IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg
Core
Act as the control and risk right hand to the Global CISO, bridging strict European regulations (DORA, MiCA) with high-velocity global engineering to ensure the platform is compliant, resilient, and audit-ready.
Role type
IT GRC Analyst (Regulated Fintech)
Builds
A local regulated platform powered by a global-first technology model for a Stripe company (EMI/CASP).
Domain
Fintech / Cybersecurity / Regulatory Compliance (DORA, MiCA, CSSF)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT Risk Register management, DORA framework implementation, IT policy drafting and review, control testing, third-party risk assessment, SLA/KPI monitoring, Identity & Access Governance strategy, User Access Reviews, regulatory reporting liaison, BCP/DR testing coordination, incident classification and RCA
Preferred skills
Experience in Banking/Fintech/Insurance, Big 4 IT Risk advisory, CSSF/EBA guideline knowledge, Cloud fundamentals (AWS), SaaS models, modern infrastructure understanding
Technologies
AWS, SaaS models, modern infrastructure
Responsibilities
Maintain and evolve the IT Risk Register; Drive local implementation of the DORA framework; Bridge technical reality and policy by drafting IT policies; Perform periodic control testing; Support ICT due diligence and risk assessments of critical vendors; Oversee Identity & Access Governance strategy; Act as primary liaison for Internal Audit regarding IT topics; Oversee the IT incident management process
Seniority
Mid-level, hands-on IC