Ict Risk Manager

il y a 1 semaine


Luxembourg ByteDance Temps plein

**ICT Risk Manager - Global Payment - Luxembourg**
- Luxembourg

Regular
- R&D - Security

Job ID: A58984

**Responsibilities**

Team Intro PIPO Luxembourg is a dynamic, forward-thinking organisation at the forefront of the payments industry. As part of a fast-growing, ambitious company, you will have the unique opportunity to shape and refine our ICT Framework while playing a pivotal role in our mission to innovate and deliver exceptional payment solutions. About the role As part of the second line of defence, we are seeking an accomplished and proactive ICT Risk Manager who thrives in a fast-paced, challenging environment. This is a career-defining opportunity to take ownership of our ICT Risk function, build robust frameworks, and make a lasting impact. Reporting to the Chief Information Officer but with independent autonomy, you will play a critical role in strengthening our digital resilience, protecting against ICT risks, and ensuring compliance with Luxembourg’s regulatory framework and internal governance standards. Responsibilities: - Implementing and managing the ICT Risk Management framework aligned with regulatory requirements such as the EU Digital Operational Resilience Act (DORA) and CSSF circulars, ensuring that ICT risks are identified, assessed, mitigated, monitored, and reported within the institution's risk appetite. - Supporting and coordinating first line of defence functions in defining, drafting, implementing, and maintaining policies and procedures to ensure compliance with applicable regulatory requirements and internal governance standards; continuous compliance monitoring. - Conducting regular ICT risk assessments focused on payment services, maintaining an ICT risk register, and updating policies and controls in response to evolving threats and incidents. - Coordinating ICT incident response and remediation efforts across multiple stakeholders to minimize operational impact and ensure timely resolution. - Overseeing security testing activities such as penetration testing and vulnerability assessments specifically related to payment functions and processes. - Managing ICT business continuity plans and conducting resilience testing to ensure operational stability under adverse conditions. - Monitoring third-party service providers through due diligence, risk assessments, and service level agreement (SLA) performance reviews to manage supply chain risks. - Serving as the primary contact for ICT-related regulatory communications, audit responses, and reporting to both management and regulators, ensuring compliance with CSSF and other supervisory expectations. - Integrating ICT risk management into the institution’s overall risk management framework, maintaining independence from ICT operations to provide objective control and oversight. - Staying ahead of regulatory developments, sharing insights and recommendations with the leadership team to adapt policies and practices as needed. - Driving a strong ICT risk awareness and culture across the organization by delivering engaging, business-focused training and fostering an open, solutions-driven approach. - Actively contributing to the development of new products and services, ensuring ICT compliance is seamlessly integrated into innovation.

**Qualifications**

Minimum Qualifications - Relevant professional experience of typically 2-5 years in information security, ICT risk management, IT governance, or cybersecurity, preferably within the payment and financial services industry. - Good knowledge of regulatory requirements applicable to payment institutions in Europe, including the Digital Operational Resilience Act (DORA), PSD2, and related EU regulatory technical standards and guidelines. - Understanding of ICT risk management frameworks and security standards such as ISO 27001, ISO 27005, the NIST Cybersecurity Framework, industry standards such as PCI DSS, and familiarity with risk management methodologies. - Self-starter mentality, with a high level of initiative and discipline to independently lead projects and drive impactful outcomes. - Strong analytical, communication, relationship-building, and organizational skills to effectively report and collaborate across business units, ICT teams, and external stakeholders. - Basic understanding of micro-service architecture, cloud technologies and general ICT terms and processes. - Fluency in English. Preferred Qualifications - Advanced certifications such as CRISC (Certified in Risk and Information Systems Control), CompTIA Security+, ISO 27001 Lead Implementer/Auditor, or equivalent recognized ICT security and risk certifications. - Experience with ICT risk management in payment or electronic money institutions, including practical knowledge of incident response, penetration testing, business continuity, and third-party risk management. - Familiarity with Luxembourg-specific regulatory circulars such as CSSF Circular 25/880 and other supervisory expectations. - Participation in spe


  • Senior Ict Risk Manager

    il y a 1 semaine


    Luxembourg Austin Bright Temps plein

    **Introduction**: You shall become a part of one of the biggest financial systems in the world. The holding is one of the biggest banking organizations in the world when measured by total assets. They provide a secure atmosphere and are reliable. They are looking for a Senior ICT risk Manager with extensive banking knowledge to help strengthen their risk...

