At a Glance
- Tasks: Conduct risk assessments and ensure security throughout project lifecycles.
- Company: AXA XL is a leader in solving complex risks with innovative solutions.
- Benefits: Enjoy flexible working options and a diverse, inclusive workplace.
- Why this job: Join a dynamic team that values your input and fosters professional growth.
- Qualifications: Bachelor's degree in a relevant field and experience in risk assessments required.
- Other info: Opportunity to work in a collaborative environment with top industry talent.
The predicted salary is between 48000 - 84000 £ per year.
The Secure Project Lifecycle process has been established to perform risk assessments, ensuring security is considered as part of the design and throughout the project lifecycle. The SPL process governs projects within the Planview time recording and management system and those that are managed outside such as Move to the Cloud (MttC) programme.
The role will be to augment the Information Security team to perform risk assessments of projects, provide guidance and acquire outcomes/decisions from the project manager, enterprise architect, technical architect, solutions architect, data privacy officer, project management office, strategic change development, IT Infrastructure and Operations and penetration testers.
The specialist will work under the responsibility of the Head of IS Services and Risk Management and will report to the Secure Project Lifecycle Team Lead. The responsibilities of the role will include the following:
- Review submission of IS Criticality Assessment (ISCA) questionnaire (ISCA Dashboard)
- Determine high level security requirements and project criticality, based on standard project activities and data classification from DP pre-screening
- Work with assigned architect to ensure security requirements are finalized in design (High Level Design), review with Enterprise Architecture, Solutions Architecture, Cyber Security and Cyber Assurance
- Review of all security requirements and evidence provided by the project manager to support closure of each requirement:
- Review and feedback on ISCA questionnaire
- Review and feedback on High Level Design (HLD)
- Present at ISCA Project Technical Review
- Attend and obtain HLD sign-off at Technical Design Authority, Solutions Design Authority (SDA) and Data Intelligence and Analytics (DIA)
- Obtain Third Party Risk Evaluation Platform (TPREP) scorecard for TP SaaS solutions from Security Contracts team
- Obtain Minimum Technical Security Baseline compliance reporting from QualysGuard
- Obtain Cloud Permit from Enterprise Architecture
- Obtain Code Review and Analysis – in house solutions only from SCD
- Self-serve vulnerability assessment compliance report of assets in scope
- Liaise with Cyber Assurance on penetration testing of solution and obtain sign off
- Obtain Digital Hub registration for external facing solutions from Cyber Assurance
- Produce Project Security Assessment closure report
- Perform a final review of all open security requirements and their status before any stage gate approval can be provided (effectively the Production Go/No-go decision).
- Ensure AXA XL SDLC agile, waterfall and infra waterfall processes are followed
- Store all evidence in IS projects shared area
- Update the project register daily to ensure project status is maintained and update the Project Security Assessment (PSA) template as a record of activity. Submit PSA for sign off to complete risk assessment
- Manage project RAG status ensuring activities trending amber and red are highlighted to management and the project manager
- Liaise with project manager to support the development of the risk acceptance (PM is responsible) where needed
- Attend meetings with project manager, stakeholders, ISCA technical review, architectural design authorities and pen testing reviews. Challenge design decisions not compliant with security, escalate issues when they become known, offer options to resolve
We’re looking for someone who has these abilities and skills:
- Bachelor’s degree in computer science, Engineering, or related field with a senior level of professional experience (Required)
- Established knowledge of performing project risk assessments (Required)
- Experience in performing Information Security technical risk assessments (Required)
- Proficient in information security risk and governance frameworks (ISO 27005, EBIOS)
- Expert analytical and reporting skills (Required)
- Expert in Microsoft Office (Word, Excel, PowerPoint, Access) (Required)
- Ability to effectively communicate and positively influence diverse stakeholders and team members (Required)
- Excellent attention to detail and the ability to create clear, concise, and engaging presentations (Required)
- Information Security and /or Information Technology industry certification (CISSP, CISM, CRISC, GIAC, CISSP or equivalent) (Required)
- Experience in articulating IS risks in business language and advising on the appropriate risk management action > 5 years (Preferred)
- Experience in information security management reporting and related methodologies > 5-10 years (Preferred)
- Experience in multinational companies (Preferred)
AXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. For mid-sized companies, multinationals and even some inspirational individuals we don’t just provide re/insurance, we reinvent it.
How? By combining a strong and efficient capital platform, data-driven insights, leading technology, and the best talent in an agile and inclusive workspace, empowered to deliver top client service across all our lines of business – property, casualty, professional, financial lines and specialty.
With an innovative and flexible approach to risk solutions, we partner with those who move the world forward.
At AXA XL we are happy to talk flexible working. We are committed to building a diverse and inclusive workforce and consider flexible ways of working for every role. Talk to us about how we can make flexibility work for you.
AXA XL is an Equal Opportunity Employer.
Location: GB-GB-Ipswich
Work Locations: GB Ipswich 2nd floor, Civic Drive Civic Drive 2nd floor Ipswich
Job Field: Information Technology
Schedule: Full-time
Job Type: Standard
Senior Specialist, Agile Security and Risk Management Assessment employer: XL CATLIN
Contact Detail:
XL CATLIN Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Specialist, Agile Security and Risk Management Assessment
✨Tip Number 1
Familiarise yourself with the Secure Project Lifecycle (SPL) process. Understanding how risk assessments are integrated into project management will help you demonstrate your knowledge during interviews and discussions with stakeholders.
✨Tip Number 2
Network with professionals in the information security field, especially those who have experience with Agile methodologies. Engaging with industry peers can provide insights into the role and may even lead to referrals.
✨Tip Number 3
Prepare to discuss specific frameworks like ISO 27005 and EBIOS. Being able to articulate your understanding of these frameworks and how they apply to risk assessments will set you apart from other candidates.
✨Tip Number 4
Showcase your analytical and reporting skills by preparing examples of past projects where you successfully identified and mitigated risks. Real-life scenarios can effectively illustrate your capabilities to potential employers.
We think you need these skills to ace Senior Specialist, Agile Security and Risk Management Assessment
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in risk assessments and information security. Use keywords from the job description to demonstrate that you meet the specific requirements of the role.
Craft a Compelling Cover Letter: In your cover letter, explain why you're passionate about the role and how your background aligns with the responsibilities outlined in the job description. Be sure to mention any relevant certifications and your experience with risk management frameworks.
Showcase Your Analytical Skills: Provide examples in your application that showcase your analytical and reporting skills. Mention specific projects where you successfully performed risk assessments and how you communicated findings to stakeholders.
Highlight Communication Abilities: Since the role requires effective communication with diverse stakeholders, include examples of how you've positively influenced team members or managed stakeholder expectations in previous roles.
How to prepare for a job interview at XL CATLIN
✨Understand the Secure Project Lifecycle
Familiarise yourself with the Secure Project Lifecycle process and how it integrates risk assessments into project management. Be prepared to discuss how you can contribute to ensuring security is a priority throughout the project lifecycle.
✨Showcase Your Risk Assessment Experience
Highlight your previous experience in performing project risk assessments, particularly in information security. Be ready to provide specific examples of how you've identified risks and implemented mitigation strategies in past projects.
✨Communicate Effectively with Stakeholders
Demonstrate your ability to communicate complex security concepts in business language. Prepare to discuss how you have positively influenced diverse stakeholders in previous roles, as this will be crucial for liaising with project managers and architects.
✨Prepare for Technical Discussions
Brush up on your knowledge of information security frameworks like ISO 27005 and EBIOS. Be ready to engage in technical discussions about security requirements and design decisions, showcasing your analytical skills and attention to detail.