04 ago
|
Axa Group
|
Madrid
ppstrongAbout AXA /strong /ppAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can. /ppstrongAbout the entity /strong /ppAXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation. /ppWe set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution. /ppWe are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary. /ppAt AXA Group Operations, we want to be recognized in three fields of action: /pulliState-of-the-art Data Technology to drive customer experience /liliState-of-the-art Procurement Sourcing to drive efficiency and better manage risks /liliHigh-Performing General Team for stronger partnerships with AXA entities /li /ulpstrongJob position pitch /strong /ppDrive Information Security in terms of oversight, assurance, risks, accuracy of reporting. Challenge the information security practice and escalate gap in the entity and to the Market CCSO when necessary. /ppCoach and facilitate the deployment of security projects and the Group Security Program. /ppAct as a key advisor to local security Management on information security matters (e.g. risk management, cybersecurity, security control, monitoring, information privacy, operations, identity access management, security architecture, incident management and forensics) /ppSupport the development of the security shared services and facilitate the implementation within the local entity. /ppstrongWhere will you be in the organization? /strong /ppYou will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).
/ppThroughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience. /ppOur main missions: /pulliMonitor the Security Threat Landscape /liliDefine and oversee Security Standards and Strategy implementation across the Group /liliDrive local security objectives with C-Level executive (COO, CIO, CTO, CFO…) of AXA entities /liliEnsure the security of Group Operations as an entity /liliProvide centralized security services and products to AXA entities /li /ulpAXA Group Security is divided in 4 main blocks : /pulliCorporate functions (Group Mandate) : Security Advisory and Standards , Security Governance , Security Risk Assurance , Security Strategy and Awareness /li /ululliCyberDefense (Group security services and products provider ) /liliGroup Operations Security (Security of the hosting entity ) /liliCorporate Chief Security Officers (Oversight of entities’ security ) : Corporate Centre , European Markets , International Markets /li /ulpstrongAbout the job /strong /ppstrongMain missions /strong /pulliCollaborate with and support on one side Group Security and other group stakeholders to ensure that Information Security within the local entity is aligned with the Group Security Framework and the Group Security Strategy /li /ululliServe as an expert advisor to the entity leadership team in the implementation and maintenance of security /li /ululliAssess the entities local compliance with the information security standards, instructions and strategic initiatives /li /ululliHelp integrating the information security strategy into the entity (taking into consideration the local regulation and specificities), defines the concrete actions leading to its execution and monitors achievement /li /ululliEnsure the achievement of the information security targets in the entity, as set by Group Security. /li /ululliOrganise regular meetings with each entity to follow on progress or issues /li /ululliIdentify and analyze information security risks, recommend appropriate mitigation options and check that the entity documents the issues in clear,
business-intelligible language /li /ululliMaintain an understanding of emerging technology (like AI), risks and industry trends. Assess the impact of emerging technology in the entities, recommend and define protection priorities with the entities. /li /ululliEscalate key information security risks to the local CSO and CCSO. /li /ululliOversight the implementation of continuous information security improvement processes and activities (e.g. good practices, reporting, problem resolution) to ensure quality and relevance of security services /li /ululliEnsure that Information Security Incidents are adequately managed. Inform and escalate to the Information Security Incidents /li /ululliUndertakes assurance to validate the effectiveness of the local security activities and controls. Ensure ineffectiveness are managed using the Security Governance of the entity and the Group /li /ululliOversee the execution of information security projects /li /ululliEnsure development and maintenance of auditable processes to enforce consistency and facilitate the entity Assurance Process /li /ululliSupport the entities in responding to Information Security Audit. Ensure that overdue serious audit findings in the entities are managed with the right level of attention by following closely on the delivery of the entity and understanding potential difficulties for resolution. /li /ulpstrongExpected skills experience /strong /ppWe are looking for someone with the following experience and skills: /ppstrongEducation: /strong /pulliA university degree in a technical discipline or a related fields (information security, risks management, international relations, information security…) /li /ulpstrongList of preferred certifications: /strong /pulliInformation Security and /or Information Technology industry certification (CISSP-ISSAP, CISM, ISO 27001 Lead Auditor, SANS GIAC or equivalent) /li /ulpstrongOverall work experience in the field: /strong /pulliExperience in security, risks management, audit or related area: 5 years /li /ulpstrongSoft skills / transversal skills: /strong /pulliTeam player /liliAbility to apply analytical rigour to understand complex business scenarios /liliLocal language(s) and fluent in English (French is an advantage) /li /ulpstrongWhat we offer /strong /ppWe bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued. /p /p #J-18808-Ljbffr
📌 Head of Information Security & Risk Governance (Madrid)
🏢 Axa Group
📍 Madrid