GLOBAL CYBERSECURITY RISK MANAGER

STATION F

Saint-Ouen

Sur place

EUR 120 000 - 180 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Partial remote

Résumé du poste

L'Oréal is seeking a high-impact Cyber Risk Leader in Saint-Ouen to unite governance, risk and compliance across the organization. You will shape risk appetite, build KRIs, and drive a data-driven cyber transformation, reporting to the Head of Cyber Governance, Risk & Compliance.

Based in Saint-Ouen with regular travel, you will manage the global cyber risk team and coordinate with stakeholders in English and French, advancing the One CSRM program and integrating security data into a

Qualifications

  • Master's degree in Information Technology required.
  • Significant experience in cybersecurity risk management, within a consultancy or Fortune 500 company.
  • Ability to communicate risk credibly to both technical and non-technical audiences.
  • Deep knowledge of security frameworks and regulations (GDPR, NIS2 and CRA).
  • Certifications (CRISC, CISM, CISSP) are a plus.

Responsabilités

  • Act as strategic partner for leadership, translating cyber indicators into business risk posture.
  • Define and operationalize cyber risk appetite statements for the group.
  • Design and deploy KRIs and global cyber heatmaps for risk visibility.
  • Lead the One CSRM program and harmonize GRC processes across the group.
  • Oversee Third-Party Cyber Risk Management and CIP deployment.
  • Architect integration of security data sources into a centralized GRC tool.
  • Guide the global cyber risk management team and partner with stakeholders.

Connaissances

Cyber risk management
Risk communication
Security frameworks
GDPR/NIS2/CRA knowledge
English/French bilingual

Formation

Master's degree in Information Technology

Description du poste

About

Notre Raison d'être : Créer la beauté qui fait avancer le monde. Le désir de beauté est une force puissante qui nous fait avancer. La beauté ne se limite pas à l’apparence. Elle nous donne confiance en nous, en qui nous voulons être, et dans notre relation avec les autres. Depuis plus d’un siècle, nous exerçons ce métier unique : créateur de beauté. Notre but est d’offrir à tous, partout dans le monde, le meilleur de la beauté en termes de qualité, d’efficacité, de sécurité et de sincérité pour satisfaire tous les besoins et désirs de beauté dans leur infinie diversité. Et Parce Que Nous Sommes Le Leader De La Beauté, Nous Sommes Conscients Que Tout Ce Que Nous Faisons Peut Avoir Un Impact Significatif. C’est Pourquoi Nous Agissons Pour Inventer le futur de la beauté en ayant recours au meilleur de la technologie et de la science, inspirées par la nature. Faire avancer l’innovation sociale en offrant à nos collaborateurs le meilleur en matière de conditions de travail, de formation et de protection sociale. Construire une entreprise toujours plus inclusive qui reflète la diversité des consommateurs que nous servons. Nouer des partenariats durables avec nos clients et fournisseurs, basés sur la confiance et le développement mutuels. Œuvrer partout pour la cause des femmes et au développement des communautés qui nous entourent. Protéger la beauté de la planète en luttant contre le changement climatique, en respectant la biodiversité et en préservant les ressources naturelles.

Job Description

Hello, we're L'Oréal. We're not just building brands, we're shaping how the world experiences beauty (and it takes a lot of cool jobs to do it). Intrigued? Keep reading, this might be the opportunity you've been searching for.

A Day in the Life

Cybersecurity is the fundamental pillar of L'Oréal's digital business resilience. Reporting to the Head of Cyber Governance, Risk & Compliance, your mission is to architect and participate to the L'Oréal's Risk-Based Cyber Transformation. You will bridge the gap between technical posture and business impact by moving the cyber organization toward a data-driven cyber risk management model.

Within the Group Cybersecurity Governance, Risk and Compliance team you will:

