Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
ICT Risk Oversight Lead (Cybersecurity): Strengthening ICT risk management and second-line oversight for regulated cryptocurrency exchange and brokerage operations with an accent on technology controls, regulatory alignment, and digital asset resilience. Focus on assessing complex cyber risks, challenging first-line teams, monitoring risk appetite and KRIs, and overseeing outsourced technology and information security activities.
Location: Luxembourg, Luxembourg; based in the Luxembourg office with in-person attendance expected at least 3 days per week
Company
Robinhood is a financial technology company operating brokerage and digital asset services; Bitstamp, the regulated crypto exchange, is part of the Robinhood family.
What you will do
- Implement and enhance the ICT Risk Management framework, policies, and procedures in line with group standards and Luxembourg regulatory requirements.
- Provide second-line oversight across technology and security initiatives, business-as-usual operations, risk metrics, and key risk indicators.
- Conduct risk assessments for new products, existing systems, processes, and technology arrangements.
- Review technology controls, provide independent challenge to first-line teams, and collaborate with IT, Security, the CISO, and other stakeholders.
- Report findings and risk themes through governance forums and strengthen ICT risk awareness and risk culture.
- Promote the secure and effective use of AI for automation, efficiency, and scalable risk management.
Requirements
- 8+ years of experience in cyber, technology, or ICT risk, including second-line oversight, control effectiveness, and independent challenge.
- Experience in highly regulated environments, preferably financial services, with regulatory and governance processes.
- Knowledge of technology, cyber, and operational risks in cryptocurrency and digital asset businesses, including exchange, custody, third-party, and resilience risks.
- Strong knowledge of DORA, MiCA, the EU AI Act, CSSF expectations, and related European regulatory frameworks.
- Experience with technology risk, control assurance, incident response, internal controls, business continuity, identity and access management, and secure software development.
- Strong written and verbal English communication skills required. CISSP, CISA, CISM, or CRISC certifications are strongly preferred.
Nice to have
- Technology audit experience.
- ISO 27001, ISO 22301, or similar certifications.
Culture & Benefits
- High-impact work in a fast-moving environment focused on ethics, rigorous analysis, and proactive risk management.
- Performance-driven compensation with bonus programs.
- Supplemental health and ancillary insurance, mental health support, and a flexible lifestyle wallet.
- Paid time off, sick time, volunteer time off, parental leave, and company holidays.
- In-person office experience with catered meals, events, comfortable workspaces, and a monthly commuter stipend.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →