Essential Responsibilities :
- Support the collection of up-to-date information from the business regarding their most valuable data and its use on a yearly basis (at minimum) at a Data Element level when possible.
- Monitor the use of Data elements through security tools like DLP and Microsoft Purview.
- Help create Sensitive Information Types to better pinpoint sensitive data elements used by the business.
- Control and monitor locations of sensitive data elements in the organization (email, SharePoint, OneDrive).
- Manage and maintain the Data Classification register for unstructured data, ensuring a consistent record of the most valuable data in AXA XL, including their owner, classification, and location in different tools (Varonis, Purview, SharePoint).
- Act as a champion for Information Security when dealing with areas of the business, providing assistance with raising information risks and explaining current policy as required.
- Maintain close working relationships with appropriate teams across and outside of Information Security.
- Centralize and leverage all information available (SOC Incidents, vulnerability scans, phishing results, etc.) to best identify risks around data and the supporting assets in the organization.
- Communicate weekly on the top identified risks that are currently being monitored.
- Ensure up-to-date Information Security risk metrics are ready to be distributed as required.
- Produce monthly reporting to local IT, Security, Risk governance, and business on non-compliance around data elements use and locations.
- You will report to the Head of Information Security Services and Risk Management.
Required Skills and Abilities :
Master's degree in Computer Science, Engineering, or a related field with a minimum of 5 years of professional experience in Risk Management and / or Information Security.Expertise in synthesizing and clearly communicating complex information to all audiences, up to C-Level leaders.Experience in articulating risks in business language and advising on the appropriate risk management actions.Excellent attention to detail and the ability to create clear, concise, and engaging presentations, breaking down difficult problems.Excellent knowledge of Information Security frameworks (Mitre ATT&CK, FAIR, NIST, ISO 2700X).Fluent in English.Expert analytical and reporting skills.Excellent interpersonal and collaborative skills.Expert in Microsoft Office (Word, Excel, PowerPoint, SharePoint).Experience in multinational companies.Excellent knowledge of Risk Management.Desired Skills and Abilities :
Experience in information security management reporting and related methodologies.Information Security and / or Information Technology industry certification (CISSP, CISM, or equivalent).Familiarity with security tools to collect information and evidence (DLP, Active Directory, Varonis, Qualys).Education
UG : B.Tech / B.E. in Any SpecializationPG : MS / M.Sc(Science) in Any SpecializationSkills Required
Iso 27001, Fair, Dlp, nist, varonis , Qualys, Risk Management