Ver oferta completa

INFORMATION SECURITY RISK ASSESSMENT

Descripción de la oferta de empleo

CONTEXTTo support our business strategy and digital transformation, AXA is building a new Group Information Security Practice to ensure a coordinated response to the increasing cyber security threat, enable risk decisions to be made consistently across the organization and establish sustainable security capabilities that are integrated with the business. Our vision for Information Security is to ‘protect our stakeholders by securing our information assets, managing our cyber risk and enabling business strategies in an efficient and effective way, fully supported by executive leadership and underpinned by all AXA employees’.JOB PURPOSEThe purpose of the role is to:Support Head of Security in projects in ensuring that security is implemented by design in all projects, products, and services of GO: Security in IT Governance, Process and Methodologies and Roadmap, Oversight AXA GO Product to validate security integrationParticipate to the development and implementation of a consistent approach to all security topics within the scope, including Information Security, Operational Resilience, PS, H&S: merging security topics into security project managementSupport the Communication and advisory to the different stakeholders of the projects regarding Security by design approachSupport the Project team in the implementation of the cyber risk analysis and security assurance plan for projectsContribute in the Security in Projects team in the design enhancement of the framework to support project and product owner in meeting the security requirements: Integration and support of security into Project Management FrameworkContribute in delivering the security oversight in products and projects in GOInteract with all relevant stakeholders of the projects or customers of GO to provide visibility on the level of security of GO ProductsSupport alignment/coordination between the different line functions involve in the review of Products & Project oversight (Data Privacy, Internal Control, Operational risk, Legal…) as well other Security Stakeholders (Group Security, Cyberdefense, etc.)MISSIONSYour missions as a Security in Projects Expert are to:Identify and analyze product/project risks, recommend appropriate mitigation options and document all components in clear, business-intelligible languageServe as an expert advisor in the Security in projects team of GO in the implementation and maintenance of securityCollaborate with and support the Group Security Practice and other stakeholders as necessary to ensure that security within GO is relevant, cost-effective and is delivered in accordance with the Group Security Strategy and Security by Design best practicesSupport the implementation of continuous improvement processes and activities (e.g., good practices, reporting, problem resolution) to ensure quality and relevance of security servicesSupport the implementation of security strategy, policies, shared security services and action plans based on the Group Security StrategyContribute to the maintenance in understanding of emerging technology, risks, and industry trends. Assess the impact on the business environment and recommend appropriate mitigation actions or the prioritization of projects and investmentsEscalate the need to redirect any critical risk not properly addressed during the project lifecycle or suggest changes to the approach to mitigate critical risks and ensure legal, regulatory, or commercial compliancePromote a culture of security and raise awarenessContribute to the continuous development and maintenance of an assurance framework to enforce consistency and effectiveness in the security by design approachSupport the reporting process of information security, operational resilience, and Physical Security & Safety for different levels of customers (top management, middle management and team)Provide Quality Assurance work on local security implementationSupport the implementation of a coordinated responses to security audit and compliance issuesContribute to the governance organization and management of projects within the team (planning, framework, staffing, purchasing, operations...)PROFILEOverall work experience in the fieldExperience in cyber risk analysis, security, Cloud Architecture and projects, IT audit or related area > 4 yearsPrevious experience in managing projects preferred in an international contextPrevious experience as interim or acting Security in projects manager, Information Security Officer, Physical Security Officer, Operational Resilience Officer, or extensive experience in reporting to a CSO, CISO, CORO, PSO or other 2nd line cybersecurity expert in an international organization.Certification in one of the below is recommendedSecurity Risk analysis methodologyInformation Security and/or Information Technology industry certification (CISSP, CISSP-ISSAP, CISM, ISO 27001 Lead Auditor, GIAC or equivalent)Business Continuity Industry certification (MBCI, DRII…)Physical security certification (CPP, PSP, BTEC…)Education & certificationA license/bachelor's degree in information security, computer science, information management systems, Business, Accounting or related fieldA post-graduate degree in security or general management (such as an MBA) is an advantage but not essentialSkills & abilitiesAbility to develop networking to seek collective achievements while supporting the projectsCommunication skills: Effectively communicates (oral and written) the security by design framework & the benefits in achieving the sameAbility to apply analytical rigour to understand complex business et IT scenariosCapacity to interact with different level of stakeholders from business to technicalResults oriented, project and budget managementGood sense of organisationFlexibility on working hoursFluent in English
Ver oferta completa

Detalles de la oferta

Empresa
  • AXA Group Operations
Localidad
  • En toda España
Dirección
  • Sin especificar - Sin especificar
Fecha de publicación
  • 13/04/2024
Fecha de expiración
  • 12/07/2024
Remote Data Entry Clerk
valorlave

Maintain confidentiality of sensitive information by following data privacy and security protocols... responsibilities:accurately enter data into our systems, including customer information, inventory data, and financial data... as a data entry clerk, you will be responsible for accurately entering and......

Production Supervisor
VALEO

Manage daily: absenteeism, holidays, safety rules enforcement, environment risk analysis, communication & performance boards update... electronics engineering degree experience in manufacturing, or process engineering – methods (2-3 years), or beginner with previous training in manufacturing if you......

Quality Project Team Member
VALEO

React when a risk is identified, escalate roadblocks... if you do not meet all the requirements, don't worry, we want to meet you too! more information on valeo: https://www... which make a lot of opportunity for career growth- a business highly committed to limiting the environmental impact if its......

Call 39-2023-1 Researcher position
Centre Tecnològic de Telecomunicacions de Catalunya

For more information about the pons research unit click here (https://www... more information about cttc professional categories can be found at this link: (https://www... * cvs and any other information gathered during this process will be handled confidentially who are we? the center tecnològic de......

CALL 39-2023-2
Centre Tecnològic de Telecomunicacions de Catalunya

For more information about the pons research unit click here (https://www... more information about cttc professional categories can be found at this link: (https://www... * cvs and any other information gathered during this process will be handled confidentiallyotros datos del puestowho are we? the......

Research Position - Sustainable Artificial Intelligence RU
Centre Tecnològic de Telecomunicacions de Catalunya

More information on the greenedge project: https://greenedge-itn... more information on the research unit: https://www... * cvs and any other information gathered during this process will be handled confidentially who are we? the center tecnològic de telecomunicaciones de catalunya (cttc) is a non-profit......

Data Engineer
Innoit

Closely collaborates with information architect and system leads of it domains... your profile: bachelor's or master's in information technology or equivalent education with it focus... proven practical experience in managing data ingestion projects in hadoop environments using agile methodologies......

ICU hospital londres - enfermera UK
Reach hr consulting

You are advised that you can unsubscribe from all the above information by sending an email to unsubscribe... • provide didactic and educational material as appropriate, validate and document the patient's and family's understanding of the information transmitted conditions offered:permanent contractstarting......

Ads Quality Rater- Dutch (online Spain)
Welocalize

This is a long-term project that involves analyzing and providing feedback on texts, web pages, images, and other types of information using an online tool... job information: · contract type: freelance contract · location: remote, but must be based in spain · weekly hours: 5 to 20 hours (with occasional......

ICN2 PhD Programme 2023
INSTITUT CATALÀ DE NANOCIÈNCIA I NANOTECNOLOGIA (ICN2)

For additional information in the application procedure, please contact *****@*****... 2 reference letters... please visit the profiles of our groups at http://icn2... for any further clarification as to these requirements, applicants should contact *****@***** prior to applying... es/en/servicios-al-ciudadano/catalogo/general/20/203615/ficha......