Security Risk Assessment Analyst
Overview
Join to apply for the Security Risk Assessment Analyst role at AXA Group Operations .
This role focuses on defining and supporting security risk management processes, monitoring key risks, and advising the business on risk-driven decisions. It involves developing a comprehensive security risk framework, providing training, and promoting a risk-aware culture across the Group. Daily collaboration across entities is essential to improve security risk practices and frameworks.
About AXA
As a world-leading insurance company, we act for human progress by protecting what matters. Inclusion and diversity are core values, and we strive to create a culture of respect for colleagues, customers and communities. This is an opportunity to grow your potential while contributing to meaningful work.
About The Entity
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are a major catalyst for this transformation. We drive the evolution of our insurance business model through technology and innovation, delivering globally with high-quality advisory and execution. We operate in 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation globally to achieve scale and synergies as needed.
At AXA Group Operations, we focus on three fields of action:
- State-of-the-art Data Technology to drive customer experience
- State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
- High-Performing Global Team for stronger partnerships with AXA entities
About The Team
The Security Risk team ensures that AXA identifies, monitors, and prioritizes its key security risks across our three security disciplines. Security risk encompasses Information Security, Operational Resilience and Physical Security risks and plays a key role in AXA’s security ambition of securing the customer journey and delivering resilient services. You will be part of a dynamic global team, working with Group executives, security management teams and Chief Security Officers across operating companies. Our team is responsible for the security risk framework and vendor security risk framework.
About The Job
Main Missions
- Define the requirements and capabilities to perform security risk management and vendor security risk
- Support the risk reduction and prioritization of security activities
- Monitor key security risks for the Group and communicate to interested parties
- Develop and sustain Security Risk Management maturity and risk awareness
- Be a privileged advisor to support Business in taking risk driven decisions
Our Goals
- Design, maintain and improve a converged Security Risk framework and associated methodologies / tooling. This includes entity based risk assessments, asset based risk assessments and vendor security risk assessments
- Provide training and support to our Entities in the implementation and improvement of their local Security Risk Management Framework
- Determine the security risk posture of the Group to support strategic initiatives on risk reduction and prioritization
- Maintain and continuously improve Vendor Security, Information Security risk management and Data classification instructions and related frameworks
- Identify and Assess key transversal risks for the Group
- Provide subject matter expertise and advisory on security risk related topics
- Animate our Security Risk Community across our Entities to promote a risk-aware culture
You will be working daily transversally with reinforced interaction and co-construction.
Your Stakeholders
- Internally: you will interact with AXA Group Risk & Internal Audit, IT Leadership & Business Leadership, Group Compliance & Legal, IT Operations & Business Operations, Local/Regional CSO and Security team members
- Externally: Expected to interact with external third parties
Your Certifications
- Security and/or Information Technology industry certification (ISO 27001 (Implementer/Auditor), ISO 22301 (Implementer/Auditor), CISSP, CRISC, CISA, CISM or equivalent) preferred
Expected Skills & Experience
We are looking for someone with the following experience and skills:
Experience
- Experience in articulating security risks in business language and advising on the appropriate risk management strategy > 3 years
- Experience in Information Security field > 3 years
- Experience in Operational Resilience > 2 years
- Experience in Physical Security / Health & Safety > 2 years
Skills
- Ability to function effectively in a matrix structure
- Resilient capacity
- Proficient risk assessment, interpretation, and analytical skills
- Strong networking skills
- Team player
- Fluent in English
What We Offer
We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.
Job Details
- Seniority level: Not Applicable
- Employment type: Full-time
- Job function: Finance and Sales
- Industries: IT Services and IT Consulting