4 месяца назад
Senior GRC Program Manager (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior GRC Program Manager (Fintech): Strengthening local governance and operational execution for Ripple's Luxembourg entity with an accent on DORA compliance, ICT security frameworks, and regulatory alignment. Focus on bridging global engineering teams with regional requirements, managing outsourced security services, and ensuring operational resilience in the digital asset space.
Location: Luxembourg, Luxembourg; in-office collaboration is expected for 10+ days per month.
Company
builds crypto solutions for financial institutions, businesses, governments, and developers to improve global financial infrastructure.
What you will do
- Lead ICT operations initiatives and operational oversight of outsourced ICT and security services for the Luxembourg entity.
- Implement and maintain EU and Luxembourg security frameworks, including DORA and supporting technical standards.
- Coordinate technical security controls across infrastructure and application environments in alignment with internal controls and EBA, ESMA, and CSSF guidance.
- Work with global Engineering and IT teams to assess infrastructure, application, and architecture changes for operational resilience and regional compliance.
- Gather and analyze technical evidence such as logs, system settings, access reports, and database queries to support monitoring, incident response, audits, and regulatory examinations.
- Provide operational security guidance to Engineering, Compliance, Finance, Product, Legal, and Sales teams, including customer security questionnaires and technical contract reviews.
Requirements
- 5+ years of experience in information security infrastructure, preferably in a highly regulated industry.
- Bachelor’s degree in a relevant discipline or equivalent professional experience.
- Experience in the Luxembourg financial or technology sector and strong knowledge of the local regulatory landscape.
- Working knowledge of DORA requirements, including resilience testing, ICT third-party management, and incident response.
- Knowledge of EU regulatory frameworks such as MiCA, EBA, and ESMA standards, as well as ISO 27001, SOC 2, and NIST.
- Professional English proficiency is required. French proficiency is desirable.
Nice to have
- Experience with Jira, Confluence, JupiterOne, Okta, AWS, Tines, and integrated GRC platforms.
- Certifications such as CISSP, CISA, AWS Certified Security, or PMP.
Culture & Benefits
- Fast-paced startup environment with experienced industry leaders and opportunities for professional development.
- Flexible in-office collaboration, with managers and teams deciding which 10+ days per month to attend.
- Competitive salary, bonuses, equity, healthcare, retirement, family support, and a mobile phone stipend.
- Vacation, R&R days, wellness reimbursement, parental leave, and family planning benefits.
- Catered lunches, stocked kitchens, team offsites, bonding activities, and regular company meetings.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →