Security Risk Assessment Analyst
About the entity
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation. We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:State-of-the-art Data Technology to drive customer experience
State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
High-Performing Global Team for stronger partnerships with AXA entities
About the Team
The Security Risk team ensures that AXA is identifying, monitoring, and prioritizing its key security risks, across our three security disciplines.
Security risk which encompasses Information Security, Operational Resilience and Physical Security risks plays a key role in AXA’s security ambition of securing the customer journey and delivering resilient services to our customers. You will be part of a highly dynamic global team, working closely with Group executives, security management teams and the Chief Security Officers who’s operating companies from around the world. Our team is responsible for the security risk framework and vendor security risk framework.
About the job
Main Missions
Our main missions are to:Define the requirements and capabilities to perform security risk management and vendor security risk
Support the risk reduction and prioritization of security activities
Monitor key security risks for the Group and communicate to interested parties
Develop and sustain Security Risk Management maturity and risk awareness
Be a privileged advisor to support Business in taking risk driven decisions
Our goals are to:Design, maintain and improve a converged Security Risk framework and associated methodologies / tooling. This includes entity based risk assessments, asset based risk assessments and vendor security risk assessments
Provide training and support to our Entities in the implementation and improvement of their local Security Risk Management Framework
Determine the security risk posture of the Group to support strategic initiatives on risk reduction and prioritization
Maintain and continuously improve Vendor Security, Information Security risk management and Data classification instructions and related frameworks
Identify and Assess key transversal risks for the Group
Provide subject matter expertise and advisory on security risk related topics Animate our Security Risk Community across our Entities to promote a risk-aware culture
You will be working daily transversally with reinforced interaction and co-construction.
Your stakeholders Internally: you will interact with AXA Group Risk & Internal Audit, IT Leadership & Business Leadership, Group Compliance & Legal, IT Operations & Business Operations, Local/Regional CSO and Security team members Externally: Expected to interact with external third parties
Your Certifications Security and/or Information Technology industry certification (ISO 27001 (Implementer/Auditor), ISO 22301 (Implementer/Auditor), CISSP, CRISC, CISA, CISM or equivalent) preferred
Expected skills & experience
We are looking for someone with the following experience and skills: Experience
Experience in articulating security risks in business language and advising on the appropriate risk management strategy > 3 years
Experience in Information Security field > 3 years
Experience in Operational Resilience > 2 years
Experience in Physical Security / Health & Safety > 2 years
Skills
Ability to function effectively in a matrix structure
Resilient capacity
Proficient risk assessment, interpretation, and analytical skills
Strong networking skills
Team player
Fluent in English
What we offer
We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.