Search for new things / novelty Need for action Team work Ambition Flexibility Need for reflection Involvement at work Organization
AXA Group Operations - AXA Group's operational center of excellence.
At AXA, our mission is to empower people to live better lives. Through innovation and execution, we need to move from being a 'Payer' to a trusted partner in our clients' lives. The concrete goals of the group's activities are to create value for the global AXA organization, collaborate with the group Business Innovation to encourage innovation, and integrate simplicity and empowerment into our contribution to AXA's mission and strategy.
Present in over 18 countries, AXA Group Operations is the operational center of excellence for the AXA Group. Operating in the fields of IT (Information Technology), Data & Innovation, IT Security, Finance, Procurement, Transformation, and Outsourcing, we support the Group's strategy: Becoming an innovative 'Customer driven & Tech-led' company.
AXA Group Operations Morocco
Present in Morocco since 2009, AXA Group Operations Morocco is an offshoring entity. With its 300 employees and its various centers of expertise operating in the fields of IT, Project Management, Finance, and Human Resources, AXA GO Morocco supports Group Operations in achieving its mission.
AXA GBS Morocco operates within a predominantly collaborative culture, where people, trust, and strong professional relationships are key priorities. The company promotes close and supportive management, encouraging accountability, development, and team cohesion. This human-centered approach is reinforced by a strong organizational framework, ensuring reliability, structure, and operational efficiency. It is complemented by a moderate focus on innovation and performance, supporting continuous improvement within a well-defined environment.
The Cloud Security Engineer is responsible for:
• Act as a local Cloud Broker reference for operational security activities of the Public Cloud platforms
• Know, understand and secure the Public Cloud environment and the related context
• Review Security related changes on Public Cloud platform components
• Liaise with Security representative between Cloud Brokers, Products/Applicative owners and Group Operation Security
• Implement and control security analysis for Platform upgrades, Changes, Compliance requirements
• Implement and control Cloud Platforms Continuous Security Assurance Plan
• Integrate Security By Design prerequisites into CI/CD and Infra As a Code Provisioning
• Suggest effective security controls to be implemented for Cloud Platforms and Services
• Coordinate with Cloud product teams to consolidate cloud security reports.
• Interact with Entities Teams Representative to ensure the effective compliance and remediation of security issues (Vulnerabilities and non-compliance to AXA standards)
The activities under the scope are:
Local Governance :
• CB Security Mandates : definition, review, upgrades and evolutions
• CB Security Governance review on the security activities with GO Security, Market CB, Group Information Security etc
• CB Security Operating Model : definition with all Security teams within AXA (Group Security, Group Operation Security, Risk Teams, Operational Resilience etc)
• CB Security service catalog : define a service offer around security activities to be provided as a service to Market CB and by cascade to the entities
• CB Security processes : Define, implement and update security related processes over organizational and operational activities
• CB Security Change management : Organize the security changes between multiple teams including technical and business operations
• Organize, inform, support and report on Security projects
• Provide assistance and expertise for Secure Cloud Enablement within AXA Public Cloud (Service validation, Service Integration, Obsolescence, End of support, new Services, Versions upgrades/deprecations …)
• CB Security advisory and assistance
• CB Security onboardings
• Knowledge Management
Security Projects cross Market :
• Provide security expertise on the projects for secure enablement
• Organize security forums for information and reporting
• Implement and/or follow implementation of security projects
Local FinOps initiatives :
• Manage and implement Finops initiative identified by other stakeholders
• Define new Finops cost optimizations using Cloud advisories
• Make security posture evolve with finops considerations
Security Mandatory Compliance:
• Participate on security controls evaluations,
• Assess and evaluate new security controls and specific use cases
• Validate security controls implementations, reporting mechanisms
• Remediate and/or provide assistance for non-compliance remediations
Security Internal Audits :
• Organize security audits in project mode
• Define remediation procedures and/or participate in remediations procedures definitions with owners teams (GO Security, PUIAM Teams, CyberArk Teams, etc)
• Implement remediations, report on non-compliance, manage security exceptions
Recertification :
• Participate in evaluating the recertification frameworks, planning and roadmaps
• Review and validate remediation procedures
• Provide Market assistance
• Report
Service Enablement :
• Participate in the security of services (through the Cloud Service Board and Riks in project initiatigves)
• Identify, organize and implement security prerequisites for service consumptions
• Define and implement CB Security oversight in coordination with GO Security through Dedicated TOR (Terms of Reference) : see monthly CB governance meeting
Security Incidents :
• Manage cross Market security incident, provide assistance and act as a SPOC for Markets
Technical & functional skills:
• Bachelor degree in Computer Science, Engineering, or related field.
• An MSc Information Security is a plus
• 4+ years' experience in Operational Security on the Public Cloud Providers : Azure/AWS
• Knowledge on the Cloud Security Frameworks, Regulatory Compliance and Security Services
• Knowledge on Azure Architecture or AWS Architecture or both
• Knowledge of the Secure by Design Principles, SecOps and DevSecOps Principles
• Knowledge in change management and Secure Development LifeCycle (SDLC)
• Capacity to work in a matrix organization
• Knowledge in Security Incident Management
• Ability to learn quickly
• Strong interpersonal and communication skills; able to deal effectively with diverse cultures, skill sets and personalities, works effectively as a team player
• Organized with a proven ability to prioritize workload, meet deadlines, and utilize time effectively
• Strong facilitation, negotiation and conflict resolution skills
• Strong analytical skills
• Apply analytical rigor to understand complex business scenarios
Languages :
• English - Mandatory.
• French - Optional.
Search for new things / novelty Need for action Team work Ambition Flexibility Need for reflection Involvement at work Organization
Here you can find a recommendation rate for this vacancy, as well as information on how to promote your application. Log in / Register to view this personalised information.
ReKrute offers you this new personality test to help you get to know yourself better and make the most of your applications. Take it now, it only takes 5 minutes maximum.