Information Security Expert

hace 1 mes


Madrid, Madrid, España AXA Group A tiempo completo

Context

The Security Consultant plays an integral role in defining and assessing security requirements, security strategy and practices for Group Security and AXA global projects and clients. The security consultant will be required to effectively translate business objectives and risk management strategies into specific security requirements and processes enabled by security technologies and services.

The role will involve communicating regularly with key stakeholders globally in the AXA business. This role will report into the Information Security Executive Manager of Information Security team within Group Security.

The Role

  • Develop and maintain a security requirement gathering and maintenance process that is clearly aligned with business, technology and threat drivers
  • Develop and maintain security artefacts (e.g., models, templates, standards and procedures) that can be used to leverage security capabilities in projects and operations
  • Act as an advisor and authority on security requirements
  • Contribute at ideation and design project phases from a Group Security perspective for global projects and programmes
  • Ensure security requirements are taken into account in the architecture design
  • Participate in key projects in order to independently provide security requirements, assess the risks and ensure appropriate risk mitigation has been taken
  • Responsibility for providing input to the audit closure issues
  • Work closely with Technology Office, Internal Audit, Risk Management, Information Security Assurance teams in Group Security and other global stakeholders to maintain compliance to Group Security, regulatory and industry requirements
  • Liaison with AXA information protection stakeholders to progress internal risk and security sign-off
  • Support the development of security technology innovation roadmap
  • Track developments and changes in the digital business and threat environments to ensure that they're adequately addressed in security strategy plans and security artefacts developed for AXA
  • Validate cloud infrastructure and other reference architectures for security best practices and recommend changes to enhance security and reduce risks, where applicable
  • Review security technologies, tools and services, and make recommendations to the broader security team for their use, based on security, financial and operational metrics
  • Liaise with other security teams and security practitioners to share best practices and insights
  • Provision of assessment reports to the management team with clearly documented findings, recommendations and agreed management action plans
  • Provide subject matter expertise on policy, standards and processes for Information Security
  • Providing deep technical knowledge as well as ensuring a repository for this knowledge is built and maintained
  • Documentation creation and review
  • Role model for other staff, demonstrating effective governance arrangements are maintained
Your Profile

Candidate Profil

Must-have skills

  • Proven experience creating and maintaining security requirements for medium to large enterprise
  • Experience of modern application security practices like DevSecOps
  • Experience in using architecture methodologies such as SABSA and TOGAF
  • Good experience and technical understanding of Public and Private Cloud technologies such as AWS, Azure, Google Cloud Platform (GCP) and VMware
  • Core security capabilities in the cloud focus on native tooling in IaaS, PaaS and SaaS as well as capabilities like cloud access security brokers (CASBs), cloud workload protection platforms (CWPP) and cloud security posture management (CSPM)
  • Proven experience the following:
    • Cloud Security: Protect IaaS, PaaS and SaaS with native security features along with third-party security solutions and cloud risk management
    • Infrastructure Security: Protect infrastructure, including secure email gateways, secure web gateways, and other collaboration tools and web security technologies
    • Network Security: Keep pace with hybrid cloud architectures with modern network firewalls and technologies like zero trust architecture, microsegmentation, network access control, ZTNA, and NDR, and protect infrastructure from DDoS attacks
    • Act as Encryption SME for relevant IT and security functions
  • Familiarity with compliance & security standards across the enterprise IT landscape
  • Strong understanding of enterprise risk management methods and techniques to drive successful outcomes in a federated environment
  • Experience of working with internal teams and partners to translate business needs into security requirements
  • Experience of assessing the risk profile of software solutions, understanding how these have evolved with modern, agile development and deployment practices
  • Experience / knowledge of Information Security accreditations with a cloud-focus such as NIST Cyber Security Framework, ISO 27017/18, CSA Star and ISO27001
  • Excellent verbal and written communication skills
  • Possess strong leadership skills with experience of shaping, motivating and driving change
  • Strong influencing and negotiation skills
  • Engages in order to drive the right commercial and technological outcome
  • Ability to build credibility with peers and customer

