Job
Description
Company description Resources is the backbone of Publicis Groupe, the world s third-largest communications group.
Formed in 1998 as a small team to service a few Publicis Groupe firms, Re:Sources has grown to 5,000+ people servicing a global network of prestigious advertising, public relations, media, healthcare, and digital marketing agencies. We provide technology solutions and business services including finance, accounting, legal, benefits, procurement, tax, real estate, treasury, and risk management to help Publicis Groupe agencies do their best: create and innovate for their clients. In addition to providing essential, everyday services to our agencies, Re:Sources develops and implements platforms, applications, and tools to enhance productivity, encourage collaboration, and enable professional and personal development. We continually transform to keep pace with our ever-changing communications industry and thrive on a spirit of innovation felt around the globe. With our support, Publicis Groupe agencies continue to create and deliver award-winning campaigns for their clients. Overview JOB SUMMARY: This position is an active member of the Global Security Office (GSO), the security organization of Publicis Groupe under Re:Sources, responsible for supporting security management and compliance activities globally to Groupe agencies. This position supports security requirements of Publicis Groupe, it s agencies, and ensures the success of business by working collaboratively with internal and external stakeholders. This position also coordinates dependencies across the disciplines and organization to understand and address the ever-changing security landscape and security-related business requirements. This position reports into Sr. Manager/Manager Information Security The responsibilities associated with the position are as follows: Work as an individual contributor in Global team to support Global ISO 27001/ISMS program Support in implementation of the ISO 27001 standard for new teams, functions and locations. Perform Gap analysis, drive control implementation, risk assessments, security audits and other activities that are part of ISMS maintenance Interfaces with corporate governance, internal and external auditors. Actively participates and contributes in continual improvement activities for Security Certification, Risk and Compliance prograM Works as security point of contact to help agencies in implementation of new security certifications, primarily ISO 27001, TISAX and other security requirements as determined by business needs. Contributes to the broad range of global Information security and risk mitigation initiatives as guided by the Leadership of the Global Security Office teaM Sets and measures security effectiveness in line with services provided by GSO to Groupe agencies. Perform key compliance activities such as Control gap assessments, Internal security audits and security risk assessments Advise business or operational teams on implementation of administrative, physical and technical security controls required for security policy adherence and compliance. Coordinates the implementation of security controls. Contributes to continual improvement of Publicis Groupe s security policies, standards and guidelines. Gets involved in security documentation on a regular basis as an author or reviewer. Maintains awareness of the current industry environment that shapes opportunities for client solutions (i e news events, trends, mergers, etc). Contributes to the security awareness initiatives by publishing security bulletins, blogs, newsletters, etc OTHER JOB REQUIREMENTS: Good communication and presentation skills Ability to work effectively and collaboratively with stakeholders. Willingness to work with geographically dispersed teams may involve working during non-business hours occasionally to accommodate time-zone differences. Travel: This position will periodically require you to visit office, especially during internal and external audits. Experience At least 5 years of IT and / or information security-related experience, including experience in implementation and managing a security program based on ISO 27001 or any other well-known security standard or framework. Experience in working for an ISMS (ISO 27001) implementation and maintenance prograM Familiarity with general information security controls, processes and principles. Experience with technology security solutions such as cyber security solutions such as CSPM (Cloud Security Posture Management), CASB (Cloud Access Security Brokers), CWPP (Cloud Workload Protection Platforms), and Cloud-Native Application Protection Platform (CNAPP). Exposure in supporting risk and compliance programs for public cloud solutions (AWS, Azure, SaaS solutions), latest server & network infrastructure and databases based on relevant security requirements. Worked on standards and frameworks like TISAX, SOX, SSAE 16, PCI:DSS, SOC1/2, NIST CSF, Cloud security standards (CIS, CSA). Exposure to Data Security Posture Management (DSPM) solutions and practical usage of AI solutions in security. Responsibilities ESSENTIAL JOB REQUIREMENTS: Partner with stakeholders to plan, implement, operate and improve various ISO 27001 programs Coordinate with different technology groups for control design and implementation needs Maintain a support role in information security control implementation and technology risk mitigation projects. Implement improvement program for security compliance processes. Possess essential project management skills to drive ISO 27001 implementation projects Demonstrate communication skills regarding essential security risk and compliance concepts, processes, and procedures and their impact on IT and business processes. Demonstrate interpersonal, presentation, and relationship skills required for supporting the internal and external customers. Mandatory language skills (oral, written and listening) : English Qualifications Education & Certifications Degree from an accredited University, preferably in Computer Science, Information Systems, or a related field; relevant working IT or security experience considered. Education and experience should also include auditing and/or operational risk management exposure. Security certification such as CISM, ISO 27001 Lead Implementer, CCSK, CISSP or CRISC strongly preferred Additional information Core Competencies Team Work Project management Communication Results Driven Customer Focus Relationships Adaptability to Change Continuous Improvement Technical Competencies Security certification implementation Security Audits Security Risk Assessments Security Documentation Knowledge of eGRC Solution (such as OneTrust, Archer, etc)