Security Risk Expert Lead

AXA
Paris
EUR 40 000 - 60 000
Description du poste

JOB ENVIRONMENT

With over 102 million customers in 56 countries, AXA's strong global franchises and three lines of expertise - Property & Casualty, Life & Savings and Asset Management - provide a distinctive business portfolio. As a company whose business is to protect people, we have a responsibility to leverage our skills, resources and risk expertise to build a stronger and safer society. To achieve our mission, we are committed to redefining the standards of our business so that we truly differentiate ourselves and earn the trust of our key stakeholders.

As an integral part of AXA, at AXA Group Operations (AXA GO) we create innovative technology and data solutions to help AXA fulfill its ambition of being a customer-focused, tech-led company. AXA GO is a young and dynamic division launched in 2019 and comprises 8,000 employees across 17 countries all around the globe from Paris, France to Pune, India. We are the ones providing advice, steering technological choices and giving AXA access to innovations that will support its transformation into a customer-centric tech-led company. For this, we work in close partnership with all AXA entities.

PRESENTATION OF THE CONTEXT AND AXA GROUP SECURITY

Throughout AXA, the security community consists of 1,000 security professionals dedicated to protecting our employees, customers, operations, and brand. Our operating model integrates three key security disciplines: Information Security, Operational Resilience, and Physical Security & Safety. Our mission is to ensure that AXA remains safe, secure, and resilient.

AXA Group Security, as part of AXA GO, defines the security strategy and standards, providing assurance to the Group on the security maturity of all AXA entities. Additionally, it supports our professional family within entities to maintain their security posture and coordinate responses to crises.

This mission is achieved through four strategic levers:

  • Safe : Focuses on our people, ensuring they are prepared to face security challenges, including those involving third parties and health professionals.
  • Secure : Secures the business of today and tomorrow by enhancing security effectiveness through a risk-based approach for all entities.
  • Resilient : Enhances anticipation, detection, and reaction capabilities in case of events, incorporating Security by Design.
  • Simple: Simplifies, converges, and automates our services and activities.

PRESENTATION OF THE GROUP SECURITY RISK TEAM

The Security Risk team at AXA is dedicated to identifying, monitoring, and prioritizing key security risks across three main disciplines: Information Security, Operational Resilience, and Physical Security. These areas are crucial to AXA's goal of securing the customer journey and providing resilient services. Over the past few years, the focus on embedding risk and related data vectors has been strengthened, making them central to an effective security strategy and program that can measure and quantify risk. The team also manages Vendor Security.

As a member of this dynamic and collaborative global team, you will work closely with Group executives, security management teams, security experts, and Chief Security Officers from various operating companies worldwide. The team is responsible for both the security risk framework and the vendor security risk framework.

Our main missions include:

  • Defining the requirements and capabilities for security risk management and vendor security risk.
  • Supporting the reduction and prioritization of security activities.
  • Monitoring key security risks for the Group and communicating them to relevant parties.
  • Developing and sustaining Security Risk Management maturity and risk awareness.
  • Acting as a trusted advisor to support business decisions driven by risk.

Our goals are to:

  • Design, maintain, and improve a converged Security Risk framework and associated methodologies/tools, including entity-based, asset-based, and vendor security risk assessments.
  • Provide training and support to our entities in implementing and improving their local Security Risk Management Framework.
  • Determine the Group's security risk posture to support strategic initiatives on risk reduction and prioritization.
  • Continuously improve Vendor Security, Information Security risk management, and Data classification instructions and related frameworks.
  • Identify and assess key transversal risks for the Group.
  • Offer subject matter expertise and advisory on security risk-related topics.
  • Foster a risk-aware culture across our entities through our Security Risk Community.

You will work transversally daily, with reinforced interaction and co-construction as a guiding principle.

Your stakeholders

  • Internally : You will engage with AXA Group Risk & Internal Audit, IT Leadership & Business Leadership, Group Compliance & Legal, IT Operations & Business Operations, as well as Local/Regional CSO and Security team members.
  • Externally : You are expected to interact with external third parties.

Your Certifications

Security and/or Information Technology industry certifications: Preferred certifications include ISO 27001 (Implementer/Auditor), CISSP, CRISC, CISA, and CISM. Other relevant certifications are CEH (Certified Ethical Hacker), CCSP (Certified Cloud Security Professional), and GIAC (Global Information Assurance Certification), GRC related experience.

Qualifications

Education

  • Bachelor degree in Computer Science, Engineering, or related field
  • An MSc Information Security and Operational Risk Management is strongly preferred

Certifications

  • Information Security and/or Information Technology industry certifications in good standing (CRISC, CISSP, CISM, ISO27005 Certified Risk Manager, ISO27001 Lead Auditor or equivalent) strongly preferred
  • CBCI & Physical Security certifications are desirable

Overall work experience in the field

  • Experience in articulating security risks in business language and advising on the appropriate risk management strategy > 7 years
  • Experience in Information Security field > 5 years
  • Experience in Operational Resilience > 2 years
  • Experience in Physical Security / Health & Safety > 2 years

Skills / abilities

  • Ability to function effectively in a matrix structure
  • Ability to manage uncertainty
  • Operate adequately at senior and executive management level
  • Strong facilitation, negotiation and conflict resolution skills
  • Proficient risk assessment, interpretation and analytical skills
  • Strong networking skills
  • Team player
  • Fluent in English
Obtenez un examen gratuit et confidentiel de votre CV.
Sélectionnez le fichier ou faites-le glisser pour le déposer
Avatar
Coaching en ligne gratuit
Multipliez vos chances de décrocher un entretien !
Faites partie des premiers à découvrir de nouveaux postes de Security Risk Expert Lead à Paris