Leave us your email address and we'll send you all the new jobs according to your preferences.

Cloud Security Engineer

Posted 5 hours 23 minutes ago by AXA Group

£70,000 - £90,000 Annual
Permanent
Full Time
Other
London, United Kingdom
Job Description
Cloud Security Engineer, AXA DCP Location: London - UK / Paris - France / Milan - Italy / Barcelona or Madrid - Spain / Wroclaw - Poland

AXA's Management Committee is driving a unique strategic initiative - Digital Commercial Platform (DCP) - designed to transform AXA's value proposition. Through DCP, AXA will serve existing and new clients and partners through an evolving business model, where the focus is on risk prediction, prevention and management.

AXA DCP relies on creating a platform of AXA's risk insights, risk management, and risk prevention capabilities to enhance and support our service offering to commercial clients and third parties. End users will be able to access a broad selection of data built on existing or developing AXA assets. The platform will also create value by monetizing unique capabilities and services for our customers, aggregating, and delivering insights from unique data sets with external partners, and fostering end-customer relationships in alignment with brokers.

AXA DCP aims to:
  • Improve our underwriting pricing and claims capabilities across the commercial lines book of business of AXA Group
  • Create a platform for risk management and prevention services
  • Build an ecosystem of business partners
As Cloud Security Engineer, your main mission will be to ensure the security and integrity of our applications and infrastructure in the cloud. You will be responsible for implementing and supervising security architectures and controls throughout the software development lifecycle, collaborating closely with development and operations teams to enforce security standards.

DISCOVER your opportunity What will your essential responsibilities include?
  • Act as a trusted advisor for solution architects and development teams, providing approval and guidance on secure practices and patterns
  • Conduct security assessments and audits, identifying potential risks in software and cloud blueprints and proposing improvements
  • Design, maintain and integrate security into the CI/CD pipeline, automating security checks and testing processes following the principle "Shift Left"
  • Establish and monitor KPIs and KRIs related to infrastructure and application security in an AWS context.
  • Engage with stakeholders (especially Technology office, Product Office and data management team) to facilitate and manage resolution, with tracking of work to report on progress
  • Utilize a variety of DevSecOps tools (Qualys WAS, CheckMarks SCA for SAS & DAST, Checkov) and cloud services (AWS Inspector, GuardDuty, CloudTrail, IAM, Config, SecurityHub, WAS Manager) to identify, assess, prioritize and manage security vulnerabilities across the organization's applications, systems and networks to automate and standardize configurations
  • Foster strong partnerships with other teams (internal and external) to enhance the organization's overall security posture and minimize potential threats and to identify threats, vulnerabilities, and control improvements
  • Support the stakeholders to enable informed decision making
  • Design, implement and improve secure coding related practices, processes and standards
  • Collaborate with development and operations teams to implement security controls and best practices in the development and deployment processes
  • Participate in development and continuous improvement of security processes, policies, standards and other governing documents and ensure compliance.
  • Participate in and support delivery of security audits, threat modelling and assessments and remediation of findings
  • Participate to AXA DCP Architecture Review Board and other governance bodies/meetings related to Security activity
  • Perform in-depth analysis of application code and infrastructure, architecture, and configurations to ensure compliance with security standards
  • Assist in the investigation and resolution of security incidents in Production and Non Production environments
  • Define and implement Infrastructure as Code patterns and practices using Terraform in the context of AWS
You will report to the Chief Security Officer, AXA DCP.

SHARE your talent We're looking for someone who has these abilities and skills:

Required Skills and Abilities
  • General skills
  • At least 6 years of proven experience in IT security engineering, cloud security engineering or related roles (offensive security, blue team, red team, etc)
  • Good understanding of security standards such as ISO 27001, GDPR, OWASP Top 10, OWASP SAMM, OWASP ASVS, common web application vulnerabilities and security best practices (API Security, Container Security, Cloud Security)
  • Knowledgeable with some hands on experience on everything related to security on Amazon Web Services (AWS)
  • Experience with security architecture, Cloud technology and threat modelling
  • Self driven qualities and able to work independently with a high degree of autonomy, as well as part of a team
  • You are fluent in English
  • Good communication (verbal/written) and influencing skills, with an ability to manage internal and external relationships up to senior levels of management
  • Will be a plus:
  • Security Certifications (e.g., CISM, CISSP)
  • Cloud Certifications (e.g. AWS Solutions Architect level Associate or higher, AWS Security Specialty)
  • Auditing and Compliance Certifications (e.g., CISA)
  • Experience with machine learning tools and models
  • Cloud Security (Ideally in AWS)
  • Strong technical understanding of Cloud Security using serverless and containerized architectures
  • Experience with scalable secure architectures for applications and networks deployed in cloud environments
  • Significant knowledge on implementing tools and processes to improve automation and potential vulnerabilities and risks
  • Experience using Infrastructure as Code engines, such as Terraform, in cloud environments
  • Application development
  • Experience application development in Python and TypeScript/JavaScript that are the main programming languages used by the team
  • Experience in relational and NoSQL databases
  • Experience in secure software development practices
FIND your future AXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. For mid-sized companies, multinationals and even some inspirational individuals we don't just provide re/insurance, we reinvent it.

How? By combining a comprehensive and efficient capital platform, data-driven insights, leading technology, and the best talent in an agile and inclusive workspace, empowered to deliver top client service across all our lines of business - property, casualty, professional, financial lines and specialty.

With an innovative and flexible approach to risk solutions, we partner with those who move the world forward.

Learn more at

Inclusion & Diversity AXA XL is committed to equal employment opportunity and will consider applicants regardless of gender, sexual orientation, age, ethnicity and origins, marital status, religion, disability, or any other protected characteristic.

At AXA XL, we know that an inclusive culture and a diverse workforce enable business growth and are critical to our success. That's why we have made a strategic commitment to attract, develop, advance and retain the most diverse workforce possible, and create an inclusive culture where everyone can bring their full selves to work and can reach their highest potential. It's about helping one another - and our business - to move forward and succeed.
  • Five Business Resource Groups focused on gender, LGBTQ+, ethnicity and origins, disability and inclusion with 20 Chapters around the globe
  • Robust support for Flexible Working Arrangements
  • Enhanced family friendly leave benefits
  • Named to the Diversity Best Practices Index
  • Signatory to the UK Women in Finance Charter
Learn more at /about-us/inclusion-and-diversity. AXA XL is an Equal Opportunity Employer.

Sustainability At AXA XL, Sustainability is integral to our business strategy. In an ever changing world, AXA XL protects what matters most for our clients and communities. We know that sustainability is at the root of a more resilient future. Our 2023-26 Sustainability strategy, called "Roots of resilience", focuses on protecting natural ecosystems, addressing climate change, and embedding sustainable practices across our operations.

Our Pillars:
  • Valuing nature: How we impact nature affects how nature impacts us. Resilient ecosystems - the foundation of a sustainable planet and society - are essential to our future. We're committed to protecting and restoring nature - from mangrove forests to the bees in our backyard - by increasing biodiversity awareness and inspiring clients and colleagues to put nature at the heart of their plans.
  • Addressing climate change: The effects of a changing climate are far reaching and significant. Unpredictable weather, increasing temperatures, and rising sea levels cause both social inequalities and environmental disruption. We're building a net zero strategy, developing insurance products and services, and mobilizing to advance thought leadership and investment in societal led solutions.
  • Integrating ESG: All companies have a role to play in building a more resilient future. Incorporating ESG considerations into our internal processes and practices builds resilience from the roots of our business . click apply for full job details
Email this Job