Demo

Auditor/analyst – “off-site” ICT risk supervision (m/f)

POSTED ON 4/24/2025 AVAILABLE BEFORE 6/15/2025

Mission

As part of a specialised team, you will be in charge of analysing risk management measures related to information and communication technology (ICT) as part of the review of application files for authorisation of future financial entities and as part of the ongoing supervision of financial entities. You may participate to transversal thematic analyses and/or to national and international working groups dedicated to technical or regulatory aspects in this area. You may also participate to missions of the EU-wide joint oversight framework of critical IT third-party service providers established by the Digital Operational Resilience Act (“DORA regulation”) on the digital operational resilience of the financial sector.

Role & responsibilities

  • Analyse the sections relating to ICT organisation and ICT risk management in application files for authorisation of future professionals of the financial sector
  • Analyse the notifications for use of ICT third party service providers of entities supervised by the CSSF
  • Provide expertise and support to other supervisory departments in assessing the compliance of supervised entities with the DORA regulation
  • Provide various types of advice to other supervisory departments (advice on supervised entities’ IT strategy, their digital transformation, findings raised by their internal or external IT auditors, etc.);
  • Contribute to technological and regulatory watch in relation with new technologies and digitalization;
  • Participate in transversal analyses on topics related to ICT risk management;
  • Participate to national and international working groups dedicated to ICT and ICT risk supervision;
  • Participate to joint examinations of critical IT third-party service providers under DORA regulation

Your profile

  • University degree (at least BAC 3/Bachelor) in information systems audit, or in IT security with a specialization in finance, or in economics, finance or business management with an ICT specialization
  • Proven professional experience of at least 3 years in either the field of information systems auditing or in ICT risk management
  • Perfect command of written and spoken English. Fluency in French and/or German. Knowledge of Luxembourgish will be considered as an advantage
  • Commitment to be available for business trips abroad
  • Excellent knowledge of the CSSF circulars notably relating to ICT risk management and to ICT outsourcing
  • Knowledge of European regulation in this area (i.e. DORA, PSD, eIDAS, NIS, etc.) and interest in new technologies and digital solutions (DLT, AI, virtual currencies/crypto assets, open banking/finance, etc.) constitute an advantage
  • CISA, CISM, CISSP or equivalent certifications are an asset
  • Writing, analytical, synthesis skills and thoroughness
  • Proactivity and flexibility; ability to work independently as well as good team spirit
  • Communication skills
  • Confidentiality

The successful candidate (m/f) will be hired as public employee (“employé de l’Etat”) under a permanent contract. If the candidate meets the required conditions, s/he will be asked to apply for admission to the status of civil servant (“fonctionnaire de l’Etat”).

Prior to the conclusion of the contract, the candidate must submit an extract from the criminal record (bulletin n°3), dated less than 2 months, in order to prove their conduct and integrity.

Popular Search Topics

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Commission de Surveillance du Secteur Financier (CSSF)

Commission de Surveillance du Secteur Financier (CSSF)
Hired Organization Address Luxembourg, LU Full Time
Mission Your main responsibility is the prudential supervision of a portfolio of investment fund managers subject to the...
Commission de Surveillance du Secteur Financier (CSSF)
Hired Organization Address Luxembourg, LU Full Time
Mission The SPII Prudential Supervision division, part of the UCI Prudential Supervision and Risk Management department,...
Commission de Surveillance du Secteur Financier (CSSF)
Hired Organization Address Luxembourg, LU Full Time
Mission The SPII Prudential Supervision division within the UCI Prudential Supervision and Risk Management department is...
Commission de Surveillance du Secteur Financier (CSSF)
Hired Organization Address Luxembourg, LU Full Time
Role & responsibilities As part of the “HR Administration & Analytics” division, you will be responsible for managing a ...

Not the job you're looking for? Here are some other Auditor/analyst – “off-site” ICT risk supervision (m/f) jobs in the Luxembourg, LU area that may be a better fit.

Consultant Business Analyst

UFO² Consulting, Luxembourg, LU