CDI - HQ IT Security Manager
Summary
The IT Security Manager coordinates security activities for Rexel's HQ and Shared Services, overseeing security solutions, vulnerability management, and compliance. The role involves managing security policies, collaborating with IT teams, and reporting to the CISO.
The role coordinates and is responsible for IT Security activities within Rexel's Group IT department and HQ / Shared Services, based in Paris, France. Key aspects of the mission include:
- Overseeing the operation of the enterprise's security solutions through the management of the organization's and third-party contract security analysts.
- Ensuring the confidentiality, integrity and availability of the organization's assets.
- Maintaining an enterprise security stance through policy, architecture and training processes.
- Participating in the selection of appropriate security solutions and overseeing vulnerability audits and assessments.
Main Responsibilities & Accountabilities
Here are the main responsibilities and obligations related to the position (non-exhaustive list):
Information Security
- Ensure and promote confidentiality, integrity and availability.
- Assurance, privacy and regulatory compliance.
- Information risk management and cybersecurity.
- Information technology systems controls.
- Identity and access management.
Governance, Operations & Delivery
- Lead the implementation of ISMS policies and coordinate PCI DSS compliance for HQ.
- Document and explain deviations from security standards.
- Relay any suitable information security awareness, training and educational activities.
- Manage continuous monitoring of network, system and application security controls effectiveness.
- Manage security alerts and vulnerability management for HQ and Shared Services.
- Oversee operational security and Azure security for HQ and Shared Services.
- Drive remediation follow-up and operational security KPI reporting.
- Organize and facilitate interdepartmental communication to identify and resolve security issues.
Critical Success Factors
- Work closely and collaboratively with the relevant HQ and Shared Services IT teams, and drive continuous improvement in IT Security within those organizations.
- Maintain current knowledge of relevant information security threats and technologies.
Current Context (Place of the Role in the Organization)
- The role reports directly to the CISO and is a member of the Group IT department.
- It interfaces with peers in the Infrastructure and Application departments, and with HQ business unit leaders, to share the corporate security vision
Critical Path & Key Challenges
- Promote IT Security within the defined areas of responsibility — not only within the IT teams, but also across the end-user community.
- Drive continuous IT Security improvements in Infrastructure and Applications.
- Work with the various HQ departments that play key roles in IT Security (for example Legal, Audit & Compliance, HR and Communications).
- Bachelor's degree required in Computer Science, Information Technology or a related field.
- A minimum of 5 years' experience in the ICT field, including security-related experience.
- Security certifications such as CISSP, CISM or CISSP-ISSMP are desired.
- English — fluent (required).
Competencies & Technical Skills
The profile of the role requires the following:
- Experience in both in-house and outsourced environments.
- IT infrastructure and Systems Development Life Cycle (SDLC) experience.
- A proven ability to manage security in large environments.
- Excellent communication skills.
- Experience working in cross-functional project teams and within hybrid internal and outsourced environments.
- The ability to manage multiple priorities and build effective delivery schedules based on business needs and technical requirements.
- Strong analytical and problem-solving skills.
- Experience delivering cross-functional security projects.
- Knowledge of a wide range of security systems in use at the organization
- Solid knowledge of PCI DSS and other IT security standards.
- Familiarity with ISO frameworks, as well as NIST standards.
- Demonstrated knowledge of common information technology platforms and standards.
Chez Rexel, nous pensons que notre succès dépend de vous. Nous vous aidons à développer vos connaissances et à explorer de nouveaux domaines au sein de l'entreprise et dans le cadre de votre développement de carrière.
Nous sommes conscients de notre responsabilité sociale et nous nous engageons en faveur de l'égalité et de la diversité dans notre environnement de travail. Ensemble, nous pouvons créer un avenir meilleur. Postulez maintenant et profitez de cette opportunité de croissance et de développement.