CISO as a Service

Il y a 1 mois

Luxembourg, Ville de Luxembourg Stott and May Temps plein
Job Description

Interim CISO / CISO as a Service (Freelance)

  • Role: Interim Chief Information Security Officer (CISO)
  • Format: Freelance / Contract (100% FTE)
  • Location: Luxembourg (On-site / Hybrid)
  • Remote Work: Hybrid
  • Duration: long term

Mission Overview

We are seeking a highly experienced, bilingual Interim CISO / Outsourced CISO to act as a strategic advisor to Management and drive the information security program for a prominent organization based in Luxembourg.

This is a long-term freelance engagement through 2027. The selected consultant will take operational ownership of cybersecurity governance, ensure regulatory compliance with a specific focus on NIS2, and systematically document security standards to prepare a seamless handover to a future permanent CISO.

Key Responsibilities & Deliverables

  • Governance, Compliance & Risk Management
  • NIS2 Compliance: Align the organization’s cybersecurity measures and incident reporting mechanisms with NIS2 directive requirements.
  • Risk Registry: Maintain, mature, and evolve the corporate cybersecurity risk register.
  • Policy Management: Draft, update, and implement priority security policies, procedures, and documented standards.
  • Reporting: Produce clear security dashboards, Key Risk Indicators (KRIs), and Key Performance Indicators (KPIs) for C-level Management.
  • Operational Security & Architecture Support
  • Architecture Boards: Participate in architecture reviews, evaluate security impacts for new projects, and issue formal security validations.
  • Vulnerability Management: Supervise the technical vulnerability management lifecycle and track engineering remediation plans.
  • Incident & Crisis Response: Lead the preparation for security incidents and organize business continuity/crisis management tabletop exercises.
  • Knowledge Transfer & Handover
  • Perform a comprehensive Cybersecurity Maturity Assessment and define a 12-to-24-month security roadmap.
  • Ensure continuous knowledge transfer to internal IT and infrastructure teams.
  • Compile a comprehensive Transition Playbook to guarantee a smooth ramp-up for the incoming permanent CISO.

Required Profile & Skills

Non-Negotiable Requirements

  • Experience: 10+ years of proven experience in Cybersecurity and IT Governance, with significant time spent as an active CISO, Interim CISO, or Senior GRC Consultant.
  • Languages: Fluent in French and English (both written and spoken). The candidate must be comfortable presenting technical topics to French-speaking local teams and English-speaking board members.
  • Regulatory & Frameworks: Deep knowledge of NIS2 requirements paired with a strong mastery of standard security frameworks (ISO 27001/2, NIST, CIS, or equivalent).

Technical Competencies

  • Solid experience securing hybrid environments, specifically Microsoft 365 / Entra ID, active directory, on-premises systems, and cloud infrastructures.
  • Proven ability to review complex network/system architectures and communicate security design requirements to engineering teams.

Interpersonal Skills

  • Excellent communication, active listening, and "popularization" skills (ability to explain complex technical vulnerabilities in simple, risk-based business terms).
  • Autonomous, highly organized, and capable of driving multi-stakeholder projects in a complex, regulated environment.