Présentation société Voir les autres offres
   
 

ITS Group Benelux - Cyber Security Risk Management Advisor

Our client's Risk and Compliance team supports IT and Business Units to develop adequate solutions on operational risk management practices, focusing but not restricted to Information Security.

 

Their main missions are

  • Identify operational information risks on assets/applications, projects and 3rd-parties.
  • Advice, consult, monitor and report on risk treatment in order to reduce the overall risk exposure of IT and Business at an optimized cost.
  • Elaborate and manage the implementation of a flexible strategy to reduce Information Security risks in accordance to the Information Security policies of our client.

 

Function Description

  • you execute security risk assessments in IT and business, scoping projects or legacy assets (applications, business solutions, 3rd-parties organization, processes...). Maintenance of identified risks in the risk registry database.
  • you setup processes and procedures for an end to end security management for assets and Third-parties.
  • you perform security risk quality assurance from the creation to the closure.
  • you deliver consulting on risk management to internal customers (IT and Business):
    • Proposition or validation of measures to mitigate risks.
    • Creation of detailed or synthetic risk report, structured and formulated in line with our client and Information Security Risk Management best practices.
    • Support in increasing risk control maturity by providing a valuable follow up and reporting.
    • you report risks and overall risk posture to Information Security, IT or Business Management
    • Correlate risks across a portfolio of projects or activities; identify and propose transversal risk mitigating actions.
    • Create risk dashboards and reports for a management audience, in line with the defined risk appetite for the company.
    • Create one-pagers and synthetic risk reports for a management audience.
  • you manage customer relationship and are the Single Point Of Contact for the risk management services you deliver. You customize services to meet customer needs or expectations while ensuring compliance with risk management methodologies and guidelines. 
  • you contribute to definition and improvement of risk management methods and tools supporting those activities (risk identification guide, risk evaluation matrix, industrialization of risk monitoring and reporting framework and deliverables) taking into account your field experience as well as best practices coming from our client or other sources like regulators, Basel II, COBIT, ISO27000/31000 ...
  • you contribute to writing procedures and processes supporting risk management activities outlined above, for both an expert and non-expert audience. Experience on linking different ISMS processes is a must.
  • you are the single point of contact for security matters related to the CIAT of our assets: business support, maintenance of procedures and tooling, regular reporting, integration of the security asset management in the overall asset management processes.

   

Profile

  • Education: Bachelor/Master
  • Languages: FR/ENG/NL (no need to apply if you only master English as one of the national language is required)
  • Required knowledge / Experience:
    • Professional experience in information security (5+ years)
    • Experience in project management, process design and improvement
    • Experience in Data protection, Business continuity, Access management
    • Experience in Security Assessments on assets and Third-parties
    • Experience in delivering presentations and training
  • Mandatory Business Experience:
    • Knowledge of Information Security and Risk Management frameworks (ISO27001, SOC, NIST, OWASP, etc.)
    • Professional experience in information security (5+ years), particularly in Third-party management
    • Strong IT background.
    • Professional experience in Financial Services; used to work in large companies.
    • Preferably experience in reviewing and amending Third-party security clauses in contracts
  • Mandatory Technical Experience:
    • Significant experience in operational/security risks management.
    • Knowledge of control frameworks and audit methodologies.
    • Significant experience in working with cloud services (SaaS, HSP, AWS)
    • Knowledge of software development security best practices
    • Experience in release management, change management, incident management, testing
  • Preferable Technical Experience:
    • Security certifications like CISSP, CISM, CIPP, CCSK.
    • Experience with RSA Archer tool.
    • Experience in vulnerability management and penetration testing
  • Soft skills:
    • High performer
    • Autonomy, commitment and perseverance in personal organization.
    • Quick self-starter, pro-active attitude, team player.
    • Results-oriented, responsible for his/her tasks, resourceful.
    • Excellent English writing skills.
    • Good communication and influencing skills.
    • Good analytical and synthesis skills, ability to produce structured and concise documents, be precise and methodological.
    • Ability to work in a dynamic and multi-cultural environment.
    • Accurate & control minded, but flexible.
    • Ability to capture and adapt to stakeholder expectations while respecting processes in place.
    • Ability to mentor/coach people.

Description société

ITS Group is an IT consultancy company specializing in the sustainable development of IT infrastructures.
Founded in 1997, ITS Group has become a respected international company with more than 1500 employees Europe.

We offer our clients an assistance in all aspects of integration, administration and operation of their IT systems.
From the design of the solution to the maintenance, either on-site or in one of our service centers, we provide the assistance in project management, technical support, administration, etc.

Our goal is to support all of your projects as they affect a rapidly changing IT landscape.
In this field our values are:

- Specialization and innovation;
- Requirement for quality;
- Development and diversity of our human resources.

This conviction makes us a responsible company, committed to sustainable development.
This guarantees us creativity, reactivity and competetivity.

At a glance:

200M€ 2015 Turnover
19 years of uninterrupted growth and profits
1500 employees in Europe (France & Benelux)
Listed on Euronext since 2005

Lire la suite
Offres d'emploi similaires