Security Tools Expert – DLP | MFA | WAF | DAST
Role Purpose:
Own and optimize the end-to-end lifecycle of DLP, MFA, WAF, and DAST tooling
to protect international insurance operations. Design, implement, and operate
these controls across cloud and on-prem environments, ensuring regulatory
alignment (GDPR, cross-border data transfer rules, and relevant
insurance/privacy standards) while enabling secure business delivery.
Key Responsibilities
-
Implementation & Deployment
-
Deploy and integrate DLP, MFA, WAF, and DAST in multi-cloud and on-prem
environments by leveraging AXA Group Operations - Cyber Defense Products
-
Create secure baselines and scalable rule sets tailored to international
data flows and regional requirements.
-
Operations, Tuning & Monitoring
-
Monitor tool health, tune rules/policies, manage false
positives/negatives, and support incident response using tool data.
-
Develop runbooks and escalation paths; contribute to continuous
improvement of detection capabilities.
-
Vendor (AXA GO - Cyber Defense) & Stakeholder Engagement
-
Interact with AXA GO CD products team and PMs, licensing, and roadmap
discussions; liaise with IT, security, and business stakeholders across
regions.
-
Training & Awareness
-
Provide hands-on guidance and training on tool usage and policy
implications for IT, DevOps, and engineering teams.
-
Metrics & Reporting
-
Define and track KPIs (false positive rate, policy coverage,
time-to-tune, incident response metrics, audit readiness); report to
security leadership.
Required Qualifications
- 4–6 years:
-
Proven, hands-on track record across DLP, MFA, WAF, and DAST in
international/regulated environments.
-
Strong integration experience with SIEM/SOAR, IAM, and CI/CD; ability to own
configurations end-to-end.
-
Knowledge of GDPR and cross-border data transfer considerations;
insurance/privacy regulatory awareness.
-
Certifications such as CISSP, CISM, CCSP, or equivalent vendor credentials.
Preferred Qualifications
-
Experience in the insurance/assurance market or financial services.
-
Familiarity with incident response processes and security operations
metrics.
Key Skills and Competencies
-
Technical:
DLP, MFA, WAF, DAST, IAM, SIEM/SOAR, cloud and on-prem security, data
protection, policy design, automation.
-
Tools & Technologies:
DLP platforms, MFA solutions, WAFs, DAST tools; SIEM/SOAR; cloud providers.
-
Soft Skills:
clear communication, cross-functional collaboration (IT, DevOps,
risk/compliance), problem-solving, and attention to regulatory detail.
Performance Metrics (KPIs)
-
Time-to-configure new policies and features, policy coverage across regions.
-
False positives/negatives and mean time to tune.
-
Tool reliability and uptime; alignment with audit requirements.
-
Incident detection/response effectiveness using tool data.
-
Audit readiness and quality of evidence provided.