Strategic Decision Support & Intelligence
  • Act as a strategic partner for the leadership team, translating technical cyber indicators into a clear business risk posture.
  • Define and operationalize the Group's cyber risk appetite statements, ensuring business decisions remain within agreed security thresholds.
  • Design and deploy a dashboard of Key Risk Indicators (KRIs) to provide a comprehensive view of global risk exposure.
  • Deliver and present global cyber heatmaps, highlighting critical exposure points and progress against risk reduction targets.
Global Consistency & ERM Integration
  • Ensure the seamless integration of cybersecurity risks into the Group ERM (Enterprise Risk Management) methodology, providing a consistent language for risk reporting at the highest level.
  • Harmonize and synchronize cyber risk processes by leading a consistent "One CSRM" program worldwide.
  • Drive the convergence of GRC processes into a unified global risk calculation engine.
Operational Risk & Process Excellence
  • Crown Jewels Security: Ensure specific risk frameworks are applied to the most critical business assets.
  • TPCRM Leadership (Third-Party Cyber Risk Management): Oversee the global strategy for managing supply chain and vendor risks. Ensure that third-party exposure is quantified and mitigated in line with the Group's risk appetite.
  • CIP (Cyber Into Project): Manage the deployment and enhancement of the CIP process.
Advanced Analytics & Strategic Foresight
  • Design and frame predictive risk assessment models to provide management team with strategic foresight.
Leadership, Coaching & Operational Excellence
  • Direct management of the global cyber risk management team.
  • Act as a cyber risk liaison with relevant stakeholders.
  • Architect the integration of disparate security data sources into a centralized GRC tool.
  • Participate to the GRC global technology roadmap by selecting and implementing tools that support the transition from manual, point-in-time assessments to an automated, continuous risk monitoring platform.
We Are Looking For
  • Education: Master's degree in Information Technology.
  • Professional experience: You are highly experienced in GRC with a significant experience in cybersecurity risk management, within a consultancy firm or a Fortune 500 company.
  • Technical skills:
    • Experience in architecting or maturing risk management program.
    • Ability to communicate risk credibly to both technical and non-technical audiences.
    • Deep working knowledge of security frameworks and regulations (GDPR, NIS2 and CRA).
    • Strong capability to translate the evolving threat landscape into specific business risks.
    • Certifications (CRISC, CISM, CISSP) are a plus.
  • Management skills:
    • Ability to manage internal and consultancy teams.
    • Ability to communicate complex ideas effectively, in English and French, with international stakeholders and with Cybersecurity stakeholders within the Group.
  • Interpersonal skills:
    • Willingness to learn and develop new hard and soft skills.
    • Ability to navigate within a fast-moving environment.
    • Strong analytical skills.
    • Ability to lead workshops.
    • Fluency in English is essential.
    • Position based at St-Ouen (93) with regular meetings within Paris area and rare business trip abroad.
What's In It For You
  • A place for you to leave your comfort zone and grow beyond your potential (here, you'll be encouraged to try new things and take risks!)
  • Real responsibility from day 1, there's no sitting on the sidelines at L'Oréal
  • An environment where people of every ethnicity, social background, age, religion, gender and sexual orientation as well as people with disabilities are accepted, can speak up, will thrive and are celebrated!
  • A place where you can contribute to something bigger! Many of our brands have societal /environmental causes to make concrete difference
Who We Are

L'Oréal is present in 150 markets on five continents. For more than a century, L'Oréal has devoted itself solely to 'Create beauty that moves the world'; it is now the industry world leader with €42 billion consolidated sales. Together, we solve complex challenges at scale, while making sure we stay committed to making the world a more inclusive and a better place for everyone & our planet. Today, L'Oréal includes over 9k experts in beauty tech, digital, data and e-comm and is constantly growing. Championing Beauty Tech, we invent the beauty of the future while becoming the company of the future. To achieve this ambition, L'Oréal continues to recruit diverse, innovative, skilled, and passionate minds in different tech domains such as Data, Digital, Cloud, Cyber Security, IT Architecture, DevOps, Applications, and Infrastructure.

We're committed to guaranteeing inclusive recruitment processes and to advocating for hiring and promoting each candidate in an ethical and equitable way. The Group strictly prohibits discrimination against any applicant for employment because of the individual's gender identity or expression, sexual orientation, visible and/or invisible disabilities, socio-economic and/or multicultural origins, health conditions, age, religion, or any other characteristics protected by law.

Additional Information
  • Contract Type: Full-Time
  • Location: Saint-Ouen
  • Possible partial remote
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Global Cybersecurity Risk Manager
Global Cybersecurity Risk Manager

L'oreal Usa • Saint-Ouen-sur-Seine

Sur place
EUR 110 000 - 160 000
Global exposure
Global Cybersecurity Risk Manager
Global Cybersecurity Risk Manager

L'Oréal • Saint-Ouen-sur-Seine

Sur place
EUR 90 000 - 130 000
CYBERSECURITY MANAGER - INTEGRATION, IT4IT & IOT
CYBERSECURITY MANAGER - INTEGRATION, IT4IT & IOT

STATION F • Saint-Ouen

Hybride
EUR 70 000 - 100 000
Partial remote
CYBERSECURITY MANAGER - DATA & AI
CYBERSECURITY MANAGER - DATA & AI

STATION F • Saint-Ouen

Hybride
EUR 90 000 - 120 000
Possible partiel remote
Cybersecurity Audit & Compliance Manager
Cybersecurity Audit & Compliance Manager

L'Oréal • Saint-Ouen-sur-Seine

Sur place
EUR 90 000 - 130 000
Cybersecurity Manager - Integration, IT4IT & IoT
Cybersecurity Manager - Integration, IT4IT & IoT

L'Oréal • France

Sur place
EUR 90 000 - 120 000
Professional growth
Real responsibility
Inclusive culture
+1
Global Cybersecurity Manager - Cloud & Network
Global Cybersecurity Manager - Cloud & Network

L'Oréal • Saint-Ouen-sur-Seine

Sur place
EUR 90 000 - 130 000
Hybrid Work Policy: 3 days in office,
VIP staff shop and company amenities
Restaurant & gym access
CISO O+O (Online + Offline)
CISO O+O (Online + Offline)

L'Oréal • Saint-Ouen-sur-Seine

Sur place
EUR 120 000 - 160 000
CISO O+O (Online + Offline)
CISO O+O (Online + Offline)

L'Oreal • France

Sur place
EUR 120 000 - 180 000
TECH PROGRAM MANAGER - CRM EUROPE IT
TECH PROGRAM MANAGER - CRM EUROPE IT

STATION F • Levallois-Perret

Sur place
EUR 110 000 - 140 000