IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg
Core
IT GRC Analyst acting as the control and risk right hand of the Global CISO, bridging strict European regulations (DORA, MiCA) with high-velocity global engineering to ensure compliance, resilience, and audit readiness.
Role type
IT Governance, Risk & Compliance (GRC) Specialist
Builds
IT governance frameworks, risk registers, and control testing programs for a regulated fintech platform
Domain
Fintech / Digital Banking / Regulatory Compliance (CSSF, DORA, MiCA)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT Risk Management, Third-Party Risk Management (TPRM), Access Governance & Control (IAG), Regulatory Compliance & Audit Readiness, Incident Governance, Framework Knowledge (ISO 27001, NIST, COBIT), Cloud Fundamentals (AWS), SaaS models, Modern Infrastructure
Preferred skills
Experience in regulated sectors (Banking, Fintech, Insurance), Big 4 Audit (IT Risk advisory), CSSF circulars, EBA guidelines, DORA experience
Technologies
AWS, SaaS, Cloud Infrastructure
Responsibilities
Maintain and evolve the IT Risk Register, Drive local implementation of the DORA framework, Bridge the gap between technical reality and policy by drafting IT policies, Perform periodic control testing, Support ICT due diligence and risk assessments of critical vendors, Oversee Identity & Access Governance strategy, Act as primary liaison for Internal Audit regarding IT topics, Oversee the IT incident management process
Seniority
Mid-Senior, hands-on IC
