7 дней назад
IT Security Officer (DORA/Cyber Risk)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
IT Security Officer (DORA/Cyber Risk): Providing independent second-line oversight and assurance for information security, ICT risk, cyber resilience, and technology controls across Luxembourg-regulated financial services with an accent on DORA, CSSF expectations, and third-party ICT risk. Focus on challenging control design and effectiveness, performing risk assessments, overseeing incidents and remediation, and preparing risk reporting for management, committees, and boards.
Location: Munsbach, Luxembourg
Company
is a global fund administration and middle office solutions provider established in Bermuda, with approximately 13,000 employees across 112 offices.
What you will do
- Provide independent second-line oversight and challenge across information security, ICT risk, cyber resilience, and technology controls for Luxembourg entities.
- Review control design, testing results, remediation plans, policy exceptions, and risk acceptances.
- Perform information security and ICT risk assessments, control assurance reviews, thematic reviews, and independent risk opinions.
- Support DORA oversight, including ICT risk management, incident management, resilience testing, and ICT third-party risk.
- Oversee risks related to outsourcing, cloud, SaaS, and critical ICT service providers, including due diligence, contractual controls, exit arrangements, and ongoing monitoring.
- Report material risks, incidents, vulnerabilities, audit findings, and remediation status to management, risk committees, boards, regulators, and other stakeholders.
Requirements
- 7+ years of experience in information security, ICT risk, technology risk, cyber risk, internal control, audit, or technology assurance in financial services or another regulated environment.
- Strong understanding of second-line oversight, independent challenge, risk governance, and control assurance models.
- Good knowledge of DORA, CSSF ICT and cyber risk expectations, outsourcing requirements, operational resilience, and technology risk management in EU or Luxembourg-regulated financial services.
- Practical knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, CIS Controls, or equivalent frameworks.
- Experience with risk assessments, control reviews, gap assessments, remediation tracking, management reporting, and regulatory or audit engagements.
- Fluent business English required. French, German, or Luxembourgish is beneficial.
Nice to have
- Experience in Luxembourg banking or CSSF-supervised environments.
- Exposure to cloud security, SaaS risk, identity and access management, vulnerability management, SIEM/SOC operations, incident response, and resilience testing.
- Certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Implementer/Lead Auditor.
Culture & Benefits
- Work in an independent oversight, governance, and assurance capacity rather than as a hands-on SOC analyst or security engineer.
- Collaborate with Regional and Group CISOs, Technology, Risk, Compliance, Legal, DPO, Outsourcing, Internal Audit, and business stakeholders.
- Contribute to regulatory readiness for DORA, CSSF reviews, audits, client due diligence, and board-level scrutiny.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →