Luxembourg, Ville de Luxembourg
Stott and May
Temps plein
Job Description
Interim CISO / CISO as a Service (Freelance)
We are seeking a highly experienced, bilingual Interim CISO / Outsourced CISO to act as a strategic advisor to Management and drive the information security program for a prominent organization based in Luxembourg.
This is a long-term freelance engagement through 2027. The selected consultant will take operational ownership of cybersecurity governance, ensure regulatory compliance with a specific focus on NIS2, and systematically document security standards to prepare a seamless handover to a future permanent CISO.
Key Responsibilities & Deliverables
Non-Negotiable Requirements
Interim CISO / CISO as a Service (Freelance)
- Role: Interim Chief Information Security Officer (CISO)
- Format: Freelance / Contract (100% FTE)
- Location: Luxembourg (On-site / Hybrid)
- Remote Work: Hybrid
- Duration: long term
We are seeking a highly experienced, bilingual Interim CISO / Outsourced CISO to act as a strategic advisor to Management and drive the information security program for a prominent organization based in Luxembourg.
This is a long-term freelance engagement through 2027. The selected consultant will take operational ownership of cybersecurity governance, ensure regulatory compliance with a specific focus on NIS2, and systematically document security standards to prepare a seamless handover to a future permanent CISO.
Key Responsibilities & Deliverables
- Governance, Compliance & Risk Management
- NIS2 Compliance: Align the organization’s cybersecurity measures and incident reporting mechanisms with NIS2 directive requirements.
- Risk Registry: Maintain, mature, and evolve the corporate cybersecurity risk register.
- Policy Management: Draft, update, and implement priority security policies, procedures, and documented standards.
- Reporting: Produce clear security dashboards, Key Risk Indicators (KRIs), and Key Performance Indicators (KPIs) for C-level Management.
- Operational Security & Architecture Support
- Architecture Boards: Participate in architecture reviews, evaluate security impacts for new projects, and issue formal security validations.
- Vulnerability Management: Supervise the technical vulnerability management lifecycle and track engineering remediation plans.
- Incident & Crisis Response: Lead the preparation for security incidents and organize business continuity/crisis management tabletop exercises.
- Knowledge Transfer & Handover
- Perform a comprehensive Cybersecurity Maturity Assessment and define a 12-to-24-month security roadmap.
- Ensure continuous knowledge transfer to internal IT and infrastructure teams.
- Compile a comprehensive Transition Playbook to guarantee a smooth ramp-up for the incoming permanent CISO.
Non-Negotiable Requirements
- Experience: 10+ years of proven experience in Cybersecurity and IT Governance, with significant time spent as an active CISO, Interim CISO, or Senior GRC Consultant.
- Languages: Fluent in French and English (both written and spoken). The candidate must be comfortable presenting technical topics to French-speaking local teams and English-speaking board members.
- Regulatory & Frameworks: Deep knowledge of NIS2 requirements paired with a strong mastery of standard security frameworks (ISO 27001/2, NIST, CIS, or equivalent).
- Solid experience securing hybrid environments, specifically Microsoft 365 / Entra ID, active directory, on-premises systems, and cloud infrastructures.
- Proven ability to review complex network/system architectures and communicate security design requirements to engineering teams.
- Excellent communication, active listening, and "popularization" skills (ability to explain complex technical vulnerabilities in simple, risk-based business terms).
- Autonomous, highly organized, and capable of driving multi-stakeholder projects in a complex, regulated environment.