Technical Design & Technical Assurance Manager
Publication date:
20 October 2024Workload:
100%Contract type:
Unlimited employment- Place of work:PARIS
About AXA
As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.
About the entity
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:
· State-of-the-art Data Technology to drive customer experience.
· State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks.
· High-Performing Global Team for stronger partnerships with AXA entities.
Job position pitch
The Technical Design & Technical Assurance Manager plays a critical role in bringing specialized expertise and managing the team bringing higher technical skills in Security architecture to GO Security teams (Product Security Office, Engineering Center). He or she ensure complex projects from AXA GO meet security standards, participating to the definition of compliance and security controls for products.
Technical Design & Technical Assurance Manager is also responsible of the team executing technical assurance to asses the effectiveness of Security controls in GO Products
Where will you be in the organization?
The division
You will join the Group Security division, defining the security standards to be applied by AXA entities, overseeing the overall security posture across the Group and providing centralized services to support entities (Crisis Management, Security Operations Centre, etc.).
Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience.
Our main missions:
· Monitor the Security Threat Landscape.
· Define and oversee Security Standards and Strategy implementation across the Group.
· Drive local security objectives with C-Level executive (COO, CIO, CTO, CFO…) of AXA entities.
· Ensure the security of Group Operations as an entity.
· Provide centralized security services and products to AXA entities.
AXA Group Security is divided in 4 main blocks:
· Corporate functions (Group Mandate): Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and Awareness
· CyberDefense (Group security services and products provider)
· Group Operations Security (Security of the hosting entity)
· Corporate Chief Security Officers (Oversight of entities’ security): Corporate Centre, European Markets, International Markets
The department / team
Group Operation Security (GO Security) mandate, as part of AXA Group Security division, is to Secure AXA GO as an entity and secure GO Products delivered by AXA GO as a Service Provider to other entities of AXA.
About the job
Job purpose
As the GO Security Technical Design & Technical Assurance Manager, you will hold a highly strategic role within the AXA GO Security Leadership team.
Your main objective is to lead the team in charge of Security Design & Technical Assurance activities making sure security controls are implemented accordingly to security requirements and validated patterns.
You are responsible for managing technical knowledge, defining controls on complex products, and reviewing technical evidence. Your expertise will be crucial to ensure the robustness and security of our company’s IT solutions. Your team will support GO Security teams, especially Product Security Office and GO Security Engineering Center team, on complex projects and complex products security related deliverables.
Define and Maintain Technical security pattern library, and knowledge base; aligned with Group Architecture, GO Security Policies, and Standard GO Cyber Defense Products
GO Security Technical Design & Technical Assurance Manager will be the reference of GO Security in front of other highly technical stakeholders (CTO, GTO, Group Security Information Security, Cyber Defense Technology Design, etc.)
As a key member of the AXA GO Security Leadership team, you will contribute significantly to the definition of the overall security strategy, budget planning, resource allocation and GO Security governance. Your insights and leadership will be critical in shaping the direction and priorities of GO Security at the highest levels of the organization.
Main missions
Your responsibilities include:
GO Security Leadership Team
o Contribute to AXA GO Security Strategy definition in line with AXA GO Vision and Mission.
o Ensure effective allocation of resources, budget management, and prioritization of projects within the GO Security to maximize overall organizational impact and value.
o Support the implementation of coordinated responses to security audit and compliance issues.
o Serve as an expert advisor to the management of GO in the implementation and maintenance of the security measures in an evolving environment.
o Leading and facilitating cross-functional collaboration and communication across different departments and teams.
o Fostering innovation and best practices by promoting knowledge sharing and continuous improvement across the organization.
GO Security Technical Design
o Lead the team of experts working on technical design.
o Own the GO technical security pattern library, and knowledge base.
o Evaluate the security design of the architecture, including network, application, and data security measures for complex projects and products.
o Define of new security controls for complex products in coordination with GO Security Engineering Center team and GO Cyber Defense teams; aligned with industry best practices and the organization's security policies.
o Provide recommendations for improving the security posture of the architecture, including potential remediation actions and risk mitigation strategies.
o Define specific Security Assurance Plan for complex products and projects in coordination with GO Security Engineering Center team.
o Assess the security of proposed technical architecture of complex projects.
o Management of the team to maintain cutting-edge expertise.
GO Security Technical Assurance
o Lead the team of experts running technical assurance activities.
o Run technical assurance on products on standard patterns. As an example, verify that proper encryption, authentication, and authorization mechanisms are in place to protect sensitive data and systems.
o Review technical evidence review on complex products in coordination with GO Security Product Security team.
o Run assurance on AXA Minimum Technical Security Baseline to improve reporting accuracy.
o Maintain a set of security tools for technical assurance activities.
Run technical assurance of SAF per product critical technical controls.Your Profile
PROFILE
We are looking for someone with the following experience and skills:
Experience
· University degree in computer science, information security, systems architecture, or related field.
· Experience > 10
· Significant professional experience in the design and evaluation of security architectures.
· Strong experience in security management, including compliance with industry standards such as ISO 27001 and security best practices.
· Experience in vulnerability remediation.
Technical skills
· Extensive expertise in security architecture, with in-depth knowledge of principles and best practices.
· Familiarity with cloud technologies and services, as well as associated security tools.
· Ability to define appropriate security controls for complex solutions and assess their effectiveness.
· Familiarity with audit tools and the ability to examine technical evidence in depth.
Soft skills / transversal skills
· Strategic Mindset to see ahead of future needs while dealing with fast evolving environment.
· Leadership skills to manage and guide teams to align the security initiatives with corporate objectives in an uncertain environment.
· Excellent communication skills allowing to manage a team of 10 to 20 people organized in several sub teams (assertiveness, empathy, listening oriented, etc.) while creating a positive and engaging climate.
· Resourceful skills to address complex situations and interactions.
· Analytical thinking and ability to solve complex security-related problems.
· Ability to work independently and manage multiple tasks simultaneously.
· Ability to assist individuals to set goals and supports the execution of the goals through establishing strategy and providing feedback, insight and guidance to enable the individual to reach their fullest potential.
· Ability to work collaboratively with multi-disciplinary teams.
· Ability to plan up to 2-5 years ahead to ensure the successful delivery of outputs, particularly when preparing budget or resources requirements.
· Ability to prioritize activities and to manage action plans, review progress and adjust where required.
· Ability to weigh things up quickly and take the initiative within limits of authority.
· Ability to recommends solutions relevant to the complexity, scope, risk and magnitude of problems impacting the service level.
· Fluency in English is a necessity (including Information Security English).
· Fluency in French is an advantage.About AXA
As a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working with 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture ofAbout the Entity
respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:
What We Offer
- State-of-the-art Data Technology to drive customer experience
- State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
- High-Performing Global Team for stronger partnerships with AXA entities
We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.