Information Security Officer for a Support PSF
Luxembourg, LU
Your future team
Deloitte Solutions, as a Luxembourg Support Professional of the Financial Sector (PSF), is an EU-regulated company providing managed services to Financial Institutions in collaboration with our network of member firms throughout Europe.
Leveraging our Financial, Compliance and Tax operational expertise along with dedicated technology, Deloitte Solutions provides Tax, Regulatory and Transaction Reporting services and AML/KYC managed services.
The Information Security Officer supports the Chief Risk Officer and the CISO in the operation of Deloitte Solutions’ information security framework and in the oversight of ICT and information security risks.
Are you ready to take on this new challenge? Then you should come join us!
Are you ready to take on this new challenge? Then you should come join us!
Your advantages of being one of us
- A key position at the crossroads of business, IT and risk within a Luxembourg Support PSF.
- Direct collaboration with the CRO, CISO and other control functions, with real impact on our security posture.
- Access to Deloitte’s methodologies, tools and training programs to develop your information security skills and career.
- An inclusive, international working environment with flexible work arrangements in line with firm policies
Your contribution to our success
You will be the key coordinator for information security and ICT risk topics within Deloitte Solutions. In particular, you will:
-
- Maintain Information security policies and procedures aligned to ISO 27001, CSSF 20/750 and DORA.
- Contribute to the ICT risk management framework, covering identification, assessment, mitigation, monitoring and reporting of ICT and security risks.
- Coordinate ICT/security incident management and reporting (including major ICT-related incident reporting under DORA).
- Monitor and support compliance with relevant regulations and frameworks (e.g. GDPR, ISO 27001, DORA, CSSF requirements).
- Oversee that information security controls are applied in accordance with the organization’s ISO-aligned policies, procedures and leading practices.
- Coordinate or support risk assessments, vulnerability management and penetration testing (incl. multi-annual testing plans, review of results, follow-up of remediation actions).
- Contribute to third-party and outsourcing risk management, including security requirements in contracts and review of critical / important ICT service providers in line with CSSF rules and DORA.
- Collaborate with and report to the CRO of Deloitte Solutions and to the CISO, and prepare and deliver regular reports on ICT and information security risks, incidents and key indicators to the CISO, CRO and Risk Committee.
- Collaborate closely with IT, Cybersecurity Operations team, Risk Management, Compliance, Internal Control and Internal Audit to support a robust control environment, while maintaining an appropriate level of independence from day-to-day IT operations.
Your skills
- University degree in Computer Science, Information Security, Engineering, or similar; or equivalent professional experience.
- Solid experience (4+ years) in information security / ICT risk within financial services, preferably within a Luxembourg PSF, bank, management company, or similar regulated entity.
- Knowledge of CSSF 20/750, DORA and security frameworks (ISO 27001/22301, NIST or similar) and leading practices.
- Relevant certifications (CISSP, CISM, ISO 27001 or similar) are considered as a strong plus.
- Strong organizational and time-management skills, effective stakeholder engagement, and a proactive, autonomous, hands-on working attitude.
- Ability to interact and work with senior management (CRO, CISO) and service providers in a clear, pragmatic and risk-based manner.
- Strong written communication skills for clear controls documentation and executive risk reporting, proficient in Microsoft Office (Excel, PowerPoint), fluent in French and English.
Interested? Please submit your resume in English
Get to know more about Deloitte; LinkedIn page (#DeloitteLU), Instagram page, YouTube page or website.
With more than 2,600 employees and 98 nationalities, Deloitte Luxembourg is one of the Grand Duchy's largest, strongest and oldest professional services firms. For 75 years, our talented teams have been serving clients in various industries delivering high added-value offerings to national and international clients in audit and assurance, consulting, financial advisory, risk advisory, tax, and related services. Deloitte Luxembourg is part of the global Deloitte network.
Ready, steady, interview!
Preparation is key to success! Here, we share a few tips and tricks to help you feel and look your most confident.
First impressions count!
Your recruitment process
We know waiting to hear back can be torture! Take a breath and familiarize yourself with our classic recruitment procedures.
Trust in the process