AIM Authority M/F
Volkswagen Financial Services has been supporting the development of the Volkswagen Group brands - Volkswagen, Audi, Seat, Cupra, Skoda and Volkswagen Utilitaires - and their dealer networks for over thirty years. We thus play the role of a mobility vector for our end customers, individuals or companies, by providing them with a complete range of financing and leasing solutions, as well as complementary services and insurance adapted to customer needs. In 2023, for the 4th consecutive time, we were certified "Great Place to Work" and we are also ranked 18th in the Best Workplaces list. Find all the latest news from Volkswagen Financial Services on our LinkedIn space: https://www.linkedin.com/company/volkswagen-financial-services-france/mycompany/ Website: https://www.vwfs.fr/
As part of a replacement, our DSI is looking for an AIM Authority M/F.
Integrated within the GRC department, you will be responsible for the following missions:
- Process owner Access & Identity Management
- You will be the guarantor of compliance with ECB rules on access management
- You will ensure the maintenance of AIM rules and associated processes, and you will prepare the necessary evolutions in view of Headquarters evolutions
- You will support User Management or the business units in the review and improvement of their AIM processes
- You will ensure the reporting of process KPIs for local management and Headquarters
- You will assume the role of Access and Identity Management Authority (AIM Authority)
- Recertification and access control
- You will ensure the semi-annual review of access to applications and infrastructures, the periodic review of privileged access, as well as the periodic control of the use of privileged access (IT and business) or access modifications
- You will initiate and coordinate all stakeholders for certifications and the reconciliation of requests and rights within the systems
- AIM Review
- You will ensure the periodic control of the execution of AIM processes - You will perform ad hoc audits on AIM processes to ensure that the processes and their execution are compliant
- You will verify the security level of authentication mechanisms against protection needs
- You will ensure reporting to management and the LIRO
- You will follow up on improvement plans
- You will ensure the periodic review of authorizations concepts
- Segregation of Duties Management (Segregation of Duties)
- You will create and maintain comparison bases for the analysis of segregation of duties conflicts
- You will ensure a periodic review of segregation of duties conflicts
- Raising awareness among all employees
- You will assist projects and operations in the implementation of AIM
- You will explain and provide annual training on AIM to the process stakeholders
- Management of repositories and privileged access
- You will maintain the repositories of roles, privileged accounts, and shared users
- You will validate the compliance of roles
- Support IT GRC processes
You will contribute operationally to all IT GRC processes:
- G07 Manage Security
- G08 Manage Identity and Access
- G09 Manage Risk
- G10 Monitor, Evaluate & Assess Compliance
Profile sought You have a Master's degree (Bac+5): degree in information systems, certification in IS security management You have at least 5 years of experience in information security or IT security (both as a service provider and internally) Key skills: knowledge of IT security
process orientation, analytical spirit, transversality
sense of confidentiality
fluent English is essential
knowledge of Sailpoint IIQ and mastery of the Office suite
Position based in Roissy-en-France, teleworking possible at an average of 2.5 days per week