About Luxtrust
We are a multicultural and forward-thinking qualified Trust Services Provider based in Capellen, Luxembourg, with over 110 professionals and actively expanding our business internationally. We provide state-of-the-art on on-boarding, digital identities, strong authentication and security services, and qualified electronic signatures, all bundled into integrated digital documents & identity management solutions.
As a Trusted Partner, we prioritize building long-lasting relationships with our international clients and stakeholders, based on trust and integrity. We strive to be a Committed Partner, dedicating ourselves to delivering exceptional performance and showing steadfast commitment to make a positive impact. As a Visionary Scout, we are constantly seeking out new opportunities for growth and innovation, always staying ahead of the curve in our industry.
Join us in our mission to drive innovation and co-create a better future!
We are currently looking for a motivated and driven Information Security Officer.
Summary
This role contributes to improve IT security controls effectiveness, increase ISMS process maturity and keep IT risks exposure under accepted level by assisting the Chief Information Security Officer in its missions.
Missions of the role
Security Operation activities such as vulnerability management; threats monitoring; threat prevention (phishing tentative, SIEM alerts) and log review. Improve threat detection capabilities by reviewing SIEM use cases on a regular basis in closed collaboration with our SOC partner.
The security recurring controls annual plan such as access right reviews, suppliers due diligence, Supplier Review Meetings, hardening guide and CIS conformity audits of IT.
Involved in penetration-testing campaign on corporate environment. Defines pen-testing scope, prepare and coordinate pen-testers activities, review pen-testing results with IT department and manage recommendations action plan.
LuxTrust security controls: contribute to annual supplier due diligence assessment, represent department in the Compliance and audit exercises and maintain our security controls documentation accordingly.
Security incident: Involved in security Incident review, problem review and associated KPIs / KRIs reporting.
Contribute to an ongoing, proactive risk assessment program for all new and existing systems in our corporate environment and ensure that effective controls to manage these risks are in place against the company’s goals and business processes.
Participate in Audit ISO27001 and any other audits applicable to LuxTrust entities.
Manages security awareness annual program.
Implements security improvements by assessing current situation; evaluating trends; anticipating requirements; evaluation security incidents.
Provide Information Security advisory to both IT and Business units by assisting Legal, Compliance and Sales teams in due diligence exercises, new process flow or use cases and any security questions. Lead supplier due diligence assessment for the security aspects.
Maintain and improve ISMS documentation based on knowledge of best practices, regulatory requirements and specific needs of LuxTrust. Involved in procedures development and maintain it on annual basis. Participate to the Policy/Standards document review.
Assist the IT team in performing risk assessment related to technology implementation :
o Perform research and coordination with IT to drive security
o Perform research and recommendation of appropriate security protection products and services, such as log management, security event management, and intrusion detection
Project management of any related project.
Required skills
Qualifications / diploma(s): Bachelor’s or Master’s degree in Information Technology, Information Security or related experience.
Years of experience in the area:
5+ years of experience in Information Technology with security focus.
Experience in developing, documenting and maintaining policies, processes, procedures and standards
Prior security audit experience would be an asset
Knowledge of and experience in understanding documentation and regulatory compliance requirements is an asset.
Technical competencies:
Skills and knowledge of IT, networks and Information security business
PKI knowledge is an asset
Languages: French and English fluent. Any other language is an asset.
Specific skills:
Strong analytical skills to analyze information security requirements and relate them to appropriate controls
Organized, responsive, accountable and highly thorough of problem solving oriented and solution driven
Ability to synthesize
Proactive attitude
Good team player and positive attitude in a challenging environment
Strong communication and writing skills
Foster teamwork and collaboration
Core competencies at LuxTrust:
Analytical mindset & decision