Security Risk Expert
Publication date:
05 October 2024Workload:
100%Contract type:
Unlimited employment- Place of work:Zug
JOB ENVIRONMENT
With over 102 million customers in 56 countries, AXA's strong global franchises and three lines of expertise - Property & Casualty, Life & Savings and Asset Management - provide a distinctive business portfolio. As a company whose business is to protect people, we have a responsibility to leverage our skills, resources and risk expertise to build a stronger and safer society. To achieve our mission, we are committed to redefining the standards of our business so that we truly differentiate ourselves and earn the trust of our key stakeholders.
As an integral part of AXA, at AXA Group Operations (AXA GO) we create innovative technology and data solutions to help AXA fulfill its ambition of being a customer-focused, tech-led company. AXA GO is a young and dynamic division launched in 2019 and comprises 8,000 employees across 17 countries all around the globe from Paris, France to Pune, India. We are the ones providing advice, steering technological choices and giving AXA access to innovations that will support its transformation into a customer-centric tech-led company. For this, we work in close partnership with all AXA entities.
PRESENTATION OF THE CONTEXT AND AXA GROUP SECURITY
Throughout AXA, the security community represents 1000 security professionals, working daily to protect our employees, customers, operations and brand. Our operating model gathers the three security disciplines Information Security, Operational Resilience and Physical Security & Safety. Our security mission is to ensure that AXA is safe, secure and resilient.
AXA Group Security, as part of AXA GO, defines the security strategy, standards and provides assurance to the Group on the security maturity of all entities across AXA. In its role, it also supports our professional family in entities in maintaining their security posture and respond and coordinate responses to crisis.
This is accomplished through four strategic levers:
· Safe: It is about our people, have them ready to face security challenges including third parties, health professionals
· Secure: Secure the business of today and tomorrow, by increasing security effectiveness on a risk-based approach for all entities.
· Resilient: Enhance anticipation, detection and reaction capabilities in case of events & Security by design
· Simple: Simplify, converge and automate our services and activities
PRESENTATION OF THE GROUP SECURITY RISK TEAM
The Security Risk team ensures that AXA is identifying, monitoring, and prioritizing its key security risks, across our three security disciplines.
Security risk which encompasses Information Security, Operational Resilience and Physical Security risks plays a key role in AXA’s security ambition of securing the customer journey and delivering resilient services to our customers. You will be part of a highly dynamic global team, working closely with Group executives, security management teams and the Chief Security Officers who’s operating companies from around the world. Our team is responsible for the security risk framework and vendor security risk framework.
Our main missions are to:
- Define the requirements and capabilities to perform security risk management and vendor security risk
- Support the risk reduction and prioritization of security activities
- Monitor key security risks for the Group and communicate to interested parties
- Develop and sustain Security Risk Management maturity and risk awareness
- Be a privileged advisor to support Business in taking risk driven decisions
Our goals are to:
- Design, maintain and improve a converged Security Risk framework and associated methodologies / tooling. This includes entity based risk assessments, asset based risk assessments and vendor security risk assessments
- Provide training and support to our Entities in the implementation and improvement of their local Security Risk Management Framework
- Determine the security risk posture of the Group to support strategic initiatives on risk reduction and prioritization
- Maintain and continuously improve Vendor Security, Information Security risk management and Data classification instructions and related frameworks
- Identify and Assess key transversal risks for the Group
- Provide subject matter expertise and advisory on security risk related topics
- Animate our Security Risk Community across our Entities to promote a risk-aware culture
You will be working daily transversally with reinforced interaction and co-construction.
Your stakeholders
· Internally: you will interact with AXA Group Risk & Internal Audit, IT Leadership & Business Leadership, Group Compliance & Legal, IT Operations & Business Operations, Local/Regional CSO and Security team members
· Externally: Expected to interact with external third parties
Your Certifications
Security and/or Information Technology industry certification (ISO 27001 (Implementer/Auditor), ISO 22301 (Implementer/Auditor), CISSP, CRISC, CISA, CISM or equivalent) preferredYour Profile
PROFILE
Education
- Bachelor degree in Computer Science, Engineering, or related field
- A specialty in Risk, Information Security, Operational Resilience, Physical Security and Health & Safety is highly recommened
Certifications
- Information Security and /or Information Technology industry certifications in good standing (CRISC, CISSP, CISM, ISO27005 Certified Risk Manager, ISO27001 Lead Auditor, ISO22301 Lead Auditor ) strongly preferred
- CBCI & Physical Security certifications are desirable
Overall work experience in the field
- Experience in articulating security risks in business language and advising on the appropriate risk management strategy > 5 years
- Experience in Information Security field > 5 years
- Experience in Operational Resilience > 5 years
- Experience in Physical Security / Health & Safety > 5 years
Skills / abilities
About AXA
- Ability to function effectively in a matrix structure
- Resilient capacity
- Ability to manage uncertainty
- Proficient risk assessment, interpretation, and analytical skills
- Strong networking skills
- Team player
- Fluent in English
As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working with 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture ofAbout the Entity
respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:
What We Offer
- State-of-the-art Data Technology to drive customer experience
- State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
- High-Performing Global Team for stronger partnerships with AXA entities
We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.