Senior Specialist, Agile Security and Risk Management Assessment
AXA, Ipswich
Senior Specialist, Agile Security and Risk Management Assessment
Salary not available. View on company website.
AXA, Ipswich
- Full time
- Permanent
- Onsite working
Posted 1 week ago, 8 May | Get your application in now before you're too late!
Closing date: Closing date not specified
job Ref: 6908403e7d0c4ded9c188813586380f3
Full Job Description
Security Consultant - Project Risk Assessments Ipswich, UK) The Secure Project Lifecycle process has been established to perform risk assessments, ensuring security is considered as part of the design and throughout the project lifecycle. The SPL process governs projects within the Planview time recording and management system and those that are managed outside such as Move to the Cloud (MttC) programme. The role will be to augment the Information Security team to perform risk assessments of projects, provide guidance and acquire outcomes / decisions from the project manager, enterprise architect, technical architect, solutions architect, data privacy officer, project management office, strategic change development, IT Infrastructure and Operations and penetration testers. DISCOVERyour opportunity The specialist will work under the responsibility of the Head of IS Services and Risk Management and will report to the Secure Project Lifecycle Team Lead. The responsibilities of the role will include the following :
- Review submission of IS Criticality Assessment (ISCA) questionnaire (ISCA Dashboard)
- Determine high level security requirements and project criticality, based on standard project activities and data classification from DP pre-screening
- Work with assigned architect to ensure security requirements are finalized in design (High Level Design), review with Enterprise Architecture, Solutions Architecture, Cyber Security and Cyber Assurance
- Review of all security requirements and evidence provided by the project manager to support closure of each requirement : Review and feedback on ISCA questionnaireReview and feedback on High Level Design (HLD)Present at ISCA Project Technical ReviewAttend and obtain HLD sign-off at Technical Design Authority, Solutions Design Authority (SDA) and Data Intelligence and Analytics (DIA)Obtain Third Party Risk Evaluation Platform (TPREP) scorecard for TP SaaS solutions from Security Contracts teamObtain Minimum Technical Security Baseline compliance reporting from QualysGuardObtain Cloud Permit from Enterprise ArchitectureObtain Code Review and Analysis - in house solutions only from SCDSelf-serve vulnerability assessment compliance report of assets in scopeLiaise with Cyber Assurance on penetration testing of solution and obtain sign offObtain Digital Hub registration for external facing solutions from Cyber AssuranceProduce Project Security Assessment closure report
- Perform a final review of all open security requirements and their status before any stage gate approval can be provided (effectively the Production Go / No-go decision). Ensure AXA XL SDLC agile, waterfall and infra waterfall processes are followed
- Store all evidence in IS projects shared area
- Update the project register daily to ensure project status is maintained and update the Project Security Assessment (PSA) template as a record of activity. Submit PSA for sign off to complete risk assessment
- Manage project RAG status ensuring activities trending amber and red are highlighted to management and the project manager
- Liaise with project manager to support the development of the risk acceptance (PM is responsible) where needed
- Attend meetings with project manager, stakeholders, ISCA technical review, architectural design authorities and pen testing reviews. Challenge design decisions not compliant with security, escalate issues when they become known, offer options to resolve All deliverables are subject to an internal quality assurance and peer reviews will be conducted by the Information Security team.
- Bachelor's degree in computer science, Engineering, or related field with a senior level of professional experience (Required)
- Established knowledge of performing project risk assessments (Required)
- Experience in performing Information Security technical risk assessments (Required)
- Proficient in information security risk and governance frameworks (ISO 27005, EBIOS)
- Expert analytical and reporting skills (Required)
- Expert in Microsoft Office (Word, Excel, PowerPoint, Access) (Required)
- Ability to effectively communicate and positively influence diverse stakeholders and team members (Required)
- Excellent attention to detail and the ability to create clear, concise, and engaging presentations (Required)
- Fluent in English (Required)
- Information Security and / or Information Technology industry certification (CISSP, CISM, CRISC, GIAC, CISSP or equivalent) (Required)
- Experience in articulating IS risks in business language and advising on the appropriate risk management action
- Experience in information security management reporting and related methodologies
- Experience in multinational companies (Preferred)
AXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. For mid-sized companies, multinationals and even some inspirational individuals we don't just provide re / insurance, we reinvent it. How? By combining a comprehensive and efficient capital platform, data-driven insights, leading technology, and the best talent in an agile and inclusive workspace, empowered to deliver top client service across all our lines of business - property, casualty, professional, financial lines and specialty. With an innovative and flexible approach to risk solutions, we partner with those who move the world forward. Inclusion & Diversity
Direct job link
Relevant jobs
- Architecture Jobs in Basildon
- Architecture Jobs in Bedford, Wigan
- Architecture Jobs in Braintree
- Architecture Jobs in Bury St Edmunds, Suffolk
- Architecture Jobs in Cambridge, Leeds
- Architecture Jobs in Chelmsford
- Architecture Jobs in Colchester
- Architecture Jobs in Ely
- Architecture Jobs in Great Yarmouth
- Architecture Jobs in Harlow
- Architecture Jobs in Haverhill, Suffolk
- Architecture Jobs in Ipswich
- Architecture Jobs in King's Lynn, Norfolk
- Architecture Jobs in Lowestoft, Suffolk
- Architecture Jobs in Norwich
- Architecture Jobs in Peterborough
- Architecture Jobs in Southend-on-Sea
- Architecture Jobs in St Albans
- Architecture Jobs in Stevenage