Recherche de nouveauté Besoin d'action Travail en équipe Ambition Flexibilité Besoin de réflexion Implication au travail Organisation
AXA Group Operations – Centre opérationnel d’excellence du Groupe AXA.
Chez AXA, notre mission est de donner aux gens les moyens de vivre une vie meilleure. Grâce à l'innovation et à l'exécution, nous devons passer du statut de « Payeur » à un partenaire de confiance dans la vie de nos clients. Les objectifs concrets des activités du groupe sont de créer de la valeur pour l’organisation globale AXA, de collaborer avec le groupe Business Innovation pour encourager l’innovation et intégrer la simplicité et l’autonomisation dans notre contribution à la mission et à la stratégie d’AXA.
Présent dans plus de 18 pays, AXA Group Operations est le centre opérationnel d’excellence du Groupe AXA. Opérant dans les domaines de l’IT (Information Technology), Data & Innovation, Sécurité Informatique, Finance, Procurement, Transformation et Outsourcing, nous accompagnons la stratégie du Groupe : Devenir une entreprise innovante « Customer driven & Tech-led ».
AXA Group Operations Maroc
Présente au Maroc depuis 2009, AXA Group Opérations Maroc est une entité d’offshoring. Avec ses 300 collaborateurs et ses différents centres d’expertise opérant dans les domaines de l’informatique, de la Gestion de projet, de la Finance et des Ressources Humaines, AXA GO Maroc soutient Group Operations dans la réalisation de sa mission.
AXA GBS Morocco évolue dans une culture principalement orientée coopération, où l’humain, la confiance et la qualité des relations professionnelles occupent une place centrale. L’entreprise privilégie un management de proximité, axé sur l’accompagnement, la responsabilisation et le développement des compétences. Cette culture collaborative est structurée par une forte dimension organisationnelle, garantissant rigueur, fiabilité et efficacité opérationnelle. Elle est enrichie par une ouverture à l’innovation et par une exigence de performance, présentes de manière plus mesurée et encadrée.
The Cloud Security Engineer is responsible for:
• Act as a local Cloud Broker reference for operational security activities of the Public Cloud platforms
• Know, understand and secure the Public Cloud environment and the related context
• Review Security related changes on Public Cloud platform components
• Liaise with Security representative between Cloud Brokers, Products/Applicative owners and Group Operation Security
• Implement and control security analysis for Platform upgrades, Changes, Compliance requirements
• Implement and control Cloud Platforms Continuous Security Assurance Plan
• Integrate Security By Design prerequisites into CI/CD and Infra As a Code Provisioning
• Suggest effective security controls to be implemented for Cloud Platforms and Services
• Coordinate with Cloud product teams to consolidate cloud security reports.
• Interact with Entities Teams Representative to ensure the effective compliance and remediation of security issues (Vulnerabilities and non-compliance to AXA standards)
The activities under the scope are:
Local Governance :
• CB Security Mandates : definition, review, upgrades and evolutions
• CB Security Governance review on the security activities with GO Security, Market CB, Group Information Security etc
• CB Security Operating Model : definition with all Security teams within AXA (Group Security, Group Operation Security, Risk Teams, Operational Resilience etc)
• CB Security service catalog : define a service offer around security activities to be provided as a service to Market CB and by cascade to the entities
• CB Security processes : Define, implement and update security related processes over organizational and operational activities
• CB Security Change management : Organize the security changes between multiple teams including technical and business operations
• Organize, inform, support and report on Security projects
• Provide assistance and expertise for Secure Cloud Enablement within AXA Public Cloud (Service validation, Service Integration, Obsolescence, End of support, new Services, Versions upgrades/deprecations …)
• CB Security advisory and assistance
• CB Security onboardings
• Knowledge Management
Security Projects cross Market :
• Provide security expertise on the projects for secure enablement
• Organize security forums for information and reporting
• Implement and/or follow implementation of security projects
Local FinOps initiatives :
• Manage and implement Finops initiative identified by other stakeholders
• Define new Finops cost optimizations using Cloud advisories
• Make security posture evolve with finops considerations
Security Mandatory Compliance:
• Participate on security controls evaluations,
• Assess and evaluate new security controls and specific use cases
• Validate security controls implementations, reporting mechanisms
• Remediate and/or provide assistance for non-compliance remediations
Security Internal Audits :
• Organize security audits in project mode
• Define remediation procedures and/or participate in remediations procedures definitions with owners teams (GO Security, PUIAM Teams, CyberArk Teams, etc)
• Implement remediations, report on non-compliance, manage security exceptions
Recertification :
• Participate in evaluating the recertification frameworks, planning and roadmaps
• Review and validate remediation procedures
• Provide Market assistance
• Report
Service Enablement :
• Participate in the security of services (through the Cloud Service Board and Riks in project initiatigves)
• Identify, organize and implement security prerequisites for service consumptions
• Define and implement CB Security oversight in coordination with GO Security through Dedicated TOR (Terms of Reference) : see monthly CB governance meeting
Security Incidents :
• Manage cross Market security incident, provide assistance and act as a SPOC for Markets
Technical & functional skills:
• Bachelor degree in Computer Science, Engineering, or related field.
• An MSc Information Security is a plus
• 4+ years’ experience in Operational Security on the Public Cloud Providers : Azure/AWS
• Knowledge on the Cloud Security Frameworks, Regulatory Compliance and Security Services
• Knowledge on Azure Architecture or AWS Architecture or both
• Knowledge of the Secure by Design Principles, SecOps and DevSecOps Principles
• Knowledge in change management and Secure Development LifeCycle (SDLC)
• Capacity to work in a matrix organization
• Knowledge in Security Incident Management
• Ability to learn quickly
• Strong interpersonal and communication skills; able to deal effectively with diverse cultures, skill sets and personalities, works effectively as a team player
• Organized with a proven ability to prioritize workload, meet deadlines, and utilize time effectively
• Strong facilitation, negotiation and conflict resolution skills
• Strong analytical skills
• Apply analytical rigor to understand complex business scenarios
Languages :
• English – Mandatory.
• French – Optional.
Recherche de nouveauté Besoin d'action Travail en équipe Ambition Flexibilité Besoin de réflexion Implication au travail Organisation
Ici, vous pouvez retrouver un taux de recommandation de cette offre pour vous, ainsi que des informations pour mettre en avant votre candidature. Connectez-vous / Inscrivez-vous pour consulter ces informations personnalisées.
ReKrute vous offre ce nouveau test de personnalité pour mieux vous connaitre et valoriser vos candidatures. Passez-le dès maintenant, cela ne prend que 5 minutes maximum.