04 ago
|
Axa Group Operations
|
Madrid
04 ago
Axa Group Operations
Madrid
- Serving as the primary contact for the operational activities related to Cyber Defense within the Entities/OpCo’s.
- Deliver day-to-day security operations management and reporting as the 1st line of defense (execution). That includes managing related cybersecurity request, incident, change request and resolution management for services in scope.
- Oversee and drive the processes in various domain: infrastructure security operations, security incident and crisis management, audit remediations, and vulnerability management.
- Ensure comprehensive coverage and reporting of all security tool implementations across all in-scope assets.
- Monitor, report on, and drive compliance with operational SLAs, KPIs, and KRIs for subscribed services, coordinating with relevant stakeholders.
- Act as the extension of the Cyber Defense Integral team, delivering tools and services to entities/opco’s.
- Serve as the primary security operations contact within Group Operations, collaborating across organizational boundaries (e.g., OpCo’s, Solution Delivery, regional and local CISOs, vendors, etc.).
- Function as the Security Operations Subject Matter Expert (SME) to detect, respond to, and defend AXA against malicious actors and threats.
- Oversee security monitoring and the incident lifecycle, including executive and client communications, direct resource management and coordination, and end-to-end process oversight from detection to post-mortem and root-cause analysis (RCA).
- Ensure and enforce information security relevant controls and process across the AXA entities.
- Participate as required in global security programs and projects to deliver assigned objectives.
- Contribute to audit relevant investigations and their management action plans to remediate the discovered risks.
- Act as a security advocate to promote security policies and culture / mindset
- Act as a security advisor to the relevant stakeholders on security matters
- Participate and support local Security Programs and Projects
- Contribute to rapid incident response by recommending and prioritizing appropriate responses and by contributing to the lessons learned and post-incident activities
We are looking for someone with the following experience and skills:
Experience
- Diploma or Bachelor’s degree in Computer Science, IT, Engineering, or related fields
- Experience in IT > 15 years
- Experience in IT Security > 10 years
- Proven experience in running Security Operations and project works in the following categories below.
- In-depth knowledges of infrastructure and application vulnerabilities, architectures and challenges.
- Information Security and/or Information Technology industry certification like CISSP, CCSP, CISM, CISA, CEH, GCIH, GCIA, OSCP, and etc, is a plus
- Experience on Cloud Security is a plus
Technical skills
- Cross-cultural sensitivity and flexibility. Appreciate diversity and inclusiveness.
- Experience with security operations, risk and service delivery frameworks.
- Familiar with local and regional regulatory requirements for entities
- Knowledge of information security best practices, architecture, standards and threat landscape
- Customer-centric and strong service delivery skills with escalation management capabilities
- Strong interpersonal and communication skills; able to deal effectively with diverse skill sets and personalities, works effectively as a team player
- Organized with a proven ability to prioritize workload, meet deadlines, and utilize time effectively
- Able to translate technical requirements and communicate at all levels
- Apply analytical rigor to understand complex business scenarios
- Ability to function effectively in a matrix structure. xqbhyrx
- Ability to function with minimal supervision
- Subject Matter Expert for the following in-scope security services below.
Infrastructure Security (Mandatory)
- Network Security - at least intermediate knowledges for minimum 3 solutions
- Firewall review and assessment
- Intrusion Prevention System (IPS)
- DDoS protection
- Secure Web Access (Proxy)
- Web Application Firewall (WAF)
- End-Point Security - at least intermediate knowledges for minimum 2 solutions
- Malware Protection (Anti-Virus, Anti-Malware)
- Data Security - basic knowledges
- Encryption
Security Incident Management (Mandatory)
- SIEM - basic knowledges
- Security Incident Handling/Response - intermediate knowledges
Application Security & Vulnerability Management
#J-18808-Ljbffr
📌 Security Officer (Madrid)
🏢 Axa Group Operations
📍 Madrid