Security Risk Assessment Expert

hace 6 días


Madrid, Madrid, España AXA A tiempo completo

del trabajo:About AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you'll feel like you belong, are included and can thrive. You'll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.About the entityAXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.At AXA Group Operations, we want to be recognized in three fields of action:State-of-the-art Data Technology to drive customer experienceState-of-the-art Procurement & Sourcing to drive efficiency and better manage risksHigh-Performing Global Team for stronger partnerships with AXA entitiesWhere will you be in the organization?The divisionYou will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience.Our main missions:Monitor the Security Threat LandscapeDefine and oversee Security Standards and Strategy implementation across the GroupDrive local security objectives with C-Level executive (COO, CIO, CTO, CFO…) of AXA entitiesEnsure the security of Group Operations as an entityProvide centralized security services and products to AXA entitiesAXA Group Security is divided in 4 main blocks :Corporate functions (Group Mandate) : Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and AwarenessCyberDefense (Group security services and products provider)Group Operations Security (Security of the hosting entity)Corporate Chief Security Officers (Oversight of entities' security) : Corporate Centre, European Markets, International MarketsThe department / teamThe Security Risk team at AXA is dedicated to identifying, monitoring, and prioritizing key security risks across three main disciplines: Information Security, Operational Resilience, and Physical Security. These areas are crucial to AXA's goal of securing the customer journey and providing resilient services. Over the past few years, the focus on embedding risk and related data vectors has been strengthened, making them central to an effective security strategy and program that can measure and quantify risk. The team also manages Vendor Security.As a member of this dynamic and collaborative global team, you will work closely with Group executives, security management teams, security experts, and Chief Security Officers from various operating companies worldwide. The team is responsible for both the security risk framework and the vendor security risk framework.About the jobMain missionsDefining the requirements and capabilities for security risk management and vendor security risk.Supporting the reduction and prioritization of security activities.Monitoring key security risks for the Group and communicating them to relevant parties.Developing and sustaining Security Risk Management maturity and risk awareness.Acting as a trusted advisor to support business decisions driven by risk.Our goals are to :Design, maintain, and improve a converged Security Risk framework and associated methodologies/tools, including entity-based, asset-based, and vendor security risk assessments.Provide training and support to our entities in implementing and improving their local Security Risk Management Framework.Determine the Group's security risk posture to support strategic initiatives on risk reduction and prioritization.Continuously improve Vendor Security, Information Security risk management, and Data classification instructions and related frameworks.Identify and assess key transversal risks for the Group.Offer subject matter expertise and advisory on security risk-related topics.Foster a risk-aware culture across our entities through our Security Risk Community.You will work transversally daily, with reinforced interaction and co-construction as a guiding principle.Your stakeholdersInternally: You will engage with AXA Group Risk & Internal Audit, IT Leadership & Business Leadership, Group Compliance & Legal, IT Operations & Business Operations, as well as Local/Regional CSO and Security team members.Externally: You are expected to interact with external third parties.Your CertificationsSecurity and/or Information Technology industry certifications: Preferred certifications include ISO Implementer/Auditor), CISSP, CRISC, CISA, and CISM. Other relevant certifications are CEH (Certified Ethical Hacker), CCSP (Certified Cloud Security Professional), and GIAC (Global Information Assurance Certification),Expected skills & experienceWe are looking for someone with the following experience and skills:EducationBachelor degree in Computer Science, Engineering, or related fieldAn MSc Information Security and Operational Risk Management is strongly preferredCertificationsInformation Security and /or Information Technology industry certifications in good standing (CRISC, CISSP, CISM, ISO27005 Certified Risk Manager, ISO27001 Lead Auditor or equivalent) strongly preferredCBCI & Physical Security certifications are desirableOverall work experience in the fieldExperience in articulating security risks in business language and advising on the appropriate risk management strategy > 7 yearsExperience in Information Security field > 5 yearsExperience in Operational Resilience > 2 yearsExperience in Physical Security / Health & Safety > 2 yearsSkills / abilitiesAbility to function effectively in a matrix structureAbility to manage uncertaintyOperate adequately at senior and executive management levelStrong facilitation, negotiation and conflict resolution skillsProficient risk assessment, interpretation and analytical skillsStrong networking skillsTeam playerFluent in EnglishWhat we offerWe bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we're committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.



  • Madrid, Madrid, España Arcadis A tiempo completo

    Job Title: Environmental Restoration Consultant – Quantitative Risk Assessment  (f/m/d)Locations: Madrid or Barcelona, SpainJob Schedule: Full TimeArcadis is the world's leading company delivering sustainable design, engineering, and consultancy solutions for natural and built assets.We are more than 36,000 people, in over 70 countries, dedicated...


  • Madrid, Madrid, España Arcadis A tiempo completo

    DescriptionJob Title: Environmental Restoration Consultant – Quantitative Risk Assessment  (f/m/d)Locations: Madrid or Barcelona, SpainJob Schedule: Full TimeArcadis is the world's leading company delivering sustainable design, engineering, and consultancy solutions for natural and built assets.We are more than 36,000 people, in over 70 countries,...


  • Madrid, Madrid, España S.A.S. Inc. A tiempo completo

    Governance, Risk, Compliance- Audit Security Advisor- HybridNice to meet youWe're a leader in data and AI.Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers.We're also a debt-free multi-billion-dollar organization on our path to IPO-readiness.If you're looking for a...


  • Madrid, Madrid, España AXA Group Operations A tiempo completo

    About AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our...

  • Cyber Security Expert

    hace 6 días


    Madrid, Madrid, España BNP Paribas CIB A tiempo completo

    Are you ready to join a team of cyber risk experts? ‍‍Can you adapt to a wide variety of technical subjects?Are you passionate about cybersecurity and technology?INDEX Who we are Mission What you'll do What you'll bring Our perks About BNP ParibasWho We AreWe are the IT Production team, responsible for providing IT services to our clients in a secure and...


  • Madrid, Madrid, España Siemens A tiempo completo

    Join Siemens Smart Infrastructure Cybersecurity team as an Application Security Expert and shape how we embed security into every layer of our development and operations ecosystem. You'll work at the intersection of cybersecurity, cloud infrastructure, and DevOps practices—designing and implementing security controls that protect critical infrastructure...

  • Cyber, Risk

    hace 1 semana


    Madrid, Madrid, España Integrity360 A tiempo completo

    Role: Cyber Risk & Assurance ConsultantLocation: Madrid, hybridAbout Integrity360Integrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres...

  • Cyber, Risk

    hace 1 semana


    Madrid, Madrid, España Integrity360 A tiempo completo

    Role: Cyber Risk & Assurance Consultant Location: Madrid, hybridAbout Integrity360Integrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres...


  • Madrid, Madrid, España Tencentra Innovations A tiempo completo

    Role DescriptionThis is a full-time hybrid role for a Quantitative Risk Analyst based in Madrid, providing the flexibility to work remotely part-time. The primary responsibilities include developing, validating, and implementing quantitative models for risk assessment, monitoring market risk, and conducting detailed data analysis. The role involves...


  • Madrid, Madrid, España Aubay Spain A tiempo completo

    Localidad : MadridProvincia : MadridNº Vacantes (puestos) : 1FuncionesEn Aubay buscamos un Security Specialist. Si tienes experiencia sólida en seguridad de aplicaciones, coordinación de pentesting y servicios SAST, y te desenvuelves bien actuando como enlace entre equipos internos y proveedores, esta posición encaja contigo.Descripción del...