Information Security Manager

il y a 3 semaines


Luxembourg China Merchants Bank Temps plein

H- Posted by
- Hongyi Xu- Recruteur Company: China Merchants Bank Luxembourg China Merchants Bank Co., Ltd., founded in 1987, is China’s first joint-stock commercial bank which has been ranked among China’s top commercial banks for many consecutive years. CMB set up a branch that provides commercial banking services in Luxembourg in March 2015 and acts as the gateway and regional headquarter of CMB group in Continental Europe. In May 2021, China Merchants Bank Co., Ltd., has the subsidies-China Merchants Bank (Europe) S.A. in Luxembourg.

**Responsibilities**:

- Developing and implementing policies and frameworks for IT security and risk management.
- Monitoring and managing the IT systems to ensure that they are secure.
- Conducting ICT and Cybersecurity Risk-Self Assessment, in line with both EU regulation and HO policies.
- Ensuring that IT control framework is aligned to the CMB HO framework when relevant.
- Identifying potential regulatory and non-regulatory IT risks through thorough and ongoing risk assessments (such as the possibility of system failure or data loss).
- Assisting in finding practical and cost-effective solutions to identified or revealed security and risk issues.
- Building and maintaining strong and effective working relationships and effective means of communication with other relevant functions such as IT, RM, LC, OP departments.
- Working closely together with internal and external auditors on ICT Risk topics.
- Design an extensive training program and organize regular training targeted to different functions within the Bank.
- Implement a set of Key Risk Indicators (KRI) and defining metrics to regularly measure control effectiveness.
- Providing regular reporting on the ICT risk exposure, mitigating efforts, key milestones, KRIs, escalation of operational events and breaches.
- Actively engaging in end-to-end risk remediation planning, resolution, and monitoring activities.
- Serve as the point of contact for all ICT Risk Management matters.
- Monitoring key trends in the regulatory environment and best market practices (including implementation of DORA, review of real case studies, following the latest industry best practices)
- Raising awareness: influencing behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.

**Profile**:

- Master's degree (information technology, computer science, information security or a related field).
- At least 6 years of professional working experience in ICT Risk Management or in IT.
- Familiar with applicable banking regulations and how they impact the information technology (IT) department.
- Strong interpersonal skills and the ability to develop effective trustworthy relationships with the IT, RM, LC departments and business stakeholders.
- Staying aware of Information Security current affairs, business continuity, data management, security and encryption, and vulnerability analysis and audit.
- Fluent in English and Chinese. Excellent communication skills, both written and verbal to be able to articulate complex IT risks in simple business terms.
- Any relevant certifications is a plus (CISSP, CISA, CRISC).
- Audit or controls background, Big Four experience a plus.

**Disclaimer**:
The preceding description is not designed to be a complete list of all duties and responsibilities.


  • Information Security Officer

    il y a 4 semaines


    Luxembourg ING Temps plein

    Information Security OfficerIn order to strengthen the delivery organisation, ING Luxembourg is looking for an Information Security Officer.Job description :Your mission will be to reinforce a team of Security Officers in order to maintain the bank within its IT risk appetite and participate in the implementation of the DORA regulation. Taking part in...

  • Information Security Officer

    il y a 3 semaines


    Luxembourg, Luxembourg ING Temps plein

    Information Security OfficerIn order to strengthen the delivery organisation, ING Luxembourg is looking for an Information Security Officer.Job description :Your mission will be to reinforce a team of Security Officers in order to maintain the bank within its IT risk appetite and participate in the implementation of the DORA regulation. Taking part in...


  • Luxembourg Findel Airport ING Temps plein

    Information Security Officer In order to strengthen the delivery organisation, ING Luxembourg is looking for an Information Security Officer on a temporary contract bases. Job description: Your mission will be to reinforce a team of Security Officers in order to maintain the bank within its IT risk appetite and participate in the implementation of the DORA...


  • Luxembourg Tadaweb Temps plein

    **Tadaweb is a scale-up technology company founded and based in Luxembourg with offices in UK, France, Canada and USA. Founded 11 years ago, Tadaweb's mission is to make the world safer by empowering the human mind with the right information at the right time. Tadaweb offers a SaaS platform that makes OSINT investigations more effective and efficient and...


  • Luxembourg European Investment Bank Temps plein

    The **EIB**, the European Union's bank, is seeking to recruit for its **Group Risk & Compliance Directorate (GR&C) - Office of the Group Chief Compliance Officer (GR&C-OCCO) - Group Non-Financial Risk Department (GNFR), Project Management and Information Security Division (PMI), Information Security Risk Unit (InfoSec)** at its headquarters in Luxembourg, a...


  • Luxembourg Deutsche Börse Group Temps plein

    Tracing its origins to 1585, Deutsche Börse Group has become one of the world's leading exchange organisations and an innovative market infrastructure provider. In this role, we provide investors, financial institutions and companies access to global capital markets. By creating trust in the markets of today and tomorrow we foster growth and contribute to...


