Information Security Manager

Il y a 5 mois


Luxembourg China Merchants Bank Temps plein

H- Posted by
- Hongyi Xu- Recruteur Company: China Merchants Bank Luxembourg China Merchants Bank Co., Ltd., founded in 1987, is China’s first joint-stock commercial bank which has been ranked among China’s top commercial banks for many consecutive years. CMB set up a branch that provides commercial banking services in Luxembourg in March 2015 and acts as the gateway and regional headquarter of CMB group in Continental Europe. In May 2021, China Merchants Bank Co., Ltd., has the subsidies-China Merchants Bank (Europe) S.A. in Luxembourg.

**Responsibilities**:

- Developing and implementing policies and frameworks for IT security and risk management.
- Monitoring and managing the IT systems to ensure that they are secure.
- Conducting ICT and Cybersecurity Risk-Self Assessment, in line with both EU regulation and HO policies.
- Ensuring that IT control framework is aligned to the CMB HO framework when relevant.
- Identifying potential regulatory and non-regulatory IT risks through thorough and ongoing risk assessments (such as the possibility of system failure or data loss).
- Assisting in finding practical and cost-effective solutions to identified or revealed security and risk issues.
- Building and maintaining strong and effective working relationships and effective means of communication with other relevant functions such as IT, RM, LC, OP departments.
- Working closely together with internal and external auditors on ICT Risk topics.
- Design an extensive training program and organize regular training targeted to different functions within the Bank.
- Implement a set of Key Risk Indicators (KRI) and defining metrics to regularly measure control effectiveness.
- Providing regular reporting on the ICT risk exposure, mitigating efforts, key milestones, KRIs, escalation of operational events and breaches.
- Actively engaging in end-to-end risk remediation planning, resolution, and monitoring activities.
- Serve as the point of contact for all ICT Risk Management matters.
- Monitoring key trends in the regulatory environment and best market practices (including implementation of DORA, review of real case studies, following the latest industry best practices)
- Raising awareness: influencing behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.

**Profile**:

- Master's degree (information technology, computer science, information security or a related field).
- At least 6 years of professional working experience in ICT Risk Management or in IT.
- Familiar with applicable banking regulations and how they impact the information technology (IT) department.
- Strong interpersonal skills and the ability to develop effective trustworthy relationships with the IT, RM, LC departments and business stakeholders.
- Staying aware of Information Security current affairs, business continuity, data management, security and encryption, and vulnerability analysis and audit.
- Fluent in English and Chinese. Excellent communication skills, both written and verbal to be able to articulate complex IT risks in simple business terms.
- Any relevant certifications is a plus (CISSP, CISA, CRISC).
- Audit or controls background, Big Four experience a plus.

**Disclaimer**:
The preceding description is not designed to be a complete list of all duties and responsibilities.



  • Luxembourg Cargolux Temps plein

    TASK RESPONSIBILITIES: 1. Policy Development and Management: - Develop, review, and update information security policies and procedures to align with industry standards and regulatory requirements. - Assist in the development of incident response plan and playbooks 2. Risk Assessment and Management: - Support the risk assessment activity by identifying...


  • Luxembourg Next Gate Tech Temps plein

    **About Next Gate Tech**: At Next Gate Tech, we create technologies that reshape the landscape of the fund industry operations. We empower our clients by capturing the full potential of harmonized data to drive intelligent and fully automated operations. Our transformative solutions optimize processes, enhance efficiency, reduce risks, and drive cost...


  • Luxembourg Findel Airport ING Temps plein

    Information Security Officer In order to strengthen the delivery organisation, ING Luxembourg is looking for an Information Security Officer on a temporary contract bases. Job description: Your mission will be to reinforce a team of Security Officers in order to maintain the bank within its IT risk appetite and participate in the implementation of the DORA...


  • Luxembourg NTT Temps plein

    NTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future. In today’s ‘iNTTerconnected’ world, connections matter more now than ever. By bringing together talented people, world-class technology partners and emerging innovators, we help our clients solve...


  • Luxembourg Business Training Luxembourg SA Temps plein

    30 years of experience in high-end training **Business Training’s experience is built on solid ground**: we have been providing cutting-edge ICT training sessions for about 20 years. Originally, Business Training specialized in IT technical and end-user trainings (Windows, MS Office, etc.). A few years ago, our company widened the range of its training...


  • Luxembourg Tadaweb Temps plein

    **Tadaweb is a scale-up technology company founded and based in Luxembourg with offices in UK, France, Canada and USA. Founded 11 years ago, Tadaweb's mission is to make the world safer by empowering the human mind with the right information at the right time. Tadaweb offers a SaaS platform that makes OSINT investigations more effective and efficient and...


  • Luxembourg JPMorgan Chase & Co Temps plein

    **JOB DESCRIPTION** Our Information Security professionals are passionate about information security and control solutions for computing environments. While collaborating with a world-class team of technology experts, you'll partner with one or more disciplines, lines of business, regions or locations to respond to evolving business requirements and emerging...


