Назад
Company hidden
7 дней назад

IT Security Officer (DORA/Cyber Risk)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Luxembourg
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT Security Officer (DORA/Cyber Risk): Providing independent second-line oversight and assurance for information security, ICT risk, cyber resilience, and technology controls across Luxembourg-regulated financial services with an accent on DORA, CSSF expectations, and third-party ICT risk. Focus on challenging control design and effectiveness, performing risk assessments, overseeing incidents and remediation, and preparing risk reporting for management, committees, and boards.

Location: Munsbach, Luxembourg

Company

hirify.global is a global fund administration and middle office solutions provider established in Bermuda, with approximately 13,000 employees across 112 offices.

What you will do

  • Provide independent second-line oversight and challenge across information security, ICT risk, cyber resilience, and technology controls for Luxembourg entities.
  • Review control design, testing results, remediation plans, policy exceptions, and risk acceptances.
  • Perform information security and ICT risk assessments, control assurance reviews, thematic reviews, and independent risk opinions.
  • Support DORA oversight, including ICT risk management, incident management, resilience testing, and ICT third-party risk.
  • Oversee risks related to outsourcing, cloud, SaaS, and critical ICT service providers, including due diligence, contractual controls, exit arrangements, and ongoing monitoring.
  • Report material risks, incidents, vulnerabilities, audit findings, and remediation status to management, risk committees, boards, regulators, and other stakeholders.

Requirements

  • 7+ years of experience in information security, ICT risk, technology risk, cyber risk, internal control, audit, or technology assurance in financial services or another regulated environment.
  • Strong understanding of second-line oversight, independent challenge, risk governance, and control assurance models.
  • Good knowledge of DORA, CSSF ICT and cyber risk expectations, outsourcing requirements, operational resilience, and technology risk management in EU or Luxembourg-regulated financial services.
  • Practical knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, CIS Controls, or equivalent frameworks.
  • Experience with risk assessments, control reviews, gap assessments, remediation tracking, management reporting, and regulatory or audit engagements.
  • Fluent business English required. French, German, or Luxembourgish is beneficial.

Nice to have

  • Experience in Luxembourg banking or CSSF-supervised environments.
  • Exposure to cloud security, SaaS risk, identity and access management, vulnerability management, SIEM/SOC operations, incident response, and resilience testing.
  • Certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Implementer/Lead Auditor.

Culture & Benefits

  • Work in an independent oversight, governance, and assurance capacity rather than as a hands-on SOC analyst or security engineer.
  • Collaborate with Regional and Group CISOs, Technology, Risk, Compliance, Legal, DPO, Outsourcing, Internal Audit, and business stakeholders.
  • Contribute to regulatory readiness for DORA, CSSF reviews, audits, client due diligence, and board-level scrutiny.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →