Senior Information Security Compliance Officer
il y a 21 heures
Founded in Marseille in 1966 by Pierre Bellon, Sodexo is the global leader in sustainable food and valued experiences at every moment in life: learn, work, heal and play.
Operating in 45 countries, our 430,000 employees serve 100 million consumers each day. The Sodexo Group stands out for its independence and its founding family shareholding, its responsible business model and its portfolio of activities including Food Services, Facilities Management Services and Employee Benefit Solutions.
Our mission: to improve the quality of life of our employees and those we serve, and contribute to the economic, social and environmental progress in the communities where we operate
.
For Sodexo, growth and social commitment go hand in hand.
Our purpose is to create a better every day for everyone to build a better life for all.
We are looking for a Senior Information Security Compliance expert to join our Global Cybersecurity team and play a key role in ensuring that risk management processes are properly followed across the TDDI function and among business stakeholders.
Your main assignments will be :
- Build an annual consolidated Information Security Compliance Programme that provides the business, IT visibility of internal and external Audit & Assurance activity to allow appropriate demand & resource planning
- Deliver effective Security Compliance reporting to inform Risk & Issue reporting to the CISO, IT & Business Senior Leadership
- Ensure Audit & Assurance actions are managed, tracked, and reported through to mitigation
ISO27001
- Ensure the ISMS is managed and maintained in alignment with the Statement of Applicability and ISO27001/2 framework
- Define requirements for the ISMS, document and implement security policies to develop and maintain the ISMS
- Manage and maintain the ISMS documentation
- Conduct and supervise Sodexo Group's regular audits and review the implemented controls covered by the ISMS scope to align to the business need
- Develop a plan to scale up ISO27001 practices to a wider scope to improve overall security maturity
- Explore opportunities for consolidation of ISMS where practical and appropriate
- Manage ISO22301 compliance improvements and coordinate annual testing requirements
- Build and maintain IT business continuity and the disaster recovery plan aligned to business needs
- Ensure annual recovery testing coordination of IT environment and revise requirements for critical recovery strategy aligns with business requirements
Information Security Third Party Assurance
- Manage and maintain questionnaires within the Third Party Risk Management platform used by internal and external stakeholders, enhancing the product and supporting processes where applicable.
- Conduct risk-based information security due diligence activities against vendors to provide appropriate levels of assurance to key stakeholders
- Enhance Information Security Third Party Assurance processes and engagement activities across IS&T,transversal functions and the wider business
PCI DSS, NIS2, AI Act and relevant regulations
- Coordinate and report on PCI-DSS, NIS2, AI Act compliance programmes to provide direction and assurance of operational controls and meet Sodexo's compliance requirements
Your profile and competencies :
- 6+ years of experience in Information Security and related fields
- Expert knowledge and practical experience of ISO27001 certification requirements and ISMS
- documentation
- Expert knowledge and practical experience in implementing compliance action plans regarding applicable
- regulations (i.e: NIS2, AI Act, PCI-DSS etc)
- Experience of leading and performing internal or external IT audits
- Experience of dealing with third party supplier audits
- Experience of negotiating with stakeholders in designing relevant action plans
- Experience of comprehensive IT internal audit program design and development
- General knowledge of IT environments and technologies
- General Knowledge of Security Architecture or Enterprise Architecture
- Desirable Certifications: CISA, CRISC, QSA, ISO27001 LI, ISO27001 LA.
- Ability to communicate effectively in French and in English, both written and verbally
- Analytical and problem-solving capabilities
- Strong minded
- Rigorous and organised
- Ability to gain Government Security Clearance
What we offer :
Competitive employee benefits
: 13th month salary, works council (CSE), health insurance, 50% reimbursement of public transport subscription, additional leave for family events (wedding, birth, etc.), PERECO ...
