Information Security Lead Expert

il y a 2 jours


France AXA Group Temps plein

About AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.About AXA Group OperationsAXA is becoming a sustainable tech-led company, and at AXA Group Operations (GO), we are one of the major catalysts for this transformation.We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.We are present across 13 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.At AXA GO, we want to be recognized in three fields of action :State-of-the-art Data Technology to drive customer experience.State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks.High-Performing Global Team for stronger partnerships with AXA entities.Job position pitchThe Information Security Lead Expert leads the development and implementation of the end-to-end strategic approach to Information Security.Where will you be in the organization?The division (Group Security)You will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand, and people. To achieve this, we have gathered our three security disciplines : Information Security, Operational Resilience and Physical Security.Our main missions :Monitor the Security Threat Landscape.Define and oversee Security Standards and Strategy implementation across the Group.Drive local security objectives with C-Level executive (COO, CIO, CTO, CFO…) of AXA entities.Ensure the security of AXA GO as an entity, and of AXA GO as a Service Provider.Provide centralized security services and products to AXA entities.Group Security division is divided in 4 main blocks :Corporate functions (Group Mandate) : Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and AwarenessCyber Defense (Group Security services and products provider)GO Security (Security of AXA GO as an entity, and of AXA GO as a Service Provider)Corporate Chief Security Officers (Oversight of entities’ security) : Corporate Centre, European Markets, International MarketsThe department (GO Security)GO Security department mandate, as part of Group Security division, is to secure AXA GO as an entity, and secure AXA GO Products delivered by AXA GO as a Service Provider to other entities of AXA.GO Security department is divided in 5 teams :GO Security OversightGO Security Engineering CoEGO Security Technical Design & Technical AssuranceGO Product Security OfficeGO Security Operational ExcellenceThe team (GO Security Oversight)GO Security Oversight team is responsible ofProtecting the organization's information, technology & physical assets from external and internal threats, such as cyberattacks, data breaches, and malicious insiders.Developing and implementing GO Security security policies, aligned with the Group Security instructions and regulatory requirements.Managing risks related to AXA GO as an entity, with support from Security Engineering CoE team, and report relevant risks in AXA GO Security Risk Committees.Overseeing the planification and execution of the yearly security testing campaign across AXA GODeveloping and implementing security awareness and training programs to ensure AXA GO employees understand their roles and responsibilities in maintaining a secure environment.Ensuring compliance with Group Security instructions and regulatory requirements, supervising primary assurance on AXA GO as an entity, supporting Primary Assurance activities for AXA GO as a Service Provider, and reporting to Group Security with adequate level of data accuracy.Developing and maintaining business continuity policies, Business Continuity plans and exercises to ensure AXA GO can respond effectively to incidents and maintain business operations in the event of a disaster.Overseeing physical security of AXA GO sites (offices, data centers) and people (travels, events).Prioritizing / managing the remediation of audit issues owned by GO Security Oversight.About the jobMain missionsReporting to GO Security Oversight Executive Manager , the Information Security Lead Expert leads the development and implementation of the end-to-end strategic approach to Information Security.Your responsibilities include :Support the GO Security Oversight Executive Manager in achieving GO Security Oversight team’s objectives.Manage the delivery / update of GO Security Policies :Plan the yearly development / update of GO Security Policies, in alignment with Group Security Instructions, Security risks assessments (entity, product) and feedbacks issued from internal and interested parties. GO Security Policies will comply with global laws / regulations and industry best practices, while balancing the requirements of an agile workforce and a secure environment.Lead and coordinate different teams to write / update Security policies, with the aim of getting validated Security Policies delivered by GO.Organize and facilitate information security policy stakeholder meetings to align policy and control objectives to the organization, in synchronization with synchronized with Information Security control framework.Communicate new / updated policies and spread general awareness about policy set among employees.Plan, coordinate, and execute security policies presentations to main operational teams.Gather and maintain artifacts to prepare for audits.Manage the Security awareness inside GOoEnsure that GO Security awareness strategy is aligned with Group Security Awareness StrategyoDeliver an annual awareness strategy plan for AXA GOoExecute and communicate continuously all related actions defined in the GO awareness strategy plan to all AXA GO employees as GO Security Policies, GO newsletters, news in ONE, videos, webinars, eLearning modules in YES LEARNING or LinkedIn, security events like Security Month in October, Phishing awareness, ...oMonitor continuously any awareness actions that can be tracked.Manage the Internal Security requests :oAnswer requests within the GO Security mailboxoHandle DLP alerts / incidents from GO employeesManage the GO Security / Security DeskoExecute first criticality assessment of new assets in the GO project management process with involvement of Information Security / Physical Security / Operational Resilience / Security Architecture / Data Privacy / Operational Risk teams,oDeliver evidences collection for primary assurance purpose (entities requests)Manage the GO as an entity security risksoManage security risks related to AXA GO as an entity, with support from GO Security Engineering Center team, and report relevant risks in AXA GO Security & Information Risk Committee.oUpdate AXA GO Most Valuable Data list on a yearly basisOversight of the CyberDefense / Pentest execution teamoEnsuring right funding is allocated for continuous pentestingoPrioritizing assets to be pentested in continuous pentesting (DAST included)oMonitoring campaign of pentestsoConfirm criticality of vulnerabilities raised during pentesting activityoEnsuring the remediation of issues detected in pentestsoReporting to Group SecurityoPerforming primary assurance on pentesting / remediationAutomate Internet Facing compliance with Group standardsoEnsure Digital Hub completeness & information accuracy by§Regularly review declared assets to check if they are still live & information provided is accurate§Search for undeclared assetsoMonitor AXA GO Bitsight score (all Internet Facing assets), & improve score by monitoring remediation on vulnerabilities detectedManage S1 / S2 Security Incidents & Critical / High / Medium Security ThreatsMeasuring impact on AXA GOCoordinating with IT & Security teams remediation / mitigation if impact confirmedCommunicating towards entities on AXA GO remediation / mitigation plan progressesOn Medium Security Threats , measuring impact on AXA GO depending on volumes impactedContribute to the remediation of audit issues on Information Security perimeterYour ProfileExpected skills & experienceWe are looking for someone with the following experience and skills :ExperienceUniversity degree in Security Management, Information Security, IT or related field.Information Security and / or Information Technology industry certification (ISC2 CISSP, ISACA CISM or equivalent) strongly is necessaryExperience >10 years.Relevant experience as a team lead (>5 years)Strong experience in Information Systems Security ManagementStrong experience in project management and multi-team coordination.Technical skillsProficiency in information security technologies, including intrusion detection systems.Experience in managing security incidentsFamiliarity with audit tools and the ability to examine technical evidence in depth.Soft skills / transversal skillsAbility to effectively operate in a decentralized and political corporate environment.Ability to function effectively in a matrix structureStrong communication skills to collaborate and interact with various stakeholdersExcellent time management skills (tight deadlines).Ability to prioritize activities and to manage action plans, review progress and adjust where required.Good analytical skills and the ability to clearly identify key issues.Ability to recommend solutions relevant to the complexity, scope, risk and magnitude of problems impacting the service level.Strong program / project management.Fluency in English is a necessityFluency in French is an advantageAbout AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working with 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture ofrespect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.About the EntityAXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.At AXA Group Operations, we want to be recognized in three fields of action :State-of-the-art Data Technology to drive customer experienceState-of-the-art Procurement & Sourcing to drive efficiency and better manage risksHigh-Performing Global Team for stronger partnerships with AXA entitiesWhat We OfferWe bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity &Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued. #J-18808-Ljbffr