Preferred Skills

  • Experience and working knowledge of the methodologies to conduct threat-modelling exercises on new applications and services.
  • Experience of security assessments applications and infrastructure into public cloud services.
  • Strong and demonstrated team working experience
  • Persuasive power to communicate with a variety of stakeholders in the organization
  • Creative problem-solving ability, working in ambiguous situations
  • Entrepreneurial & pragmatic mind-set
  • Experience delivering pragmatic security requirements aligned to varying degrees of risk appetites
  • Comfortable with frequent, incremental testing and deployment (Agile methodologies)
  • A strong focus on business outcomes
  • Comfort with collaboration, open communication and reaching across functional borders
  • Strong educational background with a degree preferably in Computer Science or related
  • Have superior planning and organization skills so as to work with a high-performance team, handle demanding clients and multitask effectively
  • High degree of personal motivation and ability to self-manage
  • Experience building enterprise security strategy for cloud adoption or driving the program's evolution to meet new requirements

Preferred Qualifications

  • CISSP, CISM, CCSP
  • CCP, SANS - GIAC
  • TOGAF or SABSA Certification
  • AWS/Azure/GCP Solutions Architect
  • Microsoft Certification (MCM or MCA)
  • VMWare Cloud Hosting (VCP or Higher)
  • Networking Certification (CCNA or similar)
About AXA

As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working with 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of
respect, for each other, for our customers and the communities around us. Join AXA and you'll feel like you belong, are included and can thrive. You'll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.

About the Entity

AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.

We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.

We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.

At AXA Group Operations, we want to be recognized in three fields of action:

  • State-of-the-art Data Technology to drive customer experience
  • State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
  • High-Performing Global Team for stronger partnerships with AXA entities

What We Offer

We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we're committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.



  • Madrid, Madrid, España GrabJobs A tiempo completo

    Security Architect en Barcelona. Perfil buscado (Hombre/Mujer) Support the development of security architectures including defining target states transition plans and roadmaps in alignment with business objectives and IT strategies.Offer direction guidance and collaborate with infrastructure application architecture teams and solution architects to ensure...


  • Madrid, Madrid, España Bravent A tiempo completo

    ¿Qué es BRAVENT?Somos una empresa especializada en tecnologías Microsoft donde premia la innovación y, sobre todo, el entorno colaborativo.El trabajo en equipo, el compañerismo y la flexibilidad son los pilares en los que se fundamenta nuestro día a día.Nuestra pasión por las últimas tecnologías nos lleva a estar en continua innovación, para así...


  • Madrid, Madrid, España serem. Consultoría empresarial A tiempo completo

    Desde Serem nos encontramos en la búsqueda de un Chief Information Security Officer (CISO) con más de 3 años de experiencia para importante proyecto en Madrid.Formación:Se valorará formación académica en Informática/Seguridad y/o certificado ISO 27001 Lead Auditor, CISA, CISSP, CISM.Requisitos del perfil:Gran conocimiento en estándares y...


  • Madrid, Madrid, España ING A tiempo completo

    At ING we are looking for a Information Risk Management (IRM) ExpertYour role and work environment:We are looking for a talented and enthusiastic IRM expert to join our Regional Information Risk Management Team in Spain (RegIRM-ES) of Information Risk / Technology Risk.The responsibility of this team is providing direct Information Risk Management (IRM) and...

  • SAP Security

    hace 4 semanas


    Madrid, Madrid, España Michael Page A tiempo completo

    ¿Dónde vas a trabajar? Multinational Healthcare Company ¿Qué harás en tu nuevo puesto? The successful candidate will undertake critical duties in the day-to-day operations and management of SAP security solutions, ensuring the safety and integrity of digital assets. In this role, you will navigate the complex landscape of SAP security, juggling user...


  • Madrid, Madrid, España BASF SE A tiempo completo

    ABOUT USAt BASF Digital Hub Madrid we develop innovative digital solutions for BASF, create new exciting customer experiences and business growth, and drive efficiencies in processes, helping to strengthen BASF ́s position as the digital leader in the chemical industry. We believe the right path is through creativity, trial and error and great people...


  • Madrid, Madrid, España Michael Page A tiempo completo

    ¿Dónde vas a trabajar?International Industrial Company ¿Qué harás en tu nuevo puesto? Accountable for the operational management of the company identities and the access authorizations of the IT systems as well as their regular and governance-compliant certification - from conception to implementation and reportingAccountable for the continuous...