  • Luxembourg, Luxembourg Banque Internationale du Luxembourg Temps plein

    Job Description: Responsible for leading and coordinating actions related to developing and driving the implementation of the information security plan, engaging with stakeholders to achieve business objectives. Challenge systems and procedures to identify potential adverse events. Manage information classification, control, and protection. Handle security...


  • Luxembourg, Luxembourg Banque Internationale à Luxembourg (BIL) Temps plein

    Founded in 1856, Banque Internationale à Luxembourg is the oldest multi-business bank in the Grand Duchy. From its foundation, the BIL has always played an active role in the development of the Luxembourg economy. It currently operates in retail, private and corporate banking, as well as on major capital markets. Employing more than 2 000 people, BIL is...


  • Luxembourg Banque Internationale du Luxembourg Temps plein

    Banque Internationale à Luxembourg (BIL) is one of the biggest banks in the Grand Duchy, offering retail, private, corporate and institutional banking, as well as treasury and financial market services. The majority of BIL’s 2,000 employees work at the headquarters in Luxembourg City – this centralized setup promotes swift, agile decision-making and...

  • Isrm Specialist

    il y a 7 jours


    Luxembourg GovJobs Temps plein

    **Statut** : Employé de l'État **Qui recrute ?**: Banque centrale du Luxembourg **Missions**: - Vous réalisez des analyses de risques spécifiques afin de mettre en évidence les faiblesses des systèmes d’information en collaboration avec les propriétaires fonctionnels et d’informations; - Vous réalisez des revues de sécurité sur les systèmes...


  • Luxembourg, Luxembourg (Canton) Banque Internationale à Luxembourg (BIL) Temps plein

    Founded in 1856, Banque Internationale à Luxembourg is the oldest multi-business bank in the Grand Duchy. From its foundation, the BIL has always played an active role in the development of the Luxembourg economy. It currently operates in retail, private and corporate banking, as well as on major capital markets. Employing more than 2 000 people, BIL is...


  • Luxembourg Schroders Temps plein

    **Information Security Governance Risk & Compliance,** ***Analyst (EMEA)** **Who we’re looking for** **About Schroders** We’re a global investment manager. We help institutions, intermediaries and individuals around the world invest money to meet their goals, fulfil their ambitions, and prepare for the future. We have around 6,000 people on six...


  • Luxembourg AXA Temps plein

    **Notre environnement de travail** Fière d'appartenir au Groupe AXA, une marque d'assurance internationale et un leader mondial des services financiers, la société AXA Assurances Luxembourg est un acteur majeur du secteur des assurances au Grand-Duché. Nous aidons nos clients à traverser les petites et grandes difficultés de la vie. Chaque jour, nous...


  • Luxembourg AXA Assurances Luxembourg Temps plein

    Join us ! Devenez Senior Information Security Officer chez AXA Luxembourg, pour un contrat à durée indéterminée Notre environnement de travail Fière d'appartenir au Groupe AXA, une marque d'assurance internationale et un leader mondial des services financiers, la société AXA Assurances Luxembourg est un acteur majeur du secteur des assurances au...


  • Luxembourg Hays Temps plein

    We are looking for our client located to Luxembourg an IT Information security specialist - specialised in industrial sector.Your Responsibilities as IT Information Security Specialist - Specialised in Industrial Sector : You lead general initiatives related to IT certification and compliance. You support all internal and external audit teams as the...

  • RCDevs Security

    il y a 2 semaines


    Luxembourg RCDevs Security Temps plein

    The team We are a team of tech guys, working with a bunch of hi-tech technologies every day. We don't expect you to know all of them but you must be curious and passionate to learn new things quickly (just as we do). Our R&D team has many heterogeneous knowledge and very strong skills. Our philosophy is to share and work together in the best conditions, in...

  • Cyber Security Project Manager

    il y a 4 semaines


    Luxembourg Uni Systems Temps plein

    At Uni Systems, we are working towards turning digital visions into reality. We are continuously growing and we are looking for a professional to join our UniQue Luxembourg team. In this role, you will have the opportunity to work closely with our customers in the public sector and you will be responsible for developing new business by identifying...

  • Security Project Manager

    il y a 4 semaines


    Luxembourg Sogeti, part of Capgemini Temps plein

    Map out your next move by joining our team as a Security Project Manager! If you have in-depth knowledge in Project or Program management, security and communication then do not hesitate to read the job description below and apply! You will have the unique opportunity to gain experience with the shared technical knowledge of your futures colleagues, for...

  • Security Project Manager

    il y a 2 semaines


    Luxembourg, Luxembourg Sogeti, part of Capgemini Temps plein

    Map out your next move by joining our team as a Security Project Manager If you have in-depth knowledge in Project or Program management, security and communication then do not hesitate to read the job description below and apply You will have the unique opportunity to gain experience with the shared technical knowledge of your futures colleagues, for...

  • Head IT Security

    il y a 3 semaines


    Luxembourg, Luxembourg Luxair Temps plein

    For our department Information Security within LuxairGroup, we are looking for a (an): Head IT Security (m/f) Main duties: Work with the company executives to prioritize company security initiatives and spending based on appropriate risk management and/or financial methodology.Endorse all company information security related issues including the planning...