Senior Specialist, Agile Security and Risk Management Assessment
Senior Specialist, Agile Security and Risk Management Assessment

Senior Specialist, Agile Security and Risk Management Assessment

Ipswich Full-Time 48000 - 72000 £ / year (est.) No home office possible
Go Premium
A

At a Glance

  • Tasks: Conduct risk assessments and ensure security is integrated throughout project lifecycles.
  • Company: Join AXA XL, a leader in innovative risk solutions and inclusive work culture.
  • Benefits: Competitive salary, professional development, and a dynamic work environment.
  • Why this job: Make a real impact by enhancing security in exciting projects.
  • Qualifications: Bachelor's degree in relevant field and experience in risk assessments required.
  • Other info: Collaborate with diverse teams and enjoy excellent career growth opportunities.

The predicted salary is between 48000 - 72000 £ per year.

The Secure Project Lifecycle process has been established to perform risk assessments, ensuring security is considered as part of the design and throughout the project lifecycle. The SPL process governs projects within the Planview time recording and management system and those that are managed outside such as Move to the Cloud (MttC) programme.

The role will be to augment the Information Security team to perform risk assessments of projects, provide guidance and acquire outcomes/decisions from the project manager, enterprise architect, technical architect, solutions architect, data privacy officer, project management office, strategic change development, IT Infrastructure and Operations and penetration testers.

The specialist will work under the responsibility of the Head of IS Services and Risk Management and will report to the Secure Project Lifecycle Team Lead. The responsibilities of the role will include the following:

  • Review submission of IS Criticality Assessment (ISCA) questionnaire (ISCA Dashboard)
  • Determine high level security requirements and project criticality, based on standard project activities and data classification from DP pre-screening
  • Work with assigned architect to ensure security requirements are finalized in design (High Level Design), review with Enterprise Architecture, Solutions Architecture, Cyber Security and Cyber Assurance
  • Review of all security requirements and evidence provided by the project manager to support closure of each requirement:
  • Review and feedback on ISCA questionnaire
  • Review and feedback on High Level Design (HLD)
  • Present at ISCA Project Technical Review
  • Attend and obtain HLD sign-off at Technical Design Authority, Solutions Design Authority (SDA) and Data Intelligence and Analytics (DIA)
  • Obtain Third Party Risk Evaluation Platform (TPREP) scorecard for TP SaaS solutions from Security Contracts team
  • Obtain Minimum Technical Security Baseline compliance reporting from QualysGuard
  • Obtain Cloud Permit from Enterprise Architecture
  • Obtain Code Review and Analysis – in house solutions only from SCD
  • Self-serve vulnerability assessment compliance report of assets in scope
  • Liaise with Cyber Assurance on penetration testing of solution and obtain sign off
  • Obtain Digital Hub registration for external facing solutions from Cyber Assurance
  • Produce Project Security Assessment closure report
  • Perform a final review of all open security requirements and their status before any stage gate approval can be provided (effectively the Production Go/No-go decision). Ensure AXA XL SDLC agile, waterfall and infra waterfall processes are followed
  • Store all evidence in IS projects shared area
  • Update the project register daily to ensure project status is maintained and update the Project Security Assessment (PSA) template as a record of activity. Submit PSA for sign off to complete risk assessment
  • Manage project RAG status ensuring activities trending amber and red are highlighted to management and the project manager
  • Liaise with project manager to support the development of the risk acceptance (PM is responsible) where needed
  • Attend meetings with project manager, stakeholders, ISCA technical review, architectural design authorities and pen testing reviews. Challenge design decisions not compliant with security, escalate issues when they become known, offer options to resolve
  • All deliverables are subject to an internal quality assurance and peer reviews will be conducted by the Information Security team.
  • We’re looking for someone who has these abilities and skills:

    • Bachelor’s degree in computer science, Engineering, or related field with a senior level of professional experience (Required)
    • Established knowledge of performing project risk assessments (Required)
    • Experience in performing Information Security technical risk assessments (Required)
    • Proficient in information security risk and governance frameworks (ISO 27005, EBIOS)
    • Expert analytical and reporting skills (Required)
    • Expert in Microsoft Office (Word, Excel, PowerPoint, Access) (Required)
    • Ability to effectively communicate and positively influence diverse stakeholders and team members (Required)
    • Excellent attention to detail and the ability to create clear, concise, and engaging presentations (Required)
    • Fluent in English (Required)
    • Information Security and /or Information Technology industry certification (CISSP, CISM, CRISC, GIAC, CISSP or equivalent) (Required)
    • Experience in articulating IS risks in business language and advising on the appropriate risk management action
    • Experience in information security management reporting and related methodologies
    • Experience in multinational companies (Preferred)

    AXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. For mid-sized companies, multinationals and even some inspirational individuals we don’t just provide re/insurance, we reinvent it.

