Vp Information Security Manager

Il y a 7 mois


Luxembourg JPMorgan Chase & Co Temps plein

**JOB DESCRIPTION**
Our Information Security professionals are passionate about information security and control solutions for computing environments. While collaborating with a world-class team of technology experts, you'll partner with one or more disciplines, lines of business, regions or locations to respond to evolving business requirements and emerging threats. You'll also leverage your expert knowledge of today's ever-changing cybersecurity and risk landscape to influence IT operations across the firm. Responsibilities include offering guidance, providing technology risk oversight in compliance with regulatory obligations, best practices, and support across businesses, leading risk reviews and vulnerability assessments, identifying threats, communicating with senior leaders and other stakeholders, and managing budgets

This role requires a wide variety of strengths and capabilities, including:
**Main Responsibilities Include**
- Provide technology risk oversight over how J.P. Morgan Asset Management Europe (JPMAME) adopts technology to support, enable and enhance its Business Objectives while complying with the Firm’s global policies and it’s regulatory compliance requirements.
- Through strong risk leadership and collaboration with partners, ensure the security of the Firm's computing environment, protect customer and employee confidential information, and comply with regulatory requirements as e.g., mandated by the Commission de Surveillance du Secteur Financier (CSSF) as the National Competent Authority (NCA).
- Provide risk oversight over the Information and Communication Technology (ICT) Outsourcing governance framework which is driven by local regulatory obligations. Such as, CSSF circlular 22/806 on ICT Outsourcing which requires all outsourced ICT activities and/or provisions of service provided by either J.P. Morgan affiliate or an external third party to be identified, measured, monitored and controlled in compliance with stated regulatory obligations.
- Provide independent oversight over technology and cybersecurity risks associated with the overall JPMAME governance framework. Execute on ICT governance tasks that contribute to ensuring effective ICT Performance Management and that service levels, vendors, risks, cyber threats, and budgets are carefully managed and meet overall business expectation.
- Ensure technology risk impacting the business is effectively identified, quantified, communicated, and managed, including recommendations for resolution and identifying the root cause/key themes.
- Evaluate regulatory changes relating to cybersecurity and technology impacting the legal entity
- Create and present management packs in steering committees and governance forums

This role requires a wide variety of strengths and capabilities, including:

- At least 5+ years of experience in Information Security
- Advanced knowledge of multiple IT control and project management practices, plus experience working across large environments
- Great communication skills and ability to collaborate with high-performing teams and individuals throughout the firm to accomplish common goals
- Ability to explain complex technology and security risks to non-technical audiences
- Strong proficiency in MS Office tools and proven track record of creating high quality deliverables for both internal and external stakeholders
- Expertise in information security domains, including policies and standards, risk and control assessments, access controls, regulatory compliance, technology resiliency, risk and control governance and metrics, incident management, secure systems development lifecycle, vulnerability management, third party risk management and data protection
- Analytical skills including solving and communicating complex problems, data analytics, measurement and reporting needed to drive continuous improvement

**Preferred Qualifications**
- Certified in CISA, CISM, CRISC, CISSP, CCSP or similar
- Expertise in relevant regulations, like the EBA Guidelines on ICT and Security Risk Management or the EBA Guidelines on Outsourcing Arrangements, CSSF Circulars, and/or ISO27001, GDPR and NIST frameworks
- Experience in creating and monitoring security KPIs and KRIs
- Ability to create dashboards via data visualization tools such as Power BI or Tableau
- Experience across architecture security and cloud security

**ABOUT US**

J.P. Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place



  • Luxembourg Deutsche Börse Group Temps plein

    Tracing its origins to 1585, Deutsche Börse Group has become one of the world’s leading exchange organisations and an innovative market infrastructure provider. In this role, we provide investors, financial institutions and companies access to global capital markets. By creating trust in the markets of today and tomorrow we foster growth and contribute to...


  • Luxembourg Deutsche Börse Temps plein

    **Learn. Develop. Grow. But always: Share value**: Join our international team that drives positive change, united by a spirit of openness and curiosity. We empower you to have an impact and to grow - personally and professionally. With us, you work at the heart of financial systems and evolve the way markets operate. We’re excited about the future because...


  • Luxembourg Next Gate Tech Temps plein

    **What You Will Do**: In this role, you will be responsible for developing and implementing our organization's information security strategy, as well as ensuring compliance with relevant laws, regulations, and industry standards. You will work closely with stakeholders across the organization to identify and mitigate security risks, and be responsible for...


  • Luxembourg China Merchants Bank Temps plein

    H- Posted by - Hongyi Xu- Recruteur Company: China Merchants Bank Luxembourg China Merchants Bank Co., Ltd., founded in 1987, is China’s first joint-stock commercial bank which has been ranked among China’s top commercial banks for many consecutive years. CMB set up a branch that provides commercial banking services in Luxembourg in March 2015 and acts...


