Security Risk Assessment Expert
11 days ago
Madrid
ph3About AXA /h3 pAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can. /p h3About the entity /h3 pAXA is becoming a sustainable tech‑led company and at AXA Group Operations we are one of the major catalysts for this transformation. /p pWe set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution. /p pWe are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary. /p pAt AXA Group Operations, we want to be recognized in three fields of action: /p ul liState‑of‑the‑art Data Technology to drive customer experience /li liState‑of‑the‑art Procurement Sourcing to drive efficiency and better manage risks /li liHigh‑Performing Global Team for stronger partnerships with AXA entities /li /ul h3Where will you be in the organization? /h3 h3The division /h3 pYou will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.). /p pThroughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience. /p pOur main missions: /p ul liMonitor the Security Threat Landscape /li liDefine and oversee Security Standards and Strategy implementation across the Group /li liDrive local security objectives with C‑Level executive (COO, CIO, CTO, CFO…) of AXA entities /li liEnsure the security of Group Operations as an entity /li liProvide centralized security services and products to AXA entities /li /ul pAXA Group Security is divided in 4 main blocks : /p ul liCorporate functions (Group Mandate) : Security Advisory and Standards, Security Governance, Security Risk Assurance, Security Strategy and Awareness /li liCyberDefense (Group security services and products provider) /li liGroup Operations Security (Security of the hosting entity) /li liCorporate Chief Security Officers (Oversight of entities’ security) : Corporate Centre, European Markets, International Markets /li /ul h3The department / team /h3 pThe Security Risk team at AXA is dedicated to identifying, monitoring, and prioritizing key security risks across three main disciplines: Information Security, Operational Resilience, and Physical Security. These areas are crucial to AXA's goal of securing the customer journey and providing resilient services. Over the past few years, the focus on embedding risk and related data vectors has been strengthened, making them central to an effective security strategy and program that can measure and quantify risk. The team also manages Vendor Security. /p pAs a member of this dynamic and collaborative global team, you will work closely with Group executives, security management teams, security experts, and Chief Security Officers from various operating companies worldwide. The team is responsible for both the security risk framework and the vendor security risk framework. /p h3About the job /h3 h3Main missions /h3 ul liDefining the requirements and capabilities for security risk management and vendor security risk. /li liSupporting the reduction and prioritization of security activities. /li liMonitoring key security risks for the Group and communicating them to relevant parties. /li liDeveloping and sustaining Security Risk Management maturity and risk awareness. /li liActing as a trusted advisor to support business decisions driven by risk. /li /ul pOur goals are to : /p ul liDesign, maintain, and improve a converged Security Risk framework and associated methodologies/tools, including entity‑based, asset‑based, and vendor security risk assessments. /li liProvide training and support to our entities in implementing and improving their local Security Risk Management Framework. /li liDetermine the Group's security risk posture to support strategic initiatives on risk reduction and prioritization. /li liContinuously improve Vendor Security, Information Security risk management, and Data classification instructions and related frameworks. /li liIdentify and assess key transversal risks for the Group. /li liOffer subject matter expertise and advisory on security risk‑related topics. /li liFoster a risk‑aware culture across our entities through our Security Risk Community. /li /ul pYou will work transversally daily, with reinforced interaction and co‑construction as a guiding principle. /p h3Your stakeholders /h3 ul liInternally: You will engage with AXA Group Risk Internal Audit, IT Leadership Business Leadership, Group Compliance Legal, IT Operations Business Operations, as well as Local/Regional CSO and Security team members. /li liExternally: You are expected to interact with external third parties. /li /ul h3Your Certifications /h3 pSecurity and/or Information Technology industry certifications: Preferred certifications include ISO 27001 (Implementer/Auditor), CISSP, CRISC, CISA, and CISM. Other relevant certifications are CEH (Certified Ethical Hacker), CCSP (Certified Cloud Security Professional), and GIAC (Global Information Assurance Certification), /p h3Expected skills experience /h3 pWe are looking for someone with the following experience and skills: /p h3Education /h3 ul liBachelor degree in Computer Science, Engineering, or related field /li liAn MSc Information Security and Operational Risk Management is strongly preferred /li /ul h3Certifications /h3 ul liInformation Security and /or Information Technology industry certifications in good standing (CRISC, CISSP, CISM, ISO27005 Certified Risk Manager, ISO27001 Lead Auditor or equivalent) strongly preferred /li liCBCI Physical Security certifications are desirable /li /ul h3Overall work experience in the field /h3 ul liExperience in articulating security risks in business language and advising on the appropriate risk management strategy 7 years /li liExperience in Information Security field 5 years /li liExperience in Operational Resilience 2 years /li liExperience in Physical Security / Health Safety 2 years /li /ul h3Skills / abilities /h3 ul liAbility to function effectively in a matrix structure /li liAbility to manage uncertainty /li liOperate adequately at senior and executive management level /li liStrong facilitation, negotiation and conflict resolution skills /li liProficient risk assessment, interpretation and analytical skills /li liStrong networking skills /li liTeam player /li liFluent in English /li /ul h3What we offer /h3 pWe bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued. /p /p #J-18808-Ljbffr