Security Risk Assessment Expert

hace 4 semanas


catalunya, España AXA Group A tiempo completo

About AXA As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can. About the entity AXA is becoming a sustainable tech‑led company and at AXA Group Operations we are one of the major catalysts for this transformation. We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution. We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary. At AXA Group Operations, we want to be recognized in three fields of action: State‑of‑the‑art Data Technology to drive customer experience State‑of‑the‑art Procurement & Sourcing to drive efficiency and better manage risks High‑Performing Global Team for stronger partnerships with AXA entities Where will you be in the organization? The division You will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.). Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience. Our main missions: Monitor the Security Threat Landscape Define and oversee Security Standards and Strategy implementation across the Group Drive local security objectives with C‑Level executive (COO, CIO, CTO, CFO…) of AXA entities Ensure the security of Group Operations as an entity Provide centralized security services and products to AXA entities AXA Group Security is divided in 4 main blocks : Corporate functions (Group Mandate) : Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and Awareness CyberDefense (Group security services and products provider) Group Operations Security (Security of the hosting entity) Corporate Chief Security Officers (Oversight of entities’ security) : Corporate Centre, European Markets, International Markets The department / team The Security Risk team at AXA is dedicated to identifying, monitoring, and prioritizing key security risks across three main disciplines: Information Security, Operational Resilience, and Physical Security. These areas are crucial to AXA's goal of securing the customer journey and providing resilient services. Over the past few years, the focus on embedding risk and related data vectors has been strengthened, making them central to an effective security strategy and program that can measure and quantify risk. The team also manages Vendor Security. As a member of this dynamic and collaborative global team, you will work closely with Group executives, security management teams, security experts, and Chief Security Officers from various operating companies worldwide. The team is responsible for both the security risk framework and the vendor security risk framework. About the job Main missions Defining the requirements and capabilities for security risk management and vendor security risk. Supporting the reduction and prioritization of security activities. Monitoring key security risks for the Group and communicating them to relevant parties. Developing and sustaining Security Risk Management maturity and risk awareness. Acting as a trusted advisor to support business decisions driven by risk. Our goals are to : Design, maintain, and improve a converged Security Risk framework and associated methodologies/tools, including entity‑based, asset‑based, and vendor security risk assessments. Provide training and support to our entities in implementing and improving their local Security Risk Management Framework. Determine the Group's security risk posture to support strategic initiatives on risk reduction and prioritization. Continuously improve Vendor Security, Information Security risk management, and Data classification instructions and related frameworks. Identify and assess key transversal risks for the Group. Offer subject matter expertise and advisory on security risk‑related topics. Foster a risk‑aware culture across our entities through our Security Risk Community. You will work transversally daily, with reinforced interaction and co‑construction as a guiding principle. Your stakeholders Internally: You will engage with AXA Group Risk & Internal Audit, IT Leadership & Business Leadership, Group Compliance & Legal, IT Operations & Business Operations, as well as Local/Regional CSO and Security team members. Externally: You are expected to interact with external third parties. Your Certifications Security and/or Information Technology industry certifications: Preferred certifications include ISO 27001 (Implementer/Auditor), CISSP, CRISC, CISA, and CISM. Other relevant certifications are CEH (Certified Ethical Hacker), CCSP (Certified Cloud Security Professional), and GIAC (Global Information Assurance Certification), Expected skills & experience We are looking for someone with the following experience and skills: Education Bachelor degree in Computer Science, Engineering, or related field An MSc Information Security and Operational Risk Management is strongly preferred Certifications Information Security and /or Information Technology industry certifications in good standing (CRISC, CISSP, CISM, ISO27005 Certified Risk Manager, ISO27001 Lead Auditor or equivalent) strongly preferred CBCI & Physical Security certifications are desirable Overall work experience in the field Experience in articulating security risks in business language and advising on the appropriate risk management strategy > 7 years Experience in Information Security field > 5 years Experience in Operational Resilience > 2 years Experience in Physical Security / Health & Safety > 2 years Skills / abilities Ability to function effectively in a matrix structure Ability to manage uncertainty Operate adequately at senior and executive management level Strong facilitation, negotiation and conflict resolution skills Proficient risk assessment, interpretation and analytical skills Strong networking skills Team player Fluent in English What we offer We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued. #J-18808-Ljbffr



  • catalunya, España Canonical A tiempo completo

    Overview Join to apply for the Security Risk Management Specialist role at Canonical. In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we...