  • Luxembourg PayPal Temps plein

    At PayPal (NASDAQ: PYPL), we believe that every person has the right to participate fully in the global economy. Our mission is to democratize financial services to ensure that everyone, regardless of background or economic standing, has access to affordable, convenient, and secure products and services to take control of their financial lives. Job...


  • Luxembourg PayPal Temps plein

    At PayPal (NASDAQ: PYPL), we believe that every person has the right to participate fully in the global economy. Our mission is to democratize financial services to ensure that everyone, regardless of background or economic standing, has access to affordable, convenient, and secure products and services to take control of their financial lives. Job...


  • Luxembourg Base Cyber Security Temps plein

    Are you an experienced incident response / incident handling professional? Ready for taking on a leading role, setting up and running a new layer of incident response capability to the security maturity of a Security Operations Center (SOC) servicing a global business via managed security services? Get the chance to contribute at high level by taking on a...


  • Luxembourg JAO Temps plein

    jao.eu Description In the context of reinforcing its operations and the implementation of ISO27001, JAO is in search for an Information Security Officer able to on-board and to develop quickly in a diverse IT eco-system. The person is foreseen to take over a series of duties associated with the ISMS management and to deliver support in the projects design...


  • Luxembourg Cargolux Temps plein

    TASK RESPONSIBILITIES: 1. Policy Development and Management: - Develop, review, and update information security policies and procedures to align with industry standards and regulatory requirements. - Assist in the development of incident response plan and playbooks 2. Risk Assessment and Management: - Support the risk assessment activity by identifying...


  • Luxembourg FAST Recruitment Temps plein

    votre profil - Master degree in Information Security or Information Technology - 5 years’ security related work experience, preferably within an insurance institution - Professional security management certification, such as a Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) is a preferred asset -...

  • Information Security Analyst

    il y a 4 semaines


    Luxembourg Next Gate Tech Temps plein

    **About Next Gate Tech**: At Next Gate Tech, we create technologies that reshape the landscape of the fund industry operations. We empower our clients by capturing the full potential of harmonized data to drive intelligent and fully automated operations. Our transformative solutions optimize processes, enhance efficiency, reduce risks, and drive cost...


  • Luxembourg Next Gate Tech Temps plein

    **About Next Gate Tech**: At Next Gate Tech, we create technologies that reshape the landscape of the fund industry operations. We empower our clients by capturing the full potential of harmonized data to drive intelligent and fully automated operations. Our transformative solutions optimize processes, enhance efficiency, reduce risks, and drive cost...

  • Information Security Officer

    il y a 2 semaines


    Luxembourg EFA Temps plein

    **Your responsibilities**: - Perform controls and reviews to ensure and validate conformity with defined security standards and framework NIST, ISO 27001 - Have a good knowledge of regulatory requirements (DORA, NIS ) - Manage or participate in technical projects to improve IT security - Perform IT security assessments and recommendations related to...


  • Luxembourg Findel Airport ING Temps plein

    Information Security Officer In order to strengthen the delivery organisation, ING Luxembourg is looking for an Information Security Officer on a temporary contract bases. Job description: Your mission will be to reinforce a team of Security Officers in order to maintain the bank within its IT risk appetite and participate in the implementation of the DORA...


  • Luxembourg NTT Temps plein

    NTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future. In today’s ‘iNTTerconnected’ world, connections matter more now than ever. By bringing together talented people, world-class technology partners and emerging innovators, we help our clients solve...


  • Luxembourg Business Training Luxembourg SA Temps plein

    30 years of experience in high-end training **Business Training’s experience is built on solid ground**: we have been providing cutting-edge ICT training sessions for about 20 years. Originally, Business Training specialized in IT technical and end-user trainings (Windows, MS Office, etc.). A few years ago, our company widened the range of its training...


  • Luxembourg Tadaweb Temps plein

    **Tadaweb is a scale-up technology company founded and based in Luxembourg with offices in UK, France, Canada and USA. Founded 11 years ago, Tadaweb's mission is to make the world safer by empowering the human mind with the right information at the right time. Tadaweb offers a SaaS platform that makes OSINT investigations more effective and efficient and...


  • Luxembourg Brixio Temps plein

    **About the Role**: Join a dynamic and passionate team where innovation and collaboration are at the heart of our mission. As an **Information Security Governance Consultant**, you will play a key role in supporting clients to establish and enhance their information security governance frameworks. You will work closely with experienced consultants and...


  • Luxembourg SIRCONSULTING RH Temps plein

    We are looking for our future Information Security Governance Consultant to complete our team. Your missions are defined as follows: - Assist our clients in the implementation of their strategy - Identify the security projects - Assess the maturity of controls - Manage Information Security and its risks Required profile: - Master's degree - SCADA...


  • Luxembourg City Forvis Mazars Temps plein

    Job SummaryWe are seeking a highly experienced Cyber Security Senior Consultant to join our team at Forvis Mazars.About the RoleThis is an exceptional opportunity for a seasoned professional to lead and support our clients in managing current and evolving cyber threats. As a key member of our team, you will define and implement security measures to protect...