- Location
- San Jose, CR
- Type
- Full-time
- Department
- Management
- Seniority
- Entry
- Experience
- 5+ years
- Closing date
- Today
- Source
- iCIMS
Description
Company Description
Publicis Re:Sources is the backbone of Publicis Groupe, the world's most valuable agency group. We are the only full-service, end-to-end shared service organization in the industry, enabling Groupe agencies to do what they do best: innovate and transform for their clients.
Formed in 1998 as a small team to service a few Publicis Groupe firms, Publicis Re:Sources has grown to 6,000+ employees in over 55+ countries. We provide technology solutions and business services including finance, accounting, legal, benefits, procurement, tax, real estate, treasury and risk management. Our people are at the center of everything we do, bringing curiosity, collaboration, and a commitment to excellence to their work every day.
We continually transform to keep pace with our ever-changing communications industry and thrive on a spirit of innovation felt around the globe. Learn more about Publicis Re:Sources and the Publicis Groupe agencies we support at Publicis Resources – A Publicis Groupe Company.
Overview
Objective:This role shapes and helps execute security strategy in a global, fast-moving environment where security decisions must align with business goals, platform risk, and regulatory expectations.
The position suits a practitioner who can move between strategic analysis and capability-level architecture governance: defining where the security ecosystem needs to go, where it overlaps or has gaps, and how the capability portfolio should evolve over time.
Responsibilities
Responsibilities:
Security Strategy
- Support the Director of Security Strategy and Innovation in executing strategic security priorities across programs, platforms, and business initiatives.
- Prepare briefing materials, maturity assessments, and decision support content for leadership audiences.
- Track strategic initiatives, capability gaps, and roadmap commitments to support program execution and follow-through.
Enterprise Security Architecture Governance
- Operate at the security ecosystem or urbanism level: define target-state security capabilities and how they fit together across the enterprise.
- Identify capability gaps, overlaps, and redundancies across the security portfolio, and recommend what to add, enhance, consolidate, or retire.
- Shape and maintain the strategic roadmap for security capabilities, aligned to business needs, risk priorities, and technology trends.
- Ensure the overall security architecture evolves coherently, rather than reviewing individual applications, solutions, or cloud deployments, which sit with the solution and operational architecture function.
- Apply structured analysis using frameworks such as ISO 27001, NIST, and MITRE ATT&CK to support capability and roadmap decisions.
Operating Model and Capability Strategy
- Help define the operating model for strategic initiatives, including how capabilities move from strategy into ongoing operations.
- Develop RACIs and end-to-end process definitions that span the teams involved in running each capability.
- Translate target-state capability decisions into clear ownership, sequencing, and dependencies for the teams that execute them.
Innovation Workstreams
- Support the evaluation of new security technologies, AI-enabled tools, automation opportunities, and process improvements relevant to current risk priorities.
- Contribute to pilot efforts that test security tooling, operating models, or analytical methods before broader rollout.
- Assess whether proposed innovations reduce measurable risk, improve visibility, or strengthen program maturity at the capability level.
Threat and Stakeholder Support
- Monitor threat trends and adversary behaviors that may affect enterprise, cloud, identity, API, and data security capabilities.
- Work with security operations, incident response, compliance, privacy, legal, and business teams to align capability strategy with operational lessons and regulatory obligations.
- Communicate capability gaps, risks, and roadmap recommendations clearly to both technical and non-technical stakeholders.
Qualifications
Required Qualifications
- 5 to 8 years of experience in security strategy, enterprise security architecture, risk management, or related security roles.
- Strong understanding of cloud security across Azure, AWS, and GCP at the capability and control-design level, including common failure modes.
- Experience with capability assessment, target-state architecture, threat modeling, and risk analysis.
- Working knowledge of ISO 27001, NIST CSF, and MITRE ATT&CK.
- Strong written and verbal communication, with the ability to present concise recommendations to leadership and partner teams.
Additional Information
Preferred Qualifications
- Experience in defining security capability roadmaps or operating models across multiple teams.
- Experience with security automation, analytics, or AI-supported security workflows.
- Background in incident response, forensics, threat intelligence, or compliance coordination.
- Familiarity with zero trust principles, identity and access management, secure SDLC, and privacy-aligned control design.
- Experience working across global teams with multiple stakeholders and competing priorities.