  • Luxembourg GovJobs Temps plein

    **Statut** : Employé de l'État **Qui recrute ?**: Au sein de l'ADEM, vous incarnerez le rôle d'expert-conseil, collaborant étroitement avec la Direction et les divers services. Votre mission essentielle consistera à établir des mesures de sécurité pour préserver la confidentialité, l'intégrité et la disponibilité des systèmes d'information et...


  • Luxembourg GovJobs Temps plein

    **Statut** : Fonctionnaire **Qui recrute ?**: Au sein de l'ADEM, vous incarnerez le rôle d'expert-conseil, collaborant étroitement avec la Direction et les divers services. Votre mission essentielle consistera à établir des mesures de sécurité pour préserver la confidentialité, l'intégrité et la disponibilité des systèmes d'information et des...


  • Luxembourg Grant Thornton Luxembourg Temps plein

    Description **Working place**: Company’s office, client’s office, homeworking, satellite offices **Contract type**: Permanent contract **Location**: Luxembourg Hamm / Client offices **Ready to start your next challenge?**: Grant Thornton Luxembourg is currently seeking an **_Experienced Information Security Consultant (M/F) _**to start...


  • Luxembourg ARHS Cube Temps plein

    You want to combine **passion **an **IT expertise**? You are **talented**, **motivated,** and **ambitious**? Then, we will be more than happy to **meet you**! **Ar**η**s Group - Part of Accenture**, is looking for a Senior Information Security Consultant - Strategic EU Projects (M/F) to join one of its teams located on the premises of a European...

  • Information Security Intern

    il y a 2 semaines


    Luxembourg City RTL Group Temps plein

    Job DescriptionAt RTL Group, we entertain, inform and inspire millions of people every day across multiple platforms with our strong media brands, content and products. We offer many possibilities: from TV and streaming to print, digital, radio and podcasts. More than 16,000 creatives, strategists, techies, numerical geniuses and organisational wizards work...


  • Luxembourg, Luxembourg Deutsche Börse Group Temps plein

    Job Title: Senior Information Security EngineerAbout the Role:As part of the IT Engineering Unit acting in the domains of architecture, infrastructure, and information security, you will report to the CFS IT Security Lead and take responsibilities in a broad range of application security engineering activities covering the entire CFS IT landscape. Your...

  • Isrm Specialist

    Il y a 6 mois


    Luxembourg GovJobs Temps plein

    **Statut** : Employé de l'État **Qui recrute ?**: Banque centrale du Luxembourg **Missions**: - Vous réalisez des analyses de risques spécifiques afin de mettre en évidence les faiblesses des systèmes d’information en collaboration avec les propriétaires fonctionnels et d’informations; - Vous réalisez des revues de sécurité sur les systèmes...


  • Luxembourg Schroders Temps plein

    **Information Security Governance Risk & Compliance,** ***Analyst (EMEA)** **Who we’re looking for** **About Schroders** We’re a global investment manager. We help institutions, intermediaries and individuals around the world invest money to meet their goals, fulfil their ambitions, and prepare for the future. We have around 6,000 people on six...


  • Luxembourg Luxembourg Institute of Health Temps plein

    Strategy and Management unit, integral part of Medical Informatics Department, has the objective to manage and deliver IT projects that connect healthcare and technology, while managing risks, meeting regulations and promoting continuous improvement. Dr. Lamine Traore, PhD, Head of the Strategy and Management unit, and Viktor Tynyanskyy, MSc, Information...


  • Luxembourg Luxembourg Institute of Health Temps plein

    Strategy and Management unit, integral part of Medical Informatics Department, has the objective to manage and deliver IT projects that connect healthcare and technology, while managing risks, meeting regulations and promoting continuous improvement. Dr. Lamine Traore, PhD, Head of the Strategy and Management unit, and Viktor Tynyanskyy, MSc, Information...


  • Luxembourg AXA Temps plein

    **Notre environnement de travail** Fière d'appartenir au Groupe AXA, une marque d'assurance internationale et un leader mondial des services financiers, la société AXA Assurances Luxembourg est un acteur majeur du secteur des assurances au Grand-Duché. Nous aidons nos clients à traverser les petites et grandes difficultés de la vie. Chaque jour, nous...


  • Luxembourg AXA Luxembourg Temps plein

    Devenez **Senior Information Security Officer** chez AXA Luxembourg, pour un contrat à durée indéterminée **Notre environnement de travail** Fière d'appartenir au Groupe AXA, une marque d'assurance internationale et un leader mondial des services financiers, la société AXA Assurances Luxembourg est un acteur majeur du secteur des assurances au...


  • Luxembourg POST Group Temps plein

    **DEEP - Information Security Officer**: **Date**:8 oct. 2024 **Lieu**: Luxembourg, Luxembourg **Entreprise**:POST Luxembourg Afin de renforcer les équipes de DEEP au sein de l'équipe Cybersecurity, nous recherchons actuellement un(e)** Information Security Officer **(M/F/n)** **Vos missions**: - Elaborer les politiques et la structure/cadre de...