Security Risk Assessment Analyst
Job Description
This role focuses on defining and supporting security risk management processes, monitoring key risks, and advising the business on risk-driven decisions
It involves developing a comprehensive security risk framework, providing training, and promoting a risk-aware culture across the Group
Daily collaboration across entities is essential to improve security risk practices and frameworks
About AXA As a world-leading insurance company, we act for human progress by protecting what matters
With 153,000 employees in 54 countries working for 105 million customers, we’ve created a truly dynamic and vibrant community
Inclusion and diversity link closely with our values, and together we’re nurturing a culture of respect, for each other, for our customers and the communities around us
Join AXA and you’ll feel like you belong, are included and can thrive
You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives
This is your chance to build the tomorrow you want
Know you can
About the entity AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution
We are present across 17 countries with committed, highly qualified teams
We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary
At AXA Group Operations, we want to be recognized in three fields of action: State-of-the-art Data Technology to drive customer experience State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks High-Performing Global Team for stronger partnerships with AXA entities About the Team The Security Risk team ensures that AXA is identifying, monitoring, and prioritizing its key security risks, across our three security disciplines
Security risk which encompasses Information Security, Operational Resilience and Physical Security risks plays a key role in AXA’s security ambition of securing the customer journey and delivering resilient services to our customers
You will be part of a highly dynamic global team, working closely with Group executives, security management teams and the Chief Security Officers who’s operating companies from around the world
Our team is responsible for the security risk framework and vendor security risk framework
About the job Main Missions Our main missions are to: Define the requirements and capabilities to perform security risk management and vendor security risk Support the risk reduction and prioritization of security activities Monitor key security risks for the Group and communicate to interested parties Develop and sustain Security Risk Management maturity and risk awareness Be a privileged advisor to support Business in taking risk driven decisions Our goals are to: Design, maintain and improve a converged Security Risk framework and associated methodologies / tooling
This includes entity based risk assessments, asset based risk assessments and vendor security risk assessments Provide training and support to our Entities in the implementation and improvement of their local Security Risk Management Framework Determine the security risk posture of the Group to support strategic initiatives on risk reduction and prioritization Maintain and continuously improve Vendor Security, Information Security risk management and Data classification instructions and related frameworks Identify and Assess key transversal risks for the Group Provide subject matter expertise and advisory on security risk related topics Animate our Security Risk Community across our Entities to promote a risk-aware culture You will be working daily transversally with reinforced interaction and co-construction
Your stakeholders Internally: you will interact with AXA Group Risk & Internal Audit, IT Leadership & Business Leadership, Group Compliance & Legal, IT Operations & Business Operations, Local/Regional CSO and Security team members Externally: Expected to interact with external third parties Your Certifications Security and/or Information Technology industry certification (ISO 27001 (Implementer/Auditor), ISO 22301 (Implementer/Auditor), CISSP, CRISC, CISA, CISM or equivalent) preferred Expected skills & experience We are looking for someone with the following experience and skills: Experience Experience in articulating security risks in business language and advising on the appropriate risk management strategy > 3 years Experience in Information Security field > 3 years Experience in Operational Resilience > 2 years Experience in Physical Security / Health & Safety > 2 years Skills Ability to function effectively in a matrix structure Resilient capacity Proficient risk assessment, interpretation, and analytical skills Strong networking skills Team player Fluent in English What we offer We bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.