Live opening · Posted 1 day ago

IT Security Officer

CO_GSCAPX-VAL Apex Financial Services Spain, SL · Munsbach, 3 rue Gabriel Lippmann
Workday
You are 1 day behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 1 day ago
CompanyCO_GSCAPX-VAL Apex Financial Services Spain, SL
LocationMunsbach, 3 rue Gabriel Lippmann
SkillsAzure
SourceWorkday
Listed1 day ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
35 min from Workday publishing this role to us finding it
6 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,428 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.
Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.
That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.
Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.
For our business, for clients, and for you
Role Purpose
The Information Security Officer is a Luxembourg-based Second Line of Defense role responsible for providing independent oversight, challenge, and assurance over information security, ICT risk, cyber resilience, and technology control practices for European Businesses specially within Luxembourg.
The role supports compliance with applicable regulatory expectations, including DORA, CSSF requirements, Bank of Ireland, internal policies, APEX Group standards, and risk appetite of the businesses. The role provides independent reporting and escalation to local management, governance committees, Group CISO, Regional CISO and Board-level forums, and challenges the design, implementation, remediation, and operating effectiveness of ICT and information security controls.
Key Responsibilities
Provide independent Second Line oversight and challenge of information security, ICT risk, cyber resilience, and technology control practices across Luxembourg entities.
Work together with regional CISO to carry on oversight can control tasks for region for information and cybersecurity resilience.
Review and challenge first-line control design, implementation, control testing results, remediation plans, policy exceptions, and risk acceptances.
Maintain and support the local information security governance framework in alignment with Group policies, local regulatory expectations, and the Bank’s risk appetite.
Perform and document information security and ICT risk assessments, control assurance reviews, thematic reviews, and independent risk opinions.
Support DORA-related oversight activities, including ICT risk management, ICT-related incident management, digital operational resilience testing, and ICT third-party risk oversight.
Oversee and challenge third-party, outsourcing, cloud, SaaS, and critical or important ICT service provider risks, including due diligence, contractual security controls, exit arrangements, concentration risk, and ongoing monitoring.
Support the quality review and maintenance of ICT third-party risk information, including inputs relevant to the DORA Register of Information where applicable.
Provide independent oversight of security incidents, including challenge of impact assessment, root cause analysis, remediation, lessons learned, and escalation decisions.
Monitor and report material information security risks, vulnerabilities, audit findings, regulatory findings, incidents, overdue remediation actions, and accepted risks.
Maintain local information security risk registers, control assurance records, exceptions, risk acceptance documentation, action trackers, and evidence repositories.
Support regulatory and supervisory engagements, including CSSF requests, inspections, thematic reviews, client due diligence, internal audit, and external audit activities.
Prepare and present information security and ICT risk reporting to Authorized Management, Risk Committees, Board meetings, governance forums, client due diligence meetings, and other relevant stakeholders.
Review and contribute to local policies, standards, procedures, and operating processes to ensure they remain current, proportionate, and aligned with Group and regulatory expectations.
Promote information security awareness, risk culture, and clear accountability across the Luxembourg business and technology teams.
Coordinate with Regional CISO, Group CISO, Technology, Risk, Compliance, Legal, DPO, Outsourcing, Internal Audit, and business stakeholders to ensure consistent and effective security risk oversight.
Key Skills and Experience
Essential:
7+ years of experience in information security, ICT risk, technology risk, cyber risk, internal control, audit, or technology assurance within financial services or another regulated environment.
Strong understanding of Second Line of Defense oversight, independent challenge, risk governance, and control assurance models.
Good knowledge of DORA, CSSF ICT and cyber risk expectations, outsourcing requirements, operational resilience, and technology risk management in EU or Luxembourg regulated financial services.
Practical knowledge of recognized security and risk frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, CIS Controls, or equivalent.
Hands on experience in enterprise security tooling like firewalls, IDS/IPS, DLP, Tessian, Azure AD, Microsoft Security solutions, Cyber-arc, Patching solutions, SOC solutions
Experience performing ICT or information security risk assessments, control reviews, gap assessments, remediation tracking, and management reporting.
Experience supporting regulatory, internal audit, external audit, supervisory, or client due diligence engagements.
Strong written and verbal communication skills, with the ability to translate technical risks into clear management and Board-level reporting.
Ability to challenge senior technology and business stakeholders constructively, objectively, and with evidence-based reasoning.
Desirable:
Experience in Luxembourg banking or other CSSF-supervised environments.
Exposure to cloud security, outsourcing oversight, SaaS risk, identity and access management, vulnerability management, SIEM/SOC operations, incident response, and resilience testing.
Experience with maintaining risk registers, control libraries, policy exception registers, audit action trackers, and regulatory evidence packs.
Professional certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, or equivalent.
French, German, or Luxembourgish language skills would be beneficial, in addition to fluent business English.
Personal Attributes
Independent, objective, and confident in providing constructive challenge.
Strong risk mindset with sound judgement and attention to regulatory detail.
Clear, concise communicator able to engage technical, business, senior management, and Board-level

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App