Position based in Issy-les-Moulineaux
, easily accessible via Tram T2 and RER C
if you are interested, do not hesitate to apply
-
Senior Security
il y a 10 heures
Paris, France Criteo Temps pleinSenior Security & Compliance Project ManagerYou will need to login before you can apply for a job.OverviewAs a Senior Security & Compliance Project Manager, you will drive key security and compliance initiatives across Criteo. Your role is transversal and strategic: identifying and qualifying risks, defining priorities, aligning stakeholders, and ensuring...
-
Senior Security
il y a 9 heures
Paris, France Criteo Temps pleinWhat You’ll Do: Joining the Trust & Compliance team means stepping into the engine room of security strategy at a fast‑moving tech company. A front‑row seat to how security drives innovation in a data and AI‑driven company. A strong cross‑functional culture: you’ll work with security engineers, architects, product managers, legal, compliance, and...
-
Sr. Information Security Officer
il y a 14 heures
Paris, France un emploi de Security Expert Temps pleinNotre équipe Cybersécurité recherche un·e Security Officer Senior basé·e à Lille ou Paris. L'équipe Cybersécurité Decathlon assure la protection et la sécurisation de l’ensemble du groupe : elle pilote la stratégie de gouvernance et les processus de gestion du risque, s’assure de la conformité de nos systèmes d’information, définit les...
-
Senior Security
il y a 1 semaine
Paris, France Criteo Temps pleinWhat You'll Do:Joining the Trust & Compliance team means stepping into the engine room of security strategy at a fast-moving tech company.A front-row seat to how security drives innovation in a data and AI-driven company.A strong cross-functional culture: you'll work with security engineers, architects, product managers, legal, compliance, and ops.A real...
-
Senior Security
il y a 9 heures
Paris, France Criteo Temps pleinA leading technology company in commerce media is seeking a Senior Security & Compliance Project Manager. This role involves driving security and compliance initiatives, managing risks, and ensuring effective collaboration across teams. The ideal candidate will have a master's degree in a relevant field, significant experience in security governance, and...
-
Senior Security
il y a 1 semaine
Paris, France Weglot Temps pleinUne entreprise tech en pleine croissance recherche un Senior Security & Compliance Officer basé à Paris. Vous serez responsable de la continuité opérationnelle de la sécurité tout en développant la stratégie de sécurité de l'entreprise. Ce rôle exige une solide expérience en sécurité Cloud, idéalement sur AWS, et une bonne compréhension des...
-
Information Security Project Officer
il y a 10 heures
Paris, France AXA Temps pleinJoin to apply for the Information Security Project Officer role at AXA1 month ago Be among the first 25 applicantsJoin to apply for the Information Security Project Officer role at AXAWould you like to wake up every day driven and inspired by our noble mission and to work together as one global team to empower people to live a better life?Here at AXA we...
-
Information Security Specialist
il y a 1 semaine
Paris, France Fast Retailing Temps pleinFast Retailing is a global company that operates multiple fashion brands including UNIQLO, Comptoir des Cotonniers, Princesse Tam Tam, Theory and more. As the world’s third-largest manufacturer and retailer of private-label apparel, the Fast Retailing Group offers high-quality, reasonably-priced clothing by managing everything from procurement, design, and...
-
Defence Compliance Officer
il y a 3 jours
Greater Paris Metropolitan Region, France EGIDE Temps pleinDefense Compliance Officer – FranceLocalisation :Région parisienne - PrésentielSecteur :Défense & technologies souverainesType :CDI – Temps pleinSéniorité :Confirmé / SeniorRémunération :Compétitive selon profil + equity + couverture santé complèteÀ propos d'EGIDEEGIDE développe des architectures de défense aérienne de nouvelle...
-
Security & Compliance GRC Program Lead
il y a 11 heures
Paris, France Criteo Temps pleinA leading technology company in France seeks a Senior Security & Compliance Project Manager to drive key security initiatives. You will lead multi-team projects ensuring compliance with standards like ISO27001 and SOC2. The ideal candidate has a Master's degree in Information Security and strong communication skills. Join a diverse and collaborative...