- Location
- DNU Luxembourg, rue Gabriel Lippmann
- Type
- Full-time
- Department
- Administration
- Experience
- 7+ years
- Source
- Workday
Description
The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.
Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.
That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.
Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.
For our business, for clients, and for you
Role Purpose
The Information Security Officer is a Luxembourg-based Second Line of Defense role responsible for providing independent oversight, challenge, and assurance over information security, ICT risk, cyber resilience, and technology control practices for European Businesses specially within Luxembourg.
The role supports compliance with applicable regulatory expectations, including DORA, CSSF requirements, Bank of Ireland, internal policies, APEX Group standards, and risk appetite of the businesses. The role provides independent reporting and escalation to local management, governance committees, Group CISO, Regional CISO and Board-level forums, and challenges the design, implementation, remediation, and operating effectiveness of ICT and information security controls.
Key Responsibilities
- Provide independent Second Line oversight and challenge of information security, ICT risk, cyber resilience, and technology control practices across Luxembourg entities.
- Work together with regional CISO to carry on oversight can control tasks for region for information and cybersecurity resilience.
- Review and challenge first-line control design, implementation, control testing results, remediation plans, policy exceptions, and risk acceptances.
- Maintain and support the local information security governance framework in alignment with Group policies, local regulatory expectations, and the Bank’s risk appetite.
- Perform and document information security and ICT risk assessments, control assurance reviews, thematic reviews, and independent risk opinions.
- Support DORA-related oversight activities, including ICT risk management, ICT-related incident management, digital operational resilience testing, and ICT third-party risk oversight.
- Oversee and challenge third-party, outsourcing, cloud, SaaS, and critical or important ICT service provider risks, including due diligence, contractual security controls, exit arrangements, concentration risk, and ongoing monitoring.
- Support the quality review and maintenance of ICT third-party risk information, including inputs relevant to the DORA Register of Information where applicable.
- Provide independent oversight of security incidents, including challenge of impact assessment, root cause analysis, remediation, lessons learned, and escalation decisions.
- Monitor and report material information security risks, vulnerabilities, audit findings, regulatory findings, incidents, overdue remediation actions, and accepted risks.
- Maintain local information security risk registers, control assurance records, exceptions, risk acceptance documentation, action trackers, and evidence repositories.
- Support regulatory and supervisory engagements, including CSSF requests, inspections, thematic reviews, client due diligence, internal audit, and external audit activities.
- Prepare and present information security and ICT risk reporting to Authorized Management, Risk Committees, Board meetings, governance forums, client due diligence meetings, and other relevant stakeholders.
- Review and contribute to local policies, standards, procedures, and operating processes to ensure they remain current, proportionate, and aligned with Group and regulatory expectations.
- Promote information security awareness, risk culture, and clear accountability across the Luxembourg business and technology teams.
- Coordinate with Regional CISO, Group CISO, Technology, Risk, Compliance, Legal, DPO, Outsourcing, Internal Audit, and business stakeholders to ensure consistent and effective security risk oversight.
Key Skills and Experience
Essential:
- 7+ years of experience in information security, ICT risk, technology risk, cyber risk, internal control, audit, or technology assurance within financial services or another regulated environment.
- Strong understanding of Second Line of Defense oversight, independent challenge, risk governance, and control assurance models.
- Good knowledge of DORA, CSSF ICT and cyber risk expectations, outsourcing requirements, operational resilience, and technology risk management in EU or Luxembourg regulated financial services.
- Practical knowledge of recognized security and risk frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, CIS Controls, or equivalent.
- Hands on experience in enterprise security tooling like firewalls, IDS/IPS, DLP, Tessian, Azure AD, Microsoft Security solutions, Cyber-arc, Patching solutions, SOC solutions
- Experience performing ICT or information security risk assessments, control reviews, gap assessments, remediation tracking, and management reporting.
- Experience supporting regulatory, internal audit, external audit, supervisory, or client due diligence engagements.
- Strong written and verbal communication skills, with the ability to translate technical risks into clear management and Board-level reporting.
- Ability to challenge senior technology and business stakeholders constructively, objectively, and with evidence-based reasoning.
Desirable:
- Experience in Luxembourg banking or other CSSF-supervised environments.
- Exposure to cloud security, outsourcing oversight, SaaS risk, identity and access management, vulnerability management, SIEM/SOC operations, incident response, and resilience testing.
- Experience with maintaining risk registers, control libraries, policy exception registers, audit action trackers, and regulatory evidence packs.
- Professional certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, or equivalent.
- French, German, or Luxembourgish language skills would be beneficial, in addition to fluent business English.
Personal Attributes
- Independent, objective, and confident in providing constructive challenge.
- Strong risk mindset with sound judgement and attention to regulatory detail.
- Clear, concise communicator able to engage technical, business, senior management, and Board-level audiences.
- Structured and organised, with the ability to maintain evidence, track remediation, and manage multiple priorities.
- Collaborative and pragmatic, while maintaining an appropriate level of independence from first-line technology operations.
- High integrity, discretion, and professionalism when handling sensitive security, incident, audit, and regulatory information.
Scope Clarification
This is primarily an oversight, governance, and assurance role rather than a hands-on SOC analyst, security engineering, or IT operations role. The successful candidate is expected to challenge and oversee first-line activities, not directly operate or own first-line controls except where explicitly agreed through governance.
Suggested Performance Objectives
- Maintain a current and evidence-based view of key information security, ICT, third-party, and regulatory risks.
- Improve the quality, completeness, and timeliness of risk acceptance, remediation, and governance reporting.
- Support regulatory readiness for DORA, CSSF, audit, client due diligence, and Board-level scrutiny.
- Strengthen collaboration between local management, Group CISO, Technology, Risk, Compliance, Legal, DPO, and Outsourcing stakeholders.
Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.