  • Madrid, Madrid, España Marriott A tiempo completo

    Job Number Job Category Information TechnologyLocation Madrid Regional Office, Paseo del Club Deportivo 1 Ed. 17, Madrid, Madrid, SpainSchedule Full-TimeLocated Remotely? NRelocation? NPosition Type Non-ManagementPOSITION SUMMARYTroubleshoot and repair technical problems or issues related to computer hardware and peripheral equipment. Respond to program...


  • Madrid, Madrid, España Ibm A tiempo completo

    IntroductionCustomer Success Manager Security Architect is responsible for use cases, deployment, and value realization, as well as upsell opportunities and renewal conversations by driving adoption and client usage of the identified Security products.Your Role and ResponsibilitiesWith deep roots in a hands-on technological background, and through different...


  • Madrid, Madrid, España BASF SE A tiempo completo

    ABOUT USAt BASF Digital Hub Madrid we develop innovative digital solutions for BASF, create new exciting customer experiences and business growth, and drive efficiencies in processes, helping to strengthen BASF ́s position as the digital leader in the chemical industry. We believe the right path is through creativity, trial and error and great people...

  • Security Engineer

    hace 1 mes


    Madrid, Madrid, España Michael Page A tiempo completo

    Perfil buscado (Hombre/Mujer) Desarrollar e implementar estrategias de I+D+i relacionadas con la ciberseguridad. Realizar evaluaciones de riesgo y auditorías de seguridad. Supervisar y coordinar actividades de seguridad. Colaborar con el equipo de tecnología para garantizar la seguridad en los proyectos de I+D+i. Ofrecer formación en seguridad a los...


  • Madrid, Madrid, España BASF SE A tiempo completo

    ABOUT USAt BASF Digital Hub Madrid we develop innovative digital solutions for BASF, create new exciting customer experiences and business growth, and drive efficiencies in processes, helping to strengthen BASF ́s position as the digital leader in the chemical industry. We believe the right path is through creativity, trial and error and great people...


  • Madrid, Madrid, España BASF SE A tiempo completo

    ABOUT USAt BASF Digital Hub Madrid we develop innovative digital solutions for BASF, create new exciting customer experiences and business growth, and drive efficiencies in processes, helping to strengthen BASF ́s position as the digital leader in the chemical industry. We believe the right path is through creativity, trial and error and great people...


  • Madrid, Madrid, España Mastercard A tiempo completo

    Our PurposeWe work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our...


  • Madrid, Madrid, España Mastercard A tiempo completo

    Our PurposeWe work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our...


  • Madrid, Madrid, España Swiss Re A tiempo completo

    Join a team of digital risk governance and security professionals, helping Swiss Re to fulfil its mission in making the world more resilient. As a Senior Deigital Rik Expert , you'lldrive the digital risk governance process by engaging with our customers and advisors in IT and business domains.You will be a key member of the Digital Governance Framework...


  • Madrid, Madrid, España Swiss Re A tiempo completo

    Are you ready to provide mentorship on best practices for Microsoft 365 with regards to Security, Compliance and Government aspects?If yes - we have an outstanding opportunity for YOUAbout the RoleYou would play a central role in all aspects of the Swiss Re Digital Workplace. Be ready to deal with end to end solution design and implementation of new services...

  • SAP Logistics Expert

    hace 3 semanas


    Madrid, Madrid, España GrabJobs A tiempo completo

    Work experience in one or more SAP Logistics areas SAP Sales and Distribution (SD) or SAP Material Management (MM) or SAP Plant Maintenance (PM) or SAP Quality Management (QM). Active participation in SAP projects (implementation, rollout or support / maintenance). Very good knowledge of logistics processes (business user is a plus) and understanding of the...


  • Madrid, Madrid, España Edwards Lifesciences A tiempo completo

    OverviewInnovation starts from the heart. Edwards Lifesciences is the global leader of patient-focused innovations for structural heart disease and critical care monitoring. With millions of patients served in over 100 countries, each team makes a meaningful contribution by improving patient outcomes and discovering lasting solutions for unmet patient needs....

  • Cybersecurity Intern

    hace 2 semanas


    Madrid, Madrid, España Capgemini Invent A tiempo completo

    Do you want to try a different style of consulting? Do you want to work in a dynamic and innovative environment? Join Capgemini Invent, the strategic consulting and digital transformation unit of the Capgemini groupWe are looking for ambitious people who want to start their career with us in the field of consulting in technology directions and in the...