Senior Security Consultant, Information Security
Onshore (UK) 2 days on site in Ipswich
The role will be to augment the Information Security team to act as a SME and key stakeholder on several high-profile programs as well as AXA XL sub-entities. You will provide dedicated support and security related technical expertise to your respective Business Partners to enable the business to deliver safe and secure services.
The role will involve working with key stakeholders and product owners and to understand and guide future program/product plans and security transformation in digital, as well as to perform risk assessments of current product increments, provide guidance and acquire outcomes/decisions from the project managers, enterprise architect, technical architect, solutions architect, data privacy officer, portfolio management office, strategic change development, IT Infrastructure and Operations and penetration testers. The role is transversal, and this may mean supervising different businesses units within AXA XL and those operated at arms-length in a security capacity. Ultimately, this role entails managing relationships, ensuring business partners are kept up to date with security initiatives, whilst supporting them to implement good security. Initiatives can vary from business focused changes to technical security implementations.
DISCOVERyour opportunity
The Senior Security Consultant will work under the responsibility and report into the Senior Program Manager. The responsibilities of the role will include the following:
·Partnering with business units (AXA Climate, Digital Commercial Platform, Angel Risk Management, Global AG, Brooklyn Underwriting, Innovation and Data Analytics, AXA XL Re-Insurance and others) to ensure security is managed effectively and acting as the primary contact point within security.
·Establish governance structure to support these activities.
·Raise awareness of all security activities with understanding of risk impact and reporting.
·Providing Information Security consultancy including advice for; projects, solution design, small changes, audit/assurance and application of security policy, standards, regulation, and good practice.
·Ensure security service review meetings with stakeholders take place, as needed.
·Facilitating consumption of security services.
·Supporting the assessment and interpretation of risk, recommending risk treatment options, tracking, and supporting remediation or acceptance.
·Develop and maintain relationship with key stakeholders and product owners to proactively engage and understand future product roadmaps and to ensure security requirements are considered.
·Review of in-scope project security requirements and evidence provided by the project manager or scrum master to support closure of Secure Project Lifecycle processes where the business units require support.
·Liaise between business units to support development of Risk Acknowledgement and Mitigation Plans (RAMPs).
·Support the Head of Information Security Services and Risk Management in dealing with complex, time dependent activities as and when necessary.
SHARE your talent
We’re looking for someone who has these abilities and skills:
·Bachelor’s degree in computer science, Engineering, or related field with several years of professional experience
·Excellent knowledge of working within an Agile Framework such as SAFe
·Knowledge of working in a DevSecOps environment
·An Understanding of performing project risk assessments
·Experience in performing Information Security technical risk assessments
·Proficient in information security risk and governance frameworks (ISO 27005, EBIOS)
·Ability to effectively communicate and positively influence diverse stakeholders and team members
·Excellent attention to detail and the ability to create clear, concise, and engaging presentations
·Information Security and /or Information Technology industry certification (CISSP, CISM, CRISC, GIAC, CISSP or equivalent)
·Experience in articulating IS risks in business language and advising on the appropriate risk management action
FIND your future
AXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. For mid-sized companies, multinationals and even some inspirational individuals we don’t just provide re/insurance, we reinvent it.
How? By combining a comprehensive and efficient capital platform, data-driven insights, leading technology, and the best talent in an agile and inclusive workspace, empowered to deliver top client service across all our lines of business − property, casualty, professional, financial lines and specialty.
With an innovative and flexible approach to risk solutions, we partner with those who move the world forward.
Inclusion & Diversity