Cyber Security Information Officer

5 days ago


Bucharest, Bucureşti, Romania Société Générale Full time €60,000 - €80,000 per year
Responsibilities

Societe Generale Global Solution Centre (SG GSC)andnbsp;acts as a business solutions center for Sociandeacute;tandeacute; Gandeacute;nandeacute;rale, one of the largest European financial groups. We provide quality professional services in over 35 countries in various business areas - Finance andamp; Accounting, HR, IT, Insurance, Banking and Corporate Operations. Our mission is to be a partner of choice, valued for owning, transforming and innovating with best-in-class talent.

To be part of the Insurance Business Line in Sociandeacute;tandeacute; Generale Global Solution Centre, means to be at the heart of the groupand#39;s development, in synergy with all the Retail Banking, Private Banking and specialized financial services businesses, in France and abroad. Its main challenge is to design and deliver fast, easy-to-use IT solutions that are innovative, scalable and secure, inspired and designed with customers, while ensuring quality every day.

Your future team is the Cyber Security Department, in charge of all cyber security domains, including governance and strategy, and covers both France and the 6 countries of the business unit, including Romania, for which you will deliver CISO services.

To deliver CISO services for the Insurance Romania entity, means to be in charge of all Cyber Security domains, IT Risk management and Business Continuity management. He/She applies Sociandeacute;tandeacute; Gandeacute;nandeacute;rale Group and Assurances cyber security, IT Risk and Business continuity strategies, as well as all associated regulatory requirements for the Insurance Romania entity.

As a CISO, you will report:

  • andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp; Hierarchically to the cyber security department of Societe Generale Global Solution Center (SG GSC)

  • andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp; Functionally to the Romanian entity Head

  • andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp; Functionally to Societe Generale Insurance Global CISO

andnbsp;

Missions

andnbsp; To be, as a security referent, the default contact for all security matters within Romanian Insurance entity (SGA)

andnbsp; Be responsible for the adaptation and implementation of the Sociandeacute;tandeacute; Gandeacute;nandeacute;rale Group Information Systems Security policy and strategy within SGA Romania

andnbsp; Leads the security function, relying if necessary on the network of Information Systems security correspondents

andnbsp; Reports on the risk vision of SGA Romania

andnbsp; Ensures the risk and regulatory reporting of SGA Romania

andnbsp;

andnbsp;

Activities

andnbsp; Provide advice, assistance, information, awareness-raising (particularly on best practices), alert and recommendation

andnbsp; Implement the Sociandeacute;tandeacute; Gandeacute;nandeacute;rale Group Information Systems Security policy and strategy that will have been adapted to SGA Romania and ensure its application within SGA Romania

andnbsp; Support the definition, implementation and control of Information Systems Security aspects in projects

andnbsp; Propose solutions to reduce risks to an acceptable level, and ensure that residual risks are accepted by the business lines

andnbsp; Collect Information Systems Security risk indicators on multiple aspects (legal and regulatory compliance, incidents, audit recommendations, operational security, etc.)

andnbsp; Prevent security incidents and mitigate their consequences,

  • andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp; by coordinating the Incident Management process according to Sociandeacute;tandeacute; Gandeacute;nandeacute;rale Group standards as well as European Digital Operational Resilience Act (DORA) and ITIL best practice;

  • andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp; in particular, by supervising and monitoring the vulnerability patching process;

  • andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp; by ensuring all other applicable security measures are in place and maintained in time in order to prevent security incidents

  • andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp; by participating in IT security incident management cycle: alerting, reporting and investigations in case of such event, and drafting and applying an incident response plan in coordination with BRD (Sociandeacute;tandeacute; Gandeacute;nandeacute;rale bank in Romania), ASSU (SGA) and Sociandeacute;tandeacute; Gandeacute;nandeacute;rale Group security teams. In this framework, oversee the Incident Management process and coordinate the local incident manager function.

  • andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;andnbsp;

andnbsp; Manage local Information Systems Security exemptions

andnbsp; Be open to the outside world to stay connected with risks and threats that evolve every day

And in particular,

andnbsp;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Ensure the general cyber security governance for SGA Romania, in particular organizing the Security Committees and informing top management and ASSU Security about Security progress;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Ensure that the cyber security level of SGA Romania is up to the standards of Sociandeacute;tandeacute; Gandeacute;nandeacute;rale and ASSU

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Participate in local or coordinated Security projects in the Group;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Monitor operational systems and alert in case of security incident

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Perform the ongoing surveillance process for the information systems as well as monitor the fulfillment of the action plans;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Manage security reports and indicators specific to Management, authorities, audits

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Co-ordinate the promotion of IT Security principles and rules within the company

Compliance

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Assure compliance to local regulatory IT/Sec norms

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Assure compliance with EU Norms (DORA)

IT Risk

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Calculate and centralize performance and risk indicators in the Information Security area;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Ensure reporting, risk registers, audit reports and completion of KPI and KRI as well as dashboards related to information security to management and ASF authorities.

Business Continuity

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Supervise business continuity processes in general ( BCP/DRC);

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Participate in the annual business process impact analysis in business continuity and in the organization of business continuity and crisis management tests;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Create and maintain disaster recovery plans for incidents and APT (advanced persistent threats) and act as a central point for their coordination;

User security awareness

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Identify training needs and awareness-raising on computer security and train employees in the application of preventive measures to limit security threats;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Ensure the awareness process for users through local and coordinated actions with BRD, SGA Romania and Sociandeacute;tandeacute; Gandeacute;nandeacute;rale Group.

And furthermore,

andnbsp;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Ensure Information Security Management in Projects according to Sociandeacute;tandeacute; Gandeacute;nandeacute;rale Group Methodology;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Provide security assessments for existing or potential suppliers in order to assess their security maturity level;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Prevent security incidents and mitigate their consequences by implementing security measures in the organizationandrsquo;s IT system;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Manage vulnerability and penetration testing processes and monitor action plans;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Manage recurrent security checks and alerts through SIEM and DLP applications.

andnbsp;

Profile required

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp;+5 years in cyber security positions and 10-15 years of experience overall in IT;

Soft skills:

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Team spirit, curious, proactive,

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Autonomous, rigorous,

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Risk-oriented,

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Able to disseminate IT security user awareness, user awareness oriented,

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Ability to see the global picture, good communication skills, Oral and written communication, English B2 (oral and written proficiency);

Technical skills:

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Advanced knowledge of risk analysis methodologies and security key topics (classification, AICT assessment, intrinsic/residual risks, risk scenarios);

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Knowledge and experience in risk analysis methodologies (e.g.: 27005, EBIOS,andhellip;);

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Knowledge of standards (ISO 2700x, ITIL, NIST, etc.) and security governance principles;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Knowledge of security best practices in the field of IT systems management (authorizations, data anonymization, incident management, authentication, backup, archiving, security patch management, antiviral updates, network partitioning, NAC, wifi, etc);

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Knowledge of security tool administration principles: firewalls, proxies, SIEM, DLP, IDS, IPS, vulnerability scanners like Qualys, IAM systems.

Other technical skills

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Knowledge in the following methods: Agile, DevOps, CI/CD, Github/Gitlab;

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Knowledge/experience in security architecture areas

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Security monitoring / understanding and knowledge of the main security threats (virals, cybercrime, APT) and their distribution methods.

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Possibly, experience of IT security audit missions

andmiddot;andnbsp;andnbsp;andnbsp;andnbsp; Security certifications (CISSP, ISO 2700x, NIST etc.)

Why join us

SG GSC is a Great Place to Workandreg; certified company. Here, you will find a flexible workplace and culture, autonomy, constant learning opportunities, dynamism, and talented people, making this experience a real career accelerator. You will also discover all the diversity of our businesses, in a sector that is constantly evolving and innovating.

Plus, you will enjoy all our benefits:

  • competitive compensation andamp; remuneration, including annual performance bonus;andnbsp;
  • preventive healthcare plan, and group health andamp; life insurance;andnbsp;
  • wide range of flexible benefits within a monthly budget;andnbsp;
  • office perks, wellbeing and mental health programs;andnbsp;
  • various social benefits and bonuses for personal or family events;
  • 9-to-5 workday andamp; flexible work environment: hybrid or fully remote if you are located outside Bucharest;
  • additional paid and unpaid time off, including Sabbatical leave;andnbsp;
  • learning and growth opportunities based on individual development and career plans;andnbsp;
  • unlimited access to various eLearning resources. andnbsp;
Business insight

We are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious. Whether youandrsquo;re joining us for a period of months, years, or your entire career, together we can have a positive impact on the future. Creating, daring, innovating, and taking action are part of our DNA.

