Job Description - IT Security Officer
About the role:
Enter the purpose of the role. Why does it exist?
To work on the security aspects of project delivery across the AXA UK Group,
including but not limited to design, delivery, and building processes to
ensure the controls remain in place into BAU. Working with IT teams across AXA
to achieve secure solutions through assessing risk and building pragmatic
solutions to mitigate those risks within the AXA UK risk appetite.
Key accountabilities & responsibilities
Enter the accountabilities of the role. What are the main things the role
holder needs to do?
-
To liaise with UK CTO and other assigned groups to manage the security
portions of strategic projects, working within the project teams to achieve
goals on time and on budget.
-
To deliver assigned UK Security projects, enhancing our controls and closing
new risks, on time and on budget.
-
To form adhoc cross department teams as required to make decisions that
support project delivery and solve important security problems.
-
Liaise with Group, UK CTO and Operating entity architecture teams, including
Security architecture, to maintain consistency across group strategy, and to
maintain governance over the UK IT Systems.
-
With the UK Security team to provide consultancy on the security aspects of
business goals and plans outside CTO.
-
To build secure solutions which can be measured, for example on Coverage,
Quantity, and Quality metrics, and can be moved into a supportable and
maintainable Business As Usual state.
-
To assist the rest of UK Security producing risk assessments of Group and
3rd party tools and platforms, as required.
-
To provide technical consultancy on 3rd party risk for specific solutions.
-
Act as subject matter expert to the business and to other members of the
Security team as required.
-
Proactively investigate new threats to the business and propose solutions to
address them.
-
Ensure AXA Security Policies are met and maintained, and that new technology
build has a net positive on the controls and risk posture to the UK.
-
Prepare, and when appropriate, deliver oral and written reports to the Head
of UK Security as well as other key senior managers both within Corporate
Centre and the Operating companies.
-
Work with the UK Security team on process redevelopment, working to
streamline processes, and develop new processes that allow us to improve the
efficiency and/or reduce the risk of information security.
Specialist skills & experience
-
Degree Level Education
or equivalent
-
Relevant Professional Qualification
– e.g CISSP, CISM, MIISP desirable but not required
-
Disciplined and organised mind-set with a good attention to detail.
-
Excellent time management skills, including the ability to manage a
demanding and variable workload with tight deadlines.
-
Excellent communication and interpersonal skills, including the ability to
negotiate and resolve conflict.
-
Good analytical skills and the ability to clearly identify key issues.
-
A strong customer focus to ensure internal stakeholder needs are met.
-
Some knowledge and understanding of the issues and key information
requirements affecting the IT environment.
- Project management skills.
-
Excellent Word, PowerPoint and Excel skills.
-
PCI/DSS knowledge
extremely desirable but not required.
-
IFC/SOX knowledge
extremely desirable but not required.
-
Knowledge of FSA regulations
desirable but not required.
-
Knowledge of AXA Group policies
desirable but not required.
-
Knowledge and skills in the following areas
are desirable but not required:
- ITIL
- Cloud Security
- Coding and Scripting
- Application Security
- Big Data
- Architecture
- Networking