Source description
About the role
· Support the day-to-day operational InfoSec activities for a customer unit, aligned to SG global standards and security policies. · Perform risk analysis of new business processes and solutions, providing practical security recommendations. · Conduct and support Application Sensitivity Assessments (ASA) and Secure by Design (SBD) evaluations. · Collaborate with Application owners to complete Secure by Design (SBD) process prior to production deployment. · Support the Entity ISOs and Application Owners & Managers for compliance to meet Group KRIs by providing expertise support, collaborative follow-ups. · Ensure adherence to industry standards such as NIST, ISO/IEC 27034, OWASP Top10, etc and regulatory requirements such as GDPR, AAS. · Efficient enough to manage NIST Barometer Assessments for NORDICS and to meet Group Target for 2026 . · Collaborate with development Teams to embed security best practices into software development life cycle (SDLC) · Manage and respond to Information Security Incidents, in collaboration with internal and global teams. · Perform RAF (Risk Acceptance Framework) and exception management workflows. · Deliver and support security awareness programs, including sessions and campaign planning. · Liaise with application, infrastructure, and business teams to drive Infrastructure/Hardening and application security control implementations.
More at Societe Generale