If you too want to be directly involved, grow in a stimulating and caring environment, feel useful daily and develop or strengthen your expertise, you will feel right at home with us

Still hesitating-

You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices, and sharing their skills with charities. There are many ways to get involved.

We are an equal opportunities employer, and we are proud to make diversity a strength for our company. Societe Generale is committed to recognizing and promoting all talents, regardless of their beliefs, age, disability, parental status, ethnic origin, nationality, sexual or gender identity, sexual orientation, membership of a political, religious, trade union or minority organisation, or any other characteristic that could be subject to discrimination.



  • Bucharest, Bucureşti, Romania BNP Paribas Full time €100,000 - €120,000 per year

    REQUIREMENTS AND QUALIFICATIONS: From 12 years of experience in a combination of risk management, information security and IT development or operations jobs (at least five must be in a senior leadership role)Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate information security and...


  • Bucharest, Bucureşti, Romania Garanti BBVA Romania Full time 40,000 - 60,000 per year

    We are looking for a person whoIs experienced in "eye on the glass" and information security operationsHas a track record in managing cybersecyrity tools, techniques and technologiesHas been involved in cyber security incident response and digital forensics;Is knowledgeable of international information security standards and national specific regulations;Has...


  • Bucharest, Bucureşti, Romania SES Satellites Full time 60,000 - 120,000 per year

    Requisition Number: 18910Contract Type: PermanentLocation(s):Bucharest, ROEngineer, Cyber Security Engineering (Zero Trust)The job responsibilities outlined in this document are not exhaustive and may evolve over time and be reviewed according to business needs.Role Description SummaryIn this position you will be responsible for translating advanced security...


  • Bucharest, Bucureşti, Romania ManpowerGroup Full time 90,000 - 120,000 per year

    Manpower Romania, technical & engineering division is curently looking for aCyber Security Managerfor one of our clients located in Bucharest.In this role, you will drive the development and implementation of the cybersecurity strategy, manage key security resources, and ensure alignment with organizational objectives. You will act as a leader, mentor, and...


  • Bucharest, Bucureşti, Romania Mastercard Full time €100,000 - €120,000 per year

    Our PurposeMastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships...


  • Bucharest, Bucureşti, Romania Luxoft Full time 30,000 - 60,000 per year

    Project description Join our Development Centre in Bucharest and become a member of our open-minded, progressive and professional team. In this role you will be working for one of our world-famous clients. The Chief Security Office (CSO) of our client comprises the Chief Information Security Office (CISO) and the Corporate Security unit. The CISO...


  • Bucharest, Bucureşti, Romania Hipo Imports Full time €90,000 - €120,000 per year

    As a Sr Advanced Cyb Sec Archt/Engr here at Honeywell, you will play a pivotal role in designing, implementing, and maintaining advanced cybersecurity solutions to protect our critical assets. You will collaborate with cross-functional teams to develop and execute robust cybersecurity strategies, ensuring the security and resilience of our digital...


  • Bucharest, Bucureşti, Romania Intelsat Full time €40,000 - €80,000 per year

    Requisition Number: 18715Contract Type: PermanentLocation(s):Bucharest, ROSenior Analyst, Information Security ManagementROLE DESCRIPTION:We are looking for a Senior Analyst, Information Security Management to join the ISM team in our Bucharest locationIn this role, you will contribute to the development and continuous improvement of the SES information...


  • Bucharest, Bucureşti, Romania Adecco Full time 30,000 - 60,000 per year

    Cybersecurity SpecialistLocation: Romania | Full-TimeAre you passionate about defending systems, identifying vulnerabilities, and staying ahead of threats? We're looking for aCybersecurity Specialistto join our growing security team on a contract basis (1 year, with possible extension).If you're analytical, detail-oriented, and thrive in high-stakes...


  • Bucharest, Bucureşti, Romania UiPath Full time 120,000 - 240,000 per year

    Life at UiPathThe people at UiPath believe in the transformative power of automation to change how the world works. We're committed to creating category-leading enterprise software that unleashes that power.To make that happen, we need people who are curious, self-propelled, generous, and genuine. People who love being part of a fast-moving, fast-thinking...