ICT Risk Officer

Il y a 3 jours

Kirchberg, LU Michael Page Temps plein

- Shape ICT risk oversight within Luxembourg's financial services sector.
- Build expertise in digital resilience through cross-functional exposure. About Our Client
- Our client is a financial services organisation based in Luxembourg.
- Its activities require effective technology risk management, reliable information systems and robust oversight of external service providers.
- The position involves close collaboration with Risk, IT, Information Security, Compliance and business stakeholders.

Job Description

- Maintain and enhance the ICT risk management framework, policies and procedures.
- Conduct independent ICT risk assessments covering systems, processes, projects and third-party arrangements.
- Review and challenge the design and effectiveness of IT and information security controls.
- Support alignment with DORA and applicable CSSF requirements.
- Monitor technology risks, control deficiencies and remediation plans, escalating material issues.
- Develop key risk indicators and prepare clear reporting for management and governance committees.
- Assess ICT third-party risks and challenge outsourcing assessments and ongoing monitoring.
- Review significant ICT incidents, root-cause analyses and corrective actions.
- Provide independent oversight of business continuity, disaster recovery and resilience testing.
- Contribute to regulatory enquiries and audit responses within the scope of the ICT risk function. The Successful Applicant
- Degree in information technology, cybersecurity, risk management or a related discipline.
- Relevant experience in ICT risk, IT audit, information security governance or technology risk consulting.
- Understanding of the three lines model and the responsibilities of an independent risk function.
- Familiarity with DORA, relevant CSSF expectations and recognised frameworks such as ISO 27001, COBIT or NIST.
- Ability to assess technology controls and translate technical findings into clear business risks.
- Strong analytical judgement, structured documentation skills and attention to detail.
- Confidence to challenge stakeholders constructively and follow remediation through to completion.
- Fluent English; French or another European language would be an advantage.
- CISA, CISM, CRISC or comparable certifications would be an asset. What's On Offer
- A role with direct exposure to technology risk and operational resilience.
- Collaboration with specialists across risk, technology, security and compliance.
- Opportunities to influence control improvements and management decisions.
- Scope to deepen expertise in financial services ICT risk management.
- Remuneration and benefits to be specified according to the employer and position level.