Uploaded by Mohcine

Fiche de poste Audit Remediation PMO (1)

advertisement
JOB Description
Cyber Defense is the backbone of the Security Operations of AXA and our mission is to protect the
most important assets and our brand. Our mission:
✓ Protect : Design and implement controls to defend the data and reputation of AXA and its
customers’ trust
✓ Detect: Rapidly identify issues to minimize and manage impact on AXA and its customers
✓ Respond: Resolve issues appropriately through measured steps to ensure business value
The PUAM “Privileged Users Acccess Management” Product Team are focused on improving the
performance, functionality, and security of AXA’s Privileged Access Security (PAS) solution, CyberArk.
LGF170301 Audit Observations were published in December 2017 following a review of the risk and
controls of Information and Security Operations (ISOPS).
As part of our analysis for this and other related audit observations, combined with independent
assessment and assurance activities, we completed a wide range of actions to improve both the
security and operational standards within PUAM.
LGF170301 Audit Conclusion: The privileged user access management (PUAM) solution was being
deployed without a robust process to operate the related tool (CyberArk). Moreover, despite its
criticality, the underlying infrastructure had not been checked to identify and address security
weaknesses, potentially exposing sensitive information in case of cyber-attack or malevolent Cap
Gemini India employees (issue 1 – Very High
The MAP of the remediation action plan was validated in Q1 2018. Since then, the required actions to
close LGF170301 have been expanded following a series of interactions, led to 27 controls to execute
and evidences to provide by the end of 2021.
In this context, the PUAM Program is looking to reinforce its PM team with a project manager officer:
A. Objectives
•
•
•
•
•
Co-ordinate the diverse components of the controls (planning, readiness and execution of
processes to achieve required balance of time “deadline end of November 2021”, and scope)
Moderate project meetings (planning workshop, controlling meetings, problem-solving
workshops, etc.)
Perform project controlling
Contribute globally to the project, including the redaction of the processes, evidences,
update of wiki, SharePoint and communications
Provide Overall progress, Status of milestones and deliverables, risks, and progress of
mitigating these risks, addressing urgent issues effectively..
B. Main tasks
Working closely with the Program Manager, the external partners and the technical teams, the
Project Manager officer will:
Internal
•
•
•
•
•
•
Be responsible for the operational delivery of the project (On time, On Scope) with direct
reporting and clause collaboration with the program Manger
Follow up of metrics and KPIs to monitor and control the performance of the project
Review and manage the progress of the project to ensure execution is in accordance with
defined plan and scope.
Identify and track risks, issues and alerts on the project and ensure appropriate action plans
are established and actively monitored
Act as liaison between Cyber Defense and various technical and business communities within
AXA to communicate the project status and ensure alignment with their own change
activities.
Communicate relevant and timely information to stakeholders to ensure visibility of
progress, risks, issues and associated with delivery
C. Skills:
•
Must have skills
Competencies
Description
Project Management
✓ Planning in a complex environment (large global programs) with coordination
across several entities in multiple countries
✓ Multiple stakeholders alignment to a common plan
✓ Link people (including team members and stakeholders), ideas, and
information throughout the project life cycle
✓ Manage the interactions with external parties to deliver what is expected
✓ Information Technology experience, IT, security or technical project
management
✓ Totally fluent in English
✓ Excellent communication with stakeholders
✓ Capacity to deal with uncertainties and short deadlines
✓ Problem solving
Tech Skills
Other skills
•
Nice to have skills
Competencies
Description
IT Security
✓ IT security knowledge
✓ Ideally previous experience with security solutions
Internal
Download