Informations générales
Description
Job Title: Cyber-Program Audit Expert
Department: CS2R / P&PM
About Business line/Function:
BNP Paribas Cardif is the insurance subsidiary of BNP Paribas. We are a worldwide leader of the Credit Protection Insurance market with strong positions in savings and protection insurance in more than 30 countries in Europe, Asia and Latin America.
Within CS2R (Cyber Security, Risks and Resilience direction of BNP Paribas Cardif), the Programs and Performance Management (P&PM) team oversees the implementation of the “Cyber Program” across all entities. The team steers the deployment of the program, validates with the management and the stakeholders the strategy to manage the Group priorities. It defines the CARDIF steering organization and manages the Cyber Panorama and associated committees. It validates the evidence provided by entities and provides support to entities. The team provides centralized visibility; tracks progress regarding entities’ commitments and alerts on any risks of shift.
Position Purpose:
The Cyber Program of Cardif is globally monitored and followed globally by the Programs & Performance Management (P&PM) Department of the CS2R Direction.
The objectives of the Cyber Program must be implemented by all Cardif subsidiaries worldwide. There are 25 subsidiaries. Subsidiaries of Asia, Europe and Latam are grouped in ETO regions. We have 3 subsidiaries (Japan, Taiwan and South Korea) in Region Cardif Asia and 12 in region Cardif EMEA (Europe) and 6 in Latin America.
The cyber-program audit expert works for CS2R / P&PM team, and review and validate the evidence provided by Cardif entities to confirm the requirements of the cyber program are implemented.
contributes to ensure the adequate progress of Cardif entities, the completion of their delivery and the achievement of our cyber objectives.
The role will focus on the analysis and validation of the evidence provided by the entities of one or several regions of BNP Paribas Cardif.
The evidence provided cover the various cyber topics managed in the program: Application security and configuration, Access and right management, Network access and segmentation, Data Security, Cryptography, Secure development, Logging for Security, Backup, IT continuity and resilience, Vulnerability management, Cyber risks links to third parties (TPTRM).
Responsibilities
Direct Responsibilities
- works closely withCardifRegional organization to follow the implementation of Security procedures and security rules on Information System.
- will be the Cyber Program SPOC for regional entities on different layers of Cybersecurity domains: Application security, IAM, Vulnerability management, Data Security…
- analyses and validates inthe tool Service Now the evidence provided by entities & updates progress in the Service Now tool.
- exchanges with regional and local (entity level) IT Security Officers and regional / local actors to define action plans, steer the implementation of the actions, assessthe risks.
- updates follow-up documentationpermitting toCyber Program director to have visibility on the deployment progress and to identify the main risks.
- prepares or contributes to the quarterly Cyber Program steering committee of the perimeter followed
- reports regularly to P&PM Cyber program coordinator and Head of P&PM & informs and/or alerts the management about schedule and delivery deviations. participates to thedifferent meetings organized by the P&PM team.
Contributing Responsibilities
- contributes to the definition of the cyber roadmap of a or several CardifRegion.
- shares knowledge about cyber program requirement with all the members of P&PM team
- contributes to Cyber Security risk assessments with the support of ITRO team to permit to the management to prioritize the activities
- contributes to the quarterlyCardifGlobal cyber program steering committee and the other committees which oversee the activity (Ex: Cyber Panorama, Lateral Movement steerco
Technical & Behavioral Competencies
- Minimum 3 years’ experience in Cyber Security
- IT and Information Systems Knowledge
- Very good oral and written English (nice to have)
- Knowledge of Service Now (nice to have)
- Ability to support organizations in multi-cultural landscape and to support cyber security specialists (Chief Information Security Officers and their teams)
- Autonomy, Sense of initiative
- Analytical skills
- Rigorous and Structured, Strong analytical and synthesis skills
Specific Qualifications:
Minimum 5 years of experience along with Master Degree or equivalent experience.
Skills Referential (Required knowledge, skills and abilities)
Technical Skills:
- Cyber Domain Specialization
- IT andInformation Systems knowledge
- Service Now
- IT Risk Assessment & Reporting
Behavioral Skills:
- Attention to detail / rigor
- Ability to synthetize / simplify
- Ability to deliver / Results driven
- Ability to collaborate / Teamwork
Transversal Skills:
- Ability to understand, explain and support change
- Ability to inspire others & generate people's commitment
- Analytical Ability
- Ability to develop and leverage networks
Education Level: Master Degree or equivalent
Location: Chennai or India
About BNP Paribas Group:
BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.
About BNP Paribas India Solutions:
Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.
Commitment to Diversity and Inclusion
At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.