Operations Security Specialist
Role details
Job location
Tech stack
Job description
You will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).
Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience. Our main missions:
- Monitor the Security Threat Landscape
- Define and oversee Security Standards and Strategy implementation across the Group
- Drive local security objectives with C-Level executive (COO, CIO, CTO, CFO…) of AXA entities
- Ensure the security of Group Operations as an entity
- Provide centralized security services and products to AXA entities
AXA Group Security is divided in 4 main blocks :
-
Corporate functions (Group Mandate) : Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and Awareness
-
CyberDefense (Group security services and products provider)
-
Group Operations Security (Security of the hosting entity)
-
Corporate Chief Security Officers (Oversight of entities' security) : Corporate Centre, European Markets, International Markets
About the job Job purpose You collaborate with the Local Operations Security Leader, local entity CISOs team and other local stakeholders as necessary to ensure that information security across the local entity is relevant and cost-effective. You serve as a senior security expert to Group Operations and to management of the entities in the implementation and maintenance of information security. Main missions
- Operate and maintain vulnerability management and policy compliance scanning tool
- Perform and improve vulnerability management processes as well as ensure remediation and mitigation actions are appropriately implemented
- Evaluate the impact of security threats, risks, vulnerabilities, and processes and provide solutions including current security trends
- Advise IT departments for remediation of vulnerabilities as well as hardening measurements based on the state of the art
- Identify and define system security standards to enable other departments to implement appropriate level of information security
- Perform password weakness scans and password complexity checks
- Define requirements and perform security assessments for projects and applications
- Effective communication with varying audiences at multiple levels of the organization to foster and promote Information Security
Requirements
Do you have experience in Information security?, 3 years in Security Operations context Technical skills Incident and vulnerability management, security tools and investigation technics. Soft skills / transversal skills Autonomy, think out of the box, communication with C-levels, clear communication