Job Search and Career Advice Platform

Activez les alertes d’offres d’emploi par e-mail !

Information Security Lead Expert

AXA Group

France, Paris

Sur place

EUR 70 000 - 90 000

Plein temps

Il y a 17 jours

Générez un CV personnalisé en quelques minutes

Décrochez un entretien et gagnez plus. En savoir plus

Résumé du poste

A leading insurance provider in Auvergne-Rhône-Alpes is seeking an Information Security Lead Expert to lead the development of strategic security policies. This role requires over 10 years of experience and strong project management skills to ensure the security of systems and compliance with regulatory requirements. The ideal candidate will thrive in a fast-paced environment, managing risks and coordinating efforts across various teams.

Prestations

Diverse and inclusive workplace
Opportunities for career growth
Access to global networks and expertise

Qualifications

  • Over 10 years of experience in the Information Security field.
  • At least 5 years of experience as a team lead.
  • Strong ability to manage security incidents.

Responsabilités

  • Lead the development of security policies.
  • Coordinate multiple teams for security policy updates.
  • Manage security risks related to the AXA GO entity.

Connaissances

Information Security Management
Project Management
Communication
Analytical Skills

Formation

University degree in Security Management or related field

Outils

Intrusion Detection Systems
Description du poste

About AXA

As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.

About AXA Group Operations

AXA is becoming a sustainable tech-led company, and at AXA Group Operations (GO), we are one of the major catalysts for this transformation.

We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.

We are present across 13 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.

At AXA GO, we want to be recognized in three fields of action :

  • State-of-the-art Data Technology to drive customer experience.
  • State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks.
  • High-Performing Global Team for stronger partnerships with AXA entities.

Job position pitch

The Information Security Lead Expert leads the development and implementation of the end-to-end strategic approach to Information Security.

Where will you be in the organization?

The division (Group Security)

You will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).

Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand, and people. To achieve this, we have gathered our three security disciplines : Information Security, Operational Resilience and Physical Security.

Our main missions :

  • Monitor the Security Threat Landscape.
  • Define and oversee Security Standards and Strategy implementation across the Group.
  • Drive local security objectives with C-Level executive (COO, CIO, CTO, CFO…) of AXA entities.
  • Ensure the security of AXA GO as an entity, and of AXA GO as a Service Provider.
  • Provide centralized security services and products to AXA entities.

Group Security division is divided in 4 main blocks :

  • Corporate functions (Group Mandate) : Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and Awareness
  • Cyber Defense (Group Security services and products provider)
  • GO Security (Security of AXA GO as an entity, and of AXA GO as a Service Provider)
  • Corporate Chief Security Officers (Oversight of entities’ security) : Corporate Centre, European Markets, International Markets

The department (GO Security)

GO Security department mandate, as part of Group Security division, is to secure AXA GO as an entity, and secure AXA GO Products delivered by AXA GO as a Service Provider to other entities of AXA.

GO Security department is divided in 5 teams :

  • GO Security Oversight
  • GO Security Engineering CoE
  • GO Security Technical Design & Technical Assurance
  • GO Product Security Office
  • GO Security Operational Excellence

The team (GO Security Oversight)

GO Security Oversight team is responsible of

  • Protecting the organization's information, technology & physical assets from external and internal threats, such as cyberattacks, data breaches, and malicious insiders.
  • Developing and implementing GO Security security policies, aligned with the Group Security instructions and regulatory requirements.
  • Managing risks related to AXA GO as an entity, with support from Security Engineering CoE team, and report relevant risks in AXA GO Security Risk Committees.
  • Overseeing the planification and execution of the yearly security testing campaign across AXA GO
  • Developing and implementing security awareness and training programs to ensure AXA GO employees understand their roles and responsibilities in maintaining a secure environment.
  • Ensuring compliance with Group Security instructions and regulatory requirements, supervising primary assurance on AXA GO as an entity, supporting Primary Assurance activities for AXA GO as a Service Provider, and reporting to Group Security with adequate level of data accuracy.
  • Developing and maintaining business continuity policies, Business Continuity plans and exercises to ensure AXA GO can respond effectively to incidents and maintain business operations in the event of a disaster.
  • Overseeing physical security of AXA GO sites (offices, data centers) and people (travels, events).
  • Prioritizing / managing the remediation of audit issues owned by GO Security Oversight.

About the job

Main missions

Reporting to GO Security Oversight Executive Manager , the Information Security Lead Expert leads the development and implementation of the end-to-end strategic approach to Information Security.

Your responsibilities include :

  • Support the GO Security Oversight Executive Manager in achieving GO Security Oversight team’s objectives.
  • Manage the delivery / update of GO Security Policies :
  • Plan the yearly development / update of GO Security Policies, in alignment with Group Security Instructions, Security risks assessments (entity, product) and feedbacks issued from internal and interested parties. GO Security Policies will comply with global laws / regulations and industry best practices, while balancing the requirements of an agile workforce and a secure environment.
  • Lead and coordinate different teams to write / update Security policies, with the aim of getting validated Security Policies delivered by GO.
  • Organize and facilitate information security policy stakeholder meetings to align policy and control objectives to the organization, in synchronization with synchronized with Information Security control framework.
  • Communicate new / updated policies and spread general awareness about policy set among employees.
  • Plan, coordinate, and execute security policies presentations to main operational teams.
  • Gather and maintain artifacts to prepare for audits.
  • Manage the Security awareness inside GO
  • oEnsure that GO Security awareness strategy is aligned with Group Security Awareness Strategy

    oDeliver an annual awareness strategy plan for AXA GO

    oExecute and communicate continuously all related actions defined in the GO awareness strategy plan to all AXA GO employees as GO Security Policies, GO newsletters, news in ONE, videos, webinars, eLearning modules in YES LEARNING or LinkedIn, security events like Security Month in October, Phishing awareness, ...

    oMonitor continuously any awareness actions that can be tracked.

  • Manage the Internal Security requests :
  • oAnswer requests within the GO Security mailbox

    oHandle DLP alerts / incidents from GO employees

  • Manage the GO Security / Security Desk
  • oExecute first criticality assessment of new assets in the GO project management process with involvement of Information Security / Physical Security / Operational Resilience / Security Architecture / Data Privacy / Operational Risk teams,

    oDeliver evidences collection for primary assurance purpose (entities requests)

  • Manage the GO as an entity security risks
  • oManage security risks related to AXA GO as an entity, with support from GO Security Engineering Center team, and report relevant risks in AXA GO Security & Information Risk Committee.

    oUpdate AXA GO Most Valuable Data list on a yearly basis

  • Oversight of the CyberDefense / Pentest execution team
  • oEnsuring right funding is allocated for continuous pentesting

    oPrioritizing assets to be pentested in continuous pentesting (DAST included)

    oMonitoring campaign of pentests

    oConfirm criticality of vulnerabilities raised during pentesting activity

    oEnsuring the remediation of issues detected in pentests

    oReporting to Group Security

    oPerforming primary assurance on pentesting / remediation

  • Automate Internet Facing compliance with Group standards
  • oEnsure Digital Hub completeness & information accuracy by

    §Regularly review declared assets to check if they are still live & information provided is accurate

    §Search for undeclared assets

    oMonitor AXA GO Bitsight score (all Internet Facing assets), & improve score by monitoring remediation on vulnerabilities detected

  • Manage S1 / S2 Security Incidents & Critical / High / Medium Security Threats
  • Measuring impact on AXA GO
  • Coordinating with IT & Security teams remediation / mitigation if impact confirmed
  • Communicating towards entities on AXA GO remediation / mitigation plan progresses
  • On Medium Security Threats , measuring impact on AXA GO depending on volumes impacted
  • Contribute to the remediation of audit issues on Information Security perimeter

Your Profile

Expected skills & experience

We are looking for someone with the following experience and skills :

Experience

  • University degree in Security Management, Information Security, IT or related field.
  • Information Security and / or Information Technology industry certification (ISC2 CISSP, ISACA CISM or equivalent) strongly is necessary
  • Experience >
  • 10 years.

  • Relevant experience as a team lead (>
  • 5 years)

  • Strong experience in Information Systems Security Management
  • Strong experience in project management and multi-team coordination.
  • Technical skills

    • Proficiency in information security technologies, including intrusion detection systems.
    • Experience in managing security incidents
    • Familiarity with audit tools and the ability to examine technical evidence in depth.

    Soft skills / transversal skills

    • Ability to effectively operate in a decentralized and political corporate environment.
    • Ability to function effectively in a matrix structure
    • Strong communication skills to collaborate and interact with various stakeholders
    • Excellent time management skills (tight deadlines).
    • Ability to prioritize activities and to manage action plans, review progress and adjust where required.
    • Good analytical skills and the ability to clearly identify key issues.
    • Ability to recommend solutions relevant to the complexity, scope, risk and magnitude of problems impacting the service level.
    • Strong program / project management.
    • Fluency in English is a necessity
    • Fluency in French is an advantage
    • About AXA

      As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working with 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of

      respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.

      About the Entity

      AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.

      We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.

      We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.

      At AXA Group Operations, we want to be recognized in three fields of action :

      • State-of-the-art Data Technology to drive customer experience
      • State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
      • High-Performing Global Team for stronger partnerships with AXA entities

      What We Offer

      We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity &Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez un fichier PDF, DOC, DOCX, ODT ou PAGES jusqu’à 5 Mo.