CISO O+O
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Hello, we’re L’Oréal. We're not just building brands, we're shaping how the world experiences beauty (and it takes a lot of cool jobs to do it). Intrigued? Keep reading, this might be the opportunity you've been searching for.
Vous envisagez de postuler à cet emploi ? N'attendez pas, faites défiler la page et envoyez votre candidature dès que possible pour ne pas la manquer.
A Day in the Life
This position is part of L’Oréal Group Cybersecurity Team. O+O (Online + Offline) refers to the strategic integration of digital and physical touchpoints into a single ecosystem, to provide a unified and seamless experience across every consumer & customer interaction.
Your Future Team Is Organized Around 3 Key Pillars
- Online: e-commerce, Website Factory, Consumer Engagement… This department powers up L’Oréal Digital Footprint jointly with Digital and Marketing Business Teams.
- Omnisales: Retail, Services, Commercial… Omnisales mission is to turn L’Oréal Points of Sales into Points for Experience, and to augment all commercial Teams in Markets Worldwide.
- Omniinnovation: Station F, Gen AI, Retail Lab… This Team accompanies innovative and creative initiatives to scout the most promising ones, which could be scaled at L’Oréal.
The Team works in very close collaboration with the Divisions and Zones, as well as with other L’Oréal functions such as Marketing, Finance, and more.
Reporting & Responsibilities
Reporting to the Business Platforms CISO, you will be responsible for all aspects of Information security and technology Risk Management for O+O scope, including a major Cybersecurity transformation program with a worldwide impact (Titanium). It is a Leadership role that requires a strong technical background, as well as excellent communication skills to work jointly with Business and IT Teams in order to ensure compliance to L’Oréal Information Security Policy and applicable laws and regulations, while enabling and facilitating the Business.
Your Responsibilities
- Manage O+O Cybersecurity Team, composed of both internal and external Departments Cybersecurity Managers.
- Define and enforce an information security strategy for IT O+O scope.
- Maintain close relationships with zones animating O+O Cybersecurity Community worldwide.
- Jointly with the Business and IT Teams, ensure L’Oréal Integration of Security in Projects methodology is properly applied.
- Follow‑up on Third Party Cybersecurity Risk Management: in particular, work closely with legal and purchasing teams to ensure appropriate integration of security requirements at the earliest stages of Third Parties Selection and contracting.
- Proactively identify and mitigate information security risks throughout the lifecycle of O+O assets.
- Manage security exceptions and formally document risk acceptance and associated compensatory measures.
- Lead and drive Titanium O+O Cybersecurity program jointly with infrastructure and IT O+O Teams, both at global and zone level.
- Manage regulatory compliance jointly with the concerned teams (Data Privacy, etc.).
- Follow‑up on compliance and security KPIs and put in place appropriate action plans to continuously improve these KPIs.
- Follow‑up on Threat and Vulnerability Management process and related remediation plans.
- Ensure prompt and close follow‑up of security incidents, jointly with L’Oréal CSIRT.
- Act as a Cybersecurity evangelist, designing and leading engaging awareness sessions for diverse audiences.
- As part of L’Oréal Global Cybersecurity Team, you will actively contribute to securely Create the Beauty that Moves the world.
We Are Looking For
First and foremost, we love people that are curious, collaborative, eager to have an impact, proactive and who value innovation, autonomy, and team spirit.
We are looking for someone highly experienced with at least 10 years of experience in information security in similar roles.
Your Core Skills
- Strong technical background in IT security.
- Good knowledge of Cybersecurity Strategy definition and implementation.
- Excellent interpersonal skills.
- Good knowledge of Risk Management standards.
- Good knowledge of domain‑specific and security‑related regulations and standards such as GDPR and PCI‑DSS.
- Excellent spoken/written English (international context).
- Rigorous and organized mindset.
- Team Management Experience (particularly Transversal Team Management).
- Important: You hold Cybersecurity certifications such as CISSP.
What’s In It For You
- A place for you to leave your comfort zone and grow beyond your potential (here, y