    How? By combining a comprehensive and efficient capital platform, data-driven insights, leading technology, and the best talent in an agile and inclusive workspace, empowered to deliver top client service across all our lines of business − property, casualty, professional, financial lines and specialty.

    With an innovative and flexible approach to risk solutions, we partner with those who move the world forward.

    Senior Specialist, Agile Security and Risk Management Assessment employer: AXA Group

    AXA XL is an exceptional employer, offering a dynamic and inclusive work culture that fosters collaboration and innovation in the heart of Ipswich. Employees benefit from comprehensive professional development opportunities, competitive compensation, and a commitment to work-life balance, all while contributing to meaningful projects that address complex risks in a supportive environment. Join us to be part of a team that values your expertise and empowers you to make a real impact in the field of Information Security.
    A

    Contact Detail:

    AXA Group Recruiting Team

    StudySmarter Expert Advice 🤫

    We think this is how you could land Senior Specialist, Agile Security and Risk Management Assessment

    ✨Tip Number 1

    Network like a pro! Reach out to people in your industry on LinkedIn or at local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.

    ✨Tip Number 2

    Prepare for interviews by researching the company and its projects. Understand their security processes and be ready to discuss how your skills align with their needs. Show them you’re not just another candidate!

    ✨Tip Number 3

    Practice your pitch! Be clear about your experience in risk assessments and how you can contribute to their team. A confident, concise introduction can make a lasting impression.

    ✨Tip Number 4

    Don’t forget to follow up after interviews! A quick thank-you email can keep you top of mind and show your enthusiasm for the role. Plus, it’s a great chance to reiterate why you’re the perfect fit.

    We think you need these skills to ace Senior Specialist, Agile Security and Risk Management Assessment

    Project Risk Assessments
    Information Security Technical Risk Assessments
    ISO 27005
    EBIOS
    Analytical Skills
    Reporting Skills
    Microsoft Office (Word, Excel, PowerPoint, Access)
    Communication Skills
    Attention to Detail
    Presentation Skills
    Information Security Certifications (CISSP, CISM, CRISC, GIAC)
    Risk Management
    Stakeholder Engagement
    Quality Assurance

    Some tips for your application 🫡

    Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in project risk assessments and information security. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!

    Showcase Your Analytical Skills: Since this role requires expert analytical and reporting skills, include examples of how you've successfully analysed risks in past projects. We love seeing clear, concise, and engaging presentations, so if you have any, feel free to share them!

    Communicate Clearly: Effective communication is key! When writing your application, ensure that you articulate your experience in a way that’s easy to understand. We’re looking for someone who can positively influence diverse stakeholders, so let your personality shine through.

    Apply Through Our Website: Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about what we do at StudySmarter!

    How to prepare for a job interview at AXA Group

    ✨Know Your Risk Assessment Frameworks

    Make sure you brush up on your knowledge of information security risk and governance frameworks like ISO 27005 and EBIOS. Be ready to discuss how you've applied these in past projects, as this will show your expertise and understanding of the role.

    ✨Prepare for Technical Discussions

    Since you'll be liaising with various architects and stakeholders, it's crucial to prepare for technical discussions. Familiarise yourself with High Level Design (HLD) concepts and be ready to challenge design decisions that don't comply with security standards.

    ✨Showcase Your Communication Skills

    This role requires effective communication with diverse stakeholders. Practice articulating complex IS risks in business language. You might even want to prepare a few examples where you've successfully influenced decisions or outcomes in previous roles.

    ✨Demonstrate Attention to Detail

    Given the nature of risk assessments, attention to detail is key. Bring examples of your work that highlight your ability to create clear, concise reports and presentations. This will help demonstrate your capability to manage project RAG statuses and ensure compliance.

    Senior Specialist, Agile Security and Risk Management Assessment
    AXA Group
    Location: Ipswich
    Go Premium

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    A
    • Senior Specialist, Agile Security and Risk Management Assessment

      Ipswich
      Full-Time
      48000 - 72000 £ / year (est.)
    • A

      AXA Group

      50-100
    Similar positions in other companies
    UK’s top job board for Gen Z
    discover-jobs-cta
    Discover now
    >