, purchasing, operations, ..)
Expected skills & experience
We are looking for someone with the following experience and skills:
Experience
Overall work experience in the field
- Experience in cyber risk threat analysis, security, Cloud Architecture and projects, IT audit or related area, DevSecOps, > 7 years
- Previous experience in managing projects preferred in an international context
- Previous experience as interim or acting Security in projects manager, Information Security Officer, Physical Security Officer, Operational Resilience Officer, or extensive experience in reporting to a CSO, CISO, CORO, PSO or other 2nd line cybersecurity expert in an international organization.
Skills
- Ability to develop networking, foster team collaboration to seek collective achievements while supporting the projects or product evolution
- Communication skills: Effectively communicates ( oral and written) the security by design framework & the benefits in achieving the same
- Ability to apply analytical rigour to understand complex business et IT scenarios
- Positive mindset to support the security analysis and eager to learn and grow on new technological areas or frameworks (Agile, AI, ..)
- Capacity to interact with different level of stakeholders from business to technical
- Results oriented, project and budget management
- Good sense of organisation
- Flexibility on working hours
- Fluent in English
What we offer
We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we're committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.
RÉSUMÉ DE L' OFFRE
Agile Security Risk Consultant
AXA
Paris
il y a 4 heures
S/O
Temps plein
Agile Security Risk Consultant