- Company Name
- AXA XL
- Job Title
- Chief Security Officer
- Job Description
-
**Job Title:** Chief Security Officer
**Role Summary:**
Leads the development, implementation, and governance of operational resilience, cyber security, physical security, health & safety, and regulatory compliance for a global organization. Acts as senior advisor to executive leadership and board committees, driving security strategy, cultural change, and risk mitigation across all business units.
**Expectations:**
- Establish and maintain a robust security operating model aligned with group standards.
- Ensure full compliance with global regulations (e.g., NYDFS, CFIUS, HIPAA, GDPR, DORA, AI Act).
- Deliver measurable security performance against defined targets.
- Foster a security‑first culture and elevate board confidence in risk posture.
- Manage security budgets and optimize investment in technology, automation, and talent.
**Key Responsibilities:**
1. Define and execute AXA XL security strategy, standards, and policies.
2. Advise senior management on information security, operational resilience, physical security, and health & safety matters.
3. Oversee regulatory compliance and reporting for all relevant statutes.
4. Represent security functions to the Board and sub‑committees (Risk, Audit, Technology, ESG).
5. Lead continuous improvement of security services, leveraging AI, automation, and standardization.
6. Identify, assess, and mitigate security risks; develop remediation plans.
7. Drive cultural and organizational change to embed security awareness.
8. Manage talent development, training, and knowledge management within the security organization.
9. Develop, track, and control security budgets in coordination with senior leadership.
**Required Skills:**
- Proven global leadership in corporate security, risk management, or IT security.
- Experience managing multi‑country physical and cyber security operations, preferably in insurance.
- Deep knowledge of global regulatory frameworks and data protection laws (SOX, DORA, NYDFS, HIPAA, PIPL, etc.).
- Strategic vision with ability to influence board‑level decisions.
- Strong crisis management and decision‑making under pressure.
- Cross‑cultural agility and excellent stakeholder communication.
- Ability to build and lead high‑performing, accountable teams.
**Required Education & Certifications:**
- Bachelor’s degree in Information Security, Computer Science, Engineering, Business, or related field (Master’s preferred).
- Professional certifications such as CISSP, CISM, CRISC, MBCI, DRII, CPP, PSP, or equivalent.