  • Security Engineer

    hace 4 semanas


    catalunya, España GenLayer Labs Corp. A tiempo completo

    YeagerAI is a pioneering AI research lab dedicated to revolutionizing the way humans and artificial intelligence interact. We are operating at the intersection of blockchain technology and AI to build GenLayer, a groundbreaking blockchain that integrates AI in its consensus algorithm to create smart contracts that are intelligent and capable of connecting to...

  • Cyber Security Expert

    hace 4 semanas


    catalunya, España EBRO A tiempo completo

    EBRO SUV, an iconic automotive brand currently undergoing a strategic relaunch and growth, is looking for an Information Security Specialist to strengthen the compliance and cybersecurity area. Responsibilities Support and lead the implementation, monitoring, and continuous improvement of information security management systems (ISO/IEC 27001 and ENS)....


  • catalunya, España Syntax A tiempo completo

    Date: Jan 13, 2026 Location: Barcelona, B, ES, 08022 Functional Area: Remote Competitive, above-average compensation Syntax is a leading Managed Cloud Provider for Mission Critical Enterprise Applications and has been providing comprehensive technology solutions to businesses of all sizes since 1972. Syntax has undisputed strength to implement and manage ERP...


  • catalunya, España Syntax México A tiempo completo

    Enterprise and Security Risk Manager (m/f/d) Location: Barcelona, Catalonia, Spain Join Syntax México, a leading Managed Cloud Provider since 1972. We implement and manage ERP deployments (Oracle, SAP) in secure, resilient private, public, or hybrid clouds. With strong consulting services and world‑class monitoring, we support some of North America’s...


  • catalunya, España Plain Concepts A tiempo completo

    Are you a visionary in cybersecurity strategy and policy? As the Lead AI Security Governance , you will own the AI Security Strategy domain within Plain Security Studios. This pivotal role focuses on the governance and people aspects of cybersecurity in the age of AI. You will develop and enforce frameworks that ensure our AI solutions and those of our...


  • catalunya, España Allianz Services A tiempo completo

    Overview Allianz Services is proud to serve and be part of Allianz Group, one of the world's leading insurers and asset managers. Our global footprint, with more than 8,800 employees located across ten countries and four continents, enables us to unlock value for our partners across the insurance value chain and deliver superior client experience within...


  • catalunya, España Allianz Services A tiempo completo

    Attack Surface Management Expert (m/f/d) at Allianz Services Allianz Services is part of Allianz Group, one of the world’s leading insurers and asset managers. With more than 8,000 employees across ten countries and four continents, Allianz Services delivers superior client experiences and is deeply committed to compassion, integrity, and excellence. Role...

  • Cyber Security Consultant

    hace 4 semanas


    catalunya, España Zurich Insurance A tiempo completo

    Introduction Hi there! I am Álvaro, the recruiter for this position. Nice to meet you! At Zurich Technology Delivery Center (TDC) in Barcelona, we create a collaborative, tech‑driven environment that fosters continuous learning and growth. This role is part of Zurich Insurance Group’s global TDC, focused on software development, data analytics,...


  • Plaza Catalunya, España NTT DATA Europe & Latam A tiempo completo

    NTT DATA es una consultora multinacional que ofrece soluciones tecnológicas, de negocio, estrategia, desarrollo y mantenimiento de aplicaciones, siendo referente en consultoría.Digital Technology es la unidad enfocada a acompañar a las grandes organizaciones iberoamericanas en su transformación digital, generando dividendos digitales a través de la...