Deputy Chief Information Security Officer M/F

Vacancy details

General information

Organisation

At 31 December 2023, the Dexia Group will have around 500 members of staff. In addition to Brussels and Paris, the Group has a limited international presence in Ireland, Italy and the United States.
The Dexia Group is in orderly resolution as a bank until 31 December 2023. In July 2023, the Group applied for the withdrawal of the banking and investment services authorisations of Dexia (formerly Dexia Crédit Local), which was approved by the European Central Bank in December 2023, with an implementation date of 1 January 2024.
Since 1 January 2024, Dexia (formerly Dexia Crédit Local) has therefore continued its orderly resolution as a non-bank.
Dexia offers great diversity and a real transversality of business lines and missions which enrich the professional experience of its members of staff.

Joining Dexia is a promise to evolve in a dynamic environment and to stimulate your career by developing new skills!

  

Reference

2026-467  

business

Deputy Chief Information Security Officer

Position description

Job title

Deputy Chief Information Security Officer M/F

Contract type

CDI

Job description

The Deputy CISO assists the CISO in defining, implementing, steering and monitoring the Dexia Group’s information systems security and business continuity framework.

He or she contributes both operationally and strategically to IS/BCP governance, the management of cyber and ICT risks, the handling of security incidents, as well as the monitoring of transformation projects and critical service providers within the scope of cybersecurity and crisis management.

Principal tasks
Governance, risks and compliance
·      Contributing to the definition and updating of policies, procedures and frameworks relating to Information Systems Security (ISS) and Business Continuity Planning (BCP).
·       Participating in the assessment and monitoring of ISS/BCP risks (risk mapping, Cyber RCSA (Risk & Control Self-Assessment), key risk indicators (KRIs)).
·       Coordinating and monitoring remediation plans relating to cyber and business continuity risks.
·      Coordinating the various stakeholders (suppliers, service providers, partners, etc.) involved in Dexia’s cybersecurity.
·      Contributing to interactions with internal audit, compliance, ongoing control and supervisory authorities (ACPR, AMF, etc.) where applicable.

Operational security management
·       Helping to integrate security into projects (risk analyses, security questionnaires, architecture committees).
·       Monitoring security controls: identity and access management (IAM), authorisations, logical access, and recurring checks.
·       Contributing to the analysis, management and monitoring of security and business continuity incidents.
·       Leading the development of security indicators (KRIs, information security/business continuity management dashboards) for management and governance bodies.
·       Overseeing projects to strengthen cyber security and the dedicated teams.

Business continuity and crisis management
·            Helping to define, update and test Business Continuity Plans and Disaster Recovery Plans (BCP/DRP).
·            Supporting business departments in defining their continuity requirements (RTO, RPO, process criticality).
·            Participating in the preparation of crisis scenarios and associated exercises (please specify which ones…).

Coordination and representation
·       Participating in internal IS Security/BCP steering committees (CPSSI) and security committees with external service providers and partners.

·       Contributing to strategic transformation projects from an information security and business continuity perspective.

·  Monitoring methodological, regulatory and technological developments in cybersecurity (DORA, AI Act, NIST, ISO 27001 standards, etc.).

·       Acting as backup to the Chief Information Security Officer (CISO) in their absence.

Profile

Training
·       Higher education qualification (Engineering degree, Master’s degree) in Information Systems or Cyber Security.
·       Recognised professional certification in cyber security: CISSP, CISM or equivalent.
·       Desirable certifications: CCSP, ISO/IEC 27001 Lead Implementer or Lead Auditor.

Experience
·       Substantial experience in information systems security (10 to 15 years), gained in a regulated environment (banking, insurance, the financial sector) or at a specialist consultancy firm.
Technical and functional skills
·       A solid grasp of information security concepts, cyber risks and business continuity.
·   Knowledge of frameworks and standards (ISO 27001/27002, NIST, cyber best practices).
·       Ability to manage risks, indicators and action plans.
·      Understanding of IAM issues, access management, infrastructure security and service provider security.

Additional skills
·       Strong analytical and summarising skills.
·       Intellectual rigour, organisational skills and reliability.
·      Excellent communication and influencing skills when dealing with a wide range of stakeholders (management, business units, IT department, partners, regulators, etc.).
·      Ability to work across departments with stakeholders from business units, IT and internal audit.

Languages
·       Fluent to professional-level English (spoken and written) is essential.
 
 
Key aspects of the post
·       Direct contribution to the Group’s cyber risk management and business continuity.

·       A key role in information security governance and operational resilience.

·       Acting as stand-in for the CISO during their absence.

Position location

Job location

Europe, France, Ile-de-France

Location

1, passerelle des reflets 92400 Courbevoie