IT Security Officer
Core
Independent Second Line of Defense oversight, challenge, and assurance over information security, ICT risk, cyber resilience, and technology control practices for European businesses within Luxembourg.
Role type
Second Line of Defense Information Security Officer
Builds
Independent reporting and escalation to local management, governance committees, Group CISO, Regional CISO, and Board-level forums
Domain
Financial services / Regulatory compliance (DORA, CSSF)
Deliverable
dashboards & analysis
Required skills
Second Line of Defense oversight, ICT risk governance, DORA compliance, ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, CIS Controls, enterprise security tooling, regulatory engagement, management reporting
Preferred skills
Luxembourg banking experience, cloud security, outsourcing oversight, SaaS risk, identity and access management, vulnerability management, SIEM/SOC operations, incident response, resilience testing, professional certifications (CISSP, CISM, CRISC, CISA)
Technologies
Firewalls, IDS/IPS, DLP, Tessian, Azure AD, Microsoft Security solutions, Cyber-arc, Patching solutions, SOC solutions
Responsibilities
Provide independent oversight and challenge of information security and ICT risk practices; Review and challenge first-line control design, implementation, and remediation plans; Perform ICT risk assessments and control assurance reviews; Oversee third-party, outsourcing, and cloud service provider risks; Support regulatory and supervisory engagements; Prepare and present security risk reporting to management and Board; Maintain local information security risk registers and control assurance records.
Seniority
Senior, hands-on IC