About AXA
About the entity
At AXA Group Operations, we want to be recognized in three fields of action:
- State-of-the-art Data Technology to drive customer experience
- State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
- High-Performing Global Team for stronger partnerships with AXA entities
Job position pitch
The Security Technical Design Lead plays a critical role in bringing specialized expertise in Security architecture to GO Security teams (Product Security Office, Engineering Center). He or she ensure complex projects from AXA GO meet security standards, participating to the definition of compliance and security technical controls for products.
The division
Throughout AXA Group, the security community represents composed of 1000 security professionals, working daily to protect our customers, operations, brand and people. To achieve this, we have gathered our three security disciplines: Information Security, Physical Security and Operational Resilience.
- Monitor the Security Threat Landscape
- Define and oversee Security Standards and Strategy implementation across the Group
- Drive local security objectives with C-Level executive (COO, CIO, CTO, CFO…) of AXA entities
- Ensure the security of Group Operations as an entity
- Provide centralized security services and products to AXA entities
AXA Group Security is divided in 4 main blocks :
- Corporate functions (Group Mandate) : Security Advisory and Standards, Security Governance, Security Risk & Assurance, Security Strategy and Awareness
- CyberDefense (Group security services and products provider)
- Group Operations Security (Security of the hosting entity)
- Corporate Chief Security Officers (Oversight of entities’ security) : Corporate Centre, European Markets, International Markets
The department / team
Group Operation Security (GO Security) mandate, as part of AXA Group Security division, is to Secure AXA GO as an entity and secure GO Products delivered by AXA GO as a Service Provider to other entities of AXA.
About the job
Job purpose
As the GO Security Technical Design Lead, your main objectives are to :
- Define and Maintain Technical security pattern slibrary, and knowledge base, ; aligned with Group Architecture, GO Security Policies, and Standard GO Cyber Defense Products
- Perform architecture security reviews for large and risky projects/products supporting GO Security teams, especially Product Security Office and GO Security Engineering Center team
Some example of main topics / technologies: Zero trust, network segregation, Public cloud (AWS & Azure), Containerization (Openshift), Identity and Access management services, API security, security services (A/V, EDR, SIEM…), Artificial Inteligence (AI) integration, Shadow cloud…
Main missions
Your responsibilities include :
- Own the GO technical security pattern library, and knowledge base.
- Evaluate the security design of the architecture and threat models, including network, application, and data security measures for complex projects and products;.
- Define of new security controls for complex products in coordination with GO Security Engineering Center team and GO Cyber Defense teams; aligned with industry best practices and the organization's security policies.
- Provide recommendations for improving the security posture of the architecture, including potential remediation actions and risk mitigation strategies.
Expected skills & experience
We are looking for someone with the following experience and skills:
Expected skills & experience
We are looking for someone with the following experience and skills :
- Experience
- University degree in computer science, information security, systems architecture, or related field.
- Experience > 10
- Significant professional experience in the design and evaluation of security architectures.
- Strong experience in security architecture, including threat modeling, security kill chain or similar, infrastructure technologies, cloud
Technical skills
- Extensive expertise in security architecture, with in-depth knowledge of principles and best practices.
- Familiarity with cloud technologies and services, as well as associated security tools.
- Ability to define appropriate security controls for complex solutions and assess their effectiveness.
Soft skills / transversal skills
- Strategic Mindset to see ahead of future needs while dealing with fast evolving environment.
- Resourceful skills to address complex situations and interactions.
- Analytical thinking and ability to solve complex security-related problems.
- Ability to work independently and manage multiple tasks simultaneously.
- Ability to work collaboratively with multi-disciplinary teams.
- Ability to weigh things up quickly and take the initiative within limits of authority.
- Ability to recommends solutions relevant to the complexity, scope, risk and magnitude of problems impacting the service levels.
- Fluency in English is a necessity (including Information Security English).
- Fluency in French is an advantage.
What we offer