  • Lead Security Engineer

    il y a 2 jours


    France Nabla Technologies Temps plein

    About Nabla We are a team of entrepreneurs, clinicians and engineers committed to bringing back joy to the practice of medicine. Together with a community of clinician innovators, we've harnessed the best of machine learning science to develop Nabla: the leading AI assistant that's restoring the human connection at the heart of healthcare. By streamlining...

  • Information Security Officer

    il y a 2 semaines


    Rue du Professeur Langevin, Lille, France Decathlon Digital Temps plein

    Notre équipe Corporate Operations Finance recherche un·e Security Officer basé·e à Lille.Au cœur de la direction financière du groupe Decathlon, nos équipes Corporate Operations Finance (plus de 60 coéquipiers) conçoivent, déploient et assurent le bon fonctionnement de 50 solutions informatiques.Ces solutions permettent :aux équipes Finance...

  • Security Architect

    il y a 2 jours


    France Spektrum Temps plein

    Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. Background: eu-LISA is the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) manages large-scale...


  • Boulevard de Strasbourg, Toulouse, France Loft Orbital Temps plein

    Wanna Join the Adventure?With the company expanding into defense for both the US and EU, Loft Orbital is seeking an experienced Security & Compliance Team Lead to lead and scale our company's goal of increasing our security standings across the commercial product offering. This role balances hands-on technical leadership (75%) with strong functional and...


  • France Nabla Technologies Temps plein

    A leading healthcare technology company is seeking a hands-on lead security engineer to develop and manage their security engineering function. This role involves collaborating closely with the Head of Security and IT to ensure robust infrastructure and application security within a fast-scaling startup environment. Candidates should have extensive...


  • Rue du Professeur Langevin, Lille, France Decathlon Digital Temps plein

    Notre équipe Cybersécurité recherche un·e Security Officer Senior basé·e à Lille ou Paris.L'équipe Cybersécurité Decathlon assure la protection et la sécurisation de l'ensemble du groupe : elle pilote la stratégie de gouvernance et les processus de gestion du risque, s'assure de la conformité de nos systèmes d'information, définit les moyens...

  • Security Expert

    il y a 24 heures


    Rue du Professeur Langevin, Lille, France Decathlon Digital Temps plein

    Notre équipe Cyber-sécurité recherche un·e Security Engineer Senior basé·e à Lille ou Paris.L'équipe Cybersécurité Decathlon assure la protection et la sécurisation de l'ensemble du groupe : elle pilote la stratégie de gouvernance et les processus de gestion du risque, s'assure de la conformité de nos systèmes d'information, définit les moyens...


  • Rue Anatole France, Levallois-Perret, France Devoteam Corporate Temps plein

    Company Description Devoteam is a leading consulting firm focused on digital strategy, tech platforms and cybersecurity.By combining creativity, tech and data insights, we empower our customers to transform their business and unlock the future.With 25 years' experience and +10,000 employees across 20 countries in Europe, Middle East, and Africa Devoteam...


  • Pl. Nelson Mandela, Nanterre, France VusionGroup SA Temps plein

    Description de l'entreprise Are you ready to develop the future of retail?  VusionGroup est une entreprise de retail tech en forte croissance. Implanté dans 19 pays sur 3 continents, nous sommes leader mondial des solutions de digitalisation du commerce physique.Nous inventons des technologies qui créent un impact positif sur la société en permettant...


  • France BetterHelp Temps plein

    A leading mental health service is looking for an Application Security Engineer to enhance their Application Security Team. The role involves leading security initiatives, performing code reviews, and collaborating with various teams to ensure optimal security practices. Candidates should have strong technical abilities, experience with security tools like...