Informação geral
Descrição
Tribe Security Officer
Based in Warsaw, hybrid working (50/50)
At least 5 years experience
English mandatory
About the Team
Arval IT is an international IT organization, with a workforce of around 1 000 internal and external professionals located in several countries (France, UK, Netherlands and other). As part of our sourcing strategy, we are expanding our nearshoring capabilities by establishing a new Arval Technical Center (ATC) in Poland, within an existing business operations shared service center (Arval Competence Center Warsaw, ACCW). This Arval Technical Center plays a strategic role in the development of digital expertise, and internalization of key competencies currently handled by external partners.
Arval Competence Center Warsaw is the latest initiative of the BNP Paribas group, which aims to develop competences and business services. Currently, ACCW employs over 90 people who, every day, in various languages, help Arval Group entities to efficiently serve Clients and Partners. In ACCW, solutions are being created that aim to streamline the customer and supplier verification processes. The center specializes, among others, in credit analyses and KYC analyses, and also performs tasks in the field of HR data administration and internal control.
Arval Cybersecurity & IT Risks CoE (Center of Expertise) aims at:
- Providing guidance on IT security and ensuring its implementation (through the information system security policy),
- Assessing risks, threats and their consequences and draw up a prevention plan,
- Making all ARVAL employees aware of cyber security,
- Providing recommendations to project managers on the security of their applications and deciding to audit some of them if necessary.
- Managing Cybersecurity incident through a dedicated CSIRT team, integrated in BNP Paribas CSIRT global organization.
Cybersecurity & IT Risks CoE team is composed of around 50 professionals, located today mainly in Rueil Malmaison France.
Duties - Responsibilities
We are looking for a Tribe Security Officer who will oversee security, IT risks, governance, IT continuity within the perimeter of one or two tribes.
A tribe can have up to 100 agile members who design, develop, test and maintain a portfolio of applications.
Activities
Considered as «local CISO” for the perimeter for which it is responsible, the Tribe Security Officer will:
- Ensure the deployment of Arval’s security, continuity, IT risks and Third-party risk management policies in the tribe.
- Influence decisions in line with security objectives.
- Evaluate / formalize IT risks and mitigation measures
- Monitor remediation plans
- Promote security through DevSecOps concepts and ensure that applications are embedded in security tools when they are eligible (SAST, AVS, PENTESTS, SCA)
- Participate in the remediation of vulnerabilities
- Contributes to Sprint Planning and Backlog Review whenever required
- Provide reports on the security level / vulnerabilities of applications within its scope to the CoE IT Risk and Cyber Security
- Share best practices with the IT & Cyber Security central team and other Tribe Security Officers
- Provide evidence for internal control plan and audits
Expertise and skills
Business Skills
- IT Knowledge
- Cyber Security
- IT Risk Management
- Data Quality & Security
- Risk Anticipation, Monitoring
TRANSVERSAL SKILLS
- Analytical ability
- Ability to anticipate business / strategic evolution
- Ability to inspire others & generate people's commitment
- Ability to develop and leverage networks
- Ability to understand, explain and support change
BEHAVIOURAL SKILLS
- Ability to collaborate / Teamwork
- Creativity & Innovation / Problem Solving
- Adaptability
- Ability to Deliver / Results Driven
- Attention to detail / Rigour
COMMON BASE TOOLS|methodologies
- Specific to IT Risk & Ciber
Specific SKILLS
- Proven You have at least 5 years’ experience in cyber security or IT risk management
- You are comfortable in the international environment and speak English fluently
- You're autonomous, agile, able to meet deadlines
- Certifications such as ISO27005,22301, CISPS will be a plus
Poste-type and Location
Arval Department: ACCW IT
BNP Paribas Job type: Tribe Security Officer
Location: based in the local country/regions (Poland)
We inform you that Arval Service Lease Polska Sp. z o.o. and Arval Competence Centre - Arval Service Lease Polska Sp. z o.o. Branch in Warsaw have an internal procedure for reporting breaches of law and taking follow-up actions (Whistleblowing Procedure), which is available on the Arval Service Lease Polska Sp. z o.o. website: https://www.arval.pl/ogolne/whistleblowing