Position Purpose Leveraging BNL and BNP Paribas Paris teams expertise and ISPL IT skills, the goal is to enable applications flawless production by providing secure and stable environments and by ensuring that all actions on production environments are done in a controlled manner.
As part of strengthening the protection of its IT systems and the implementation of its Cyber Security
programme, BNL and the BNP Paribas Group implements and operates a number of security solutions.
The main duties of the Operational Security Engineer are:
Carrying out operations supported by the security solutions
Operating the IAM security solutions in functional and/or technical terms
Supporting Patching and AV operations
Providing help and support to users
The teams scope will be expanded in the future beyond the first set of described activities. The team is also expected to work closely with their BNL and BNP Paribas colleagues to integrate new technologies, especially related to the new generation BNP Paribas Cloud and DevOps methods & toolchains.
Responsibilities
Direct Responsibilities For IAM and Patching AV scope, take care of:
o Incidents
o Requests
o Changes
Ensure that SLA targets are met for above activities
Handover to Italian teams if knowledge and skills are not available in ISPL
Coordinate closely with Rome IT Production Security Team and all other BNL BNP Paribas IT teams (Incident coordination, Security, Infrastructure, Development teams, etc.)
Contributing Responsibilities Contribute to the knowledge transfer with BNL Production Security team
Contribute to the definition of procedures and processes necessary for the team
Help build team spirit and integrate into BNL BNP Paribas culture
Contribute to incidents analysis and associated problem management
Contribute to the regular activity reporting and KPI calculation
Contribute to continuous improvement actions, especially the lessons learned from handovers to Paris
Contribute to the acquisition by ISPL team of new skills & knowledge to expand its scope
Technical & Behavioral Competencies Expertise in cybersecurity frameworks and practices (ISO27001, DORA, NIST, NIS2)
- Solid understanding of cloud security (GCP and/or AWS)
- Knowledge of container security (Docker, Anchore)
- Developing, evolving, and enforcing security policies and incident response plans
- Assisting with the implementation of security measures for both external and internal systems
- Knowledge of IAM/PAM systems (es. Cyberark)
Multifactor authentication MFA
Automation solution: Jenkins and Ansible tool
Knowledge of Operative system (Microsoft, Unix, RACF)
Knowledge of Middleware (Oracle, DB2, MSQL)
Power Shell, REXX, Cobol, CICS, JCL
Experience with Service Now ticketing system
Fluent in English (both written and spoken)
- Excellent communication-skills to work constructive and in cooperation with internal and external teams
- Good degree of responsibility and autonomy
Preferable:
Python
Specific Qualifications (if required) Basic knowledge of Italian language can be an advantage
Skills Referential
Behavioural Skills : (Please select up to 4 skills)
Ability to collaborate / Teamwork
Client focused
Ability to deliver / Results driven
Ability to share / pass on knowledge
Transversal Skills: (Please select up to 5 skills)
Analytical Ability
Ability to set up relevant performance indicators
Ability to develop and adapt a process
Ability to understand, explain and support change
Choose an item.
Education Level:
Bachelor Degree or equivalent
Experience Level
At least 3 years