  • Senior Ict Risk Manager

    il y a 1 semaine


    Luxembourg Austin Bright Temps plein

    You shall become a part of one of the biggest financial systems in the world. The holding is one of the biggest banking organizations in the world when measured by total assets. They provide a secure atmosphere and are reliable. They are looking for a Senior ICT risk Manager with extensive banking knowledge to help strengthen their risk management...

  • Risk and ICT Manager

    il y a 4 jours


    Luxembourg Findel Airport Standard Chartered Bank Temps plein 70.000 € - 120.000 € par an

    Requisition Number: 43528Job Location: Luxembourg, LUXWork Type: Office WorkingEmployment Type: PermanentPosting Start Date: 05/12/2025Posting End Date::We seek an experienced Risk & ICT Manager to strengthen technology, cyber, and operational risk in Luxembourg. You'll oversee ICT risk governance, ensure compliance, lead assessments, and promote a strong...


  • Luxembourg Banque Raiffeisen Temps plein

    Première banque coopérative luxembourgeoise, Banque Raiffeisen est une banque indépendante qui concentre son action commerciale sur le Luxembourg. Elle développe, pour chacun de ses 37 points de vente, trois métiers stratégiques que sont la banque de détail, la banque des entreprises et la gestion patrimoniale. Grâce à sa stratégie commerciale...

  • Senior Ict Third-party

    il y a 1 semaine


    Luxembourg Satispay Temps plein

    **About Satispay** At Satispay, we're not just reimagining payments; we're pioneering a movement toward simplicity and accessibility. Picture yourself at the forefront of innovation, leading the way in revolutionizing payments - and beyond! - across Europe, alongside a vibrant community of like-minded individuals driven by a shared vision: simplifying...


  • Luxembourg POST Group Temps plein

    **DEEP - ICT Project Manager**: **Date**:11 déc. 2024 **Lieu**: Luxembourg, Luxembourg **Entreprise**:POST Luxembourg In order to strengthen our team, we are currently looking for an experienced **ICT Project Manager (M/F/n).** **Vos missions**: - Manage the implementation of our ICT solutions (cloud, unified communication, managed services,...

  • Ict Governance Specialist

    il y a 1 semaine


    Luxembourg BTO spa Temps plein

    Who is BTO Research? BTO Research is a consulting firm, part of the Relatech Group, that has been supporting its clients in innovative projects for over 15 years, ensuring a customized approach to meet market challenges. Founded in 2008, we have gathered and enhanced the historical experience of consulting to which we have added two key elements: research...

  • Risk Analyst

    il y a 1 semaine


    Luxembourg Uni Systems Temps plein

    At Uni Systems, we are working towards turning digital visions into reality. We are continuously growing and we are looking for a Risk Analyst to join our UniQue Luxembourg team! **What will you be bringing to the team?** - Execution of risk assessment for new systems and new projects; - Managing and analyzing incoming cybersecurity threats and...


  • Luxembourg, Luxembourg Avantage Reply Temps plein 60.000 € - 120.000 € par an

    Senior Data and ICT ConsultantTasks: As part of the Data practice, assist our clients in defining, developing and integrating technical (incl. AI-based) solutions to effectively manage risks and respond to operational and regulatory challenges.Automate data anonymization and pseudonymization and optimize onboarding and communication channels Contribute to...


  • Luxembourg EBRC Temps plein

    In order to strengthen our team, we are currently looking for an experienced **ICT Project Manager (M/F/n).** **Vos missions**: - Manage the implementation of our ICT solutions (cloud, unified communication, managed services, connectivity services, etc.) for our corporate clients - Manage budgets, projects schedules as well as resource allocation - Set-up...