Security Risk Analyst

Job title:

Security Risk Analyst

Company:

AXA

Job description

CONTEXTTo support our business strategy and digital transformation, AXA is building a new Group Information Security Practice to ensure a coordinated response to the increasing cyber security threat, enable risk decisions to be made consistently across the organization and establish sustainable security capabilities that are integrated with the business. Our vision for Information Security is to ‘protect our stakeholders by securing our information assets, managing our cyber risk and enabling business strategies in an efficient and effective way, fully supported by executive leadership and underpinned by all AXA employees’.JOB PURPOSEThe purpose of the role is to:· Support Head of Security in projects in ensuring that security is implemented by design in all projects, products, and services of GO: Security in IT Governance, Process and Methodologies and Roadmap, Oversight AXA GO Product to validate security integration· Participate to the development and implementation of a consistent approach to all security topics within the scope, including Information Security, Operational Resilience, PS, H&S: merging security topics into security project management· Support the Communication and advisory to the different stakeholders of the projects regarding Security by design approach· Support the Project team in the implementation of the cyber risk analysis and security assurance plan for projects· Contribute in the Security in Projects team in the design enhancement of the framework to support project and product owner in meeting the security requirements: Integration and support of security into Project Management Framework· Contribute in delivering the security oversight in products and projects in GO· Interact with all relevant stakeholders of the projects or customers of GO to provide visibility on the level of security of GO Products· Support alignment/coordination between the different line functions involve in the review of Products & Project oversight (Data Privacy, Internal Control, Operational risk, Legal…) as well other Security Stakeholders (Group Security, Cyberdefense, etc.)MISSIONSYour missions as a Project Security Risk Analyst are to :· Identify and analyze product/project risks, recommend appropriate mitigation options and document all components in clear, business-intelligible language· Serve as an expert advisor in the Security in projects team of GO in the implementation and maintenance of security· Collaborate with and support the Group Security Practice and other stakeholders as necessary to ensure that security within GO is relevant, cost-effective and is delivered in accordance with the Group Security Strategy and Security by Design best practices· Support the implementation of continuous improvement processes and activities (e.g. good practices, reporting, problem resolution) to ensure quality and relevance of security services· Support the implementation of security strategy, policies, shared security services and action plans based on the Group Security Strategy

· Contribute to the maintenance in understanding of emerging technology, risks and industry trends. Assess the impact on the business environment and recommend appropriate mitigation actions or the prioritization of projects and investments· Escalate the need to redirect any critical risk not properly addressed during the project lifecycle or suggest changes to the approach to mitigate critical risks and ensure legal, regulatory or commercial compliance· Promote a culture of security and raise awareness· Contribute to the continuous development and maintenance of an assurance framework to enforce consistency and effectiveness in the security by design approach· Support the reporting process of information security, operational resilience and Physical Security & Safety for different levels of customers (top management, middle management and team)· Provide Quality Assurance work on local security implementation· Support the implementation of a coordinated responses to security audit and compliance issues· Contribute to the governance organization and management of projects within the team (planning, framework, staffing, purchasing, operations, ..)QualificationsPROFILEOverall work experience in the field· Experience in cyber risk threat analysis, security, Cloud Architecture and projects, IT audit or related area
7 years· Previous experience in managing projects preferred in an international context· Previous experience as interim or acting Security in projects manager, Information Security Officer, Physical Security Officer, Operational Resilience Officer, or extensive experience in reporting to a CSO, CISO, CORO, PSO or other 2nd line cybersecurity expert in an international organization.Certification in one of the below is recommended· Security Risk analysis methodology· Information Security and /or Information Technology industry certification (CISSP, CISSP-ISSAP, CISM, ISO 27001 Lead Auditor, GIAC or equivalent)· Business Continuity Industry certification (MBCI, DRII…)· Physical security certification (CPP, PSP, BTEC…)Education & certification· A license/bachelor’s degree in information security, computer science, information management systems, Business, Accounting or related field· A post-graduate degree in security or general management (such as an MBA) is an advantage but not essentialSkills / abilities· Ability to develop networking to seek collective achievements while supporting the projects· Communication skills: Effectively communicates ( oral and written) the security by design framework & the benefits in achieving the same· Ability to apply analytical rigour to understand complex business et IT scenarios· Capacity to interact with different level of stakeholders from business to technical· Results oriented, project and budget management· Good sense of organisation· Flexibility on working hours

Expected salary

Location

Paris

Job date

Fri, 15 Nov 2024 23:35:21 GMT

To help us track our recruitment effort, please indicate in your email/cover letter where (vacanciesineu.com) you saw this job posting.

Share
yonnetim

Published by
yonnetim

Recent Posts

Responsable venta empresas. Telefónica. ZARAGOZA

Job title: Responsable venta empresas. Telefónica. ZARAGOZA Company: Aragonjobs Job description Para inscribirse a esta…

56 seconds ago

Technicien(ne) de Maintenance

Location: Privas - France Salary: Competitive Type: Permanent Main Industry: Search Information Technology Jobs Other…

2 minutes ago

Verkoopmedewerker weekend Zutphen (8 uur) 1

Location: Zutphen (7201 LT) - Netherlands Salary: Competitive Type: Permanent Main Industry: Search Information Technology…

3 minutes ago

Mobile Maintenance Electrician

Location: Oxford (OX4) - Oxfordshire, South East, United Kingdom Salary: £38500 - £38800 per annum…

4 minutes ago

Payroll Analyst II

Job title: Payroll Analyst II Company: Thermo Fisher Scientific Job description Work Schedule Flex Shifts…

6 minutes ago

Stage R&D Laboratoire d’essais biomécaniques H/F in Grenoble, France

vacanciesineu.com We are excited to be named one of the World’s Best Workplaces by Fortune…

9 minutes ago
If you dont see Apply Button. Please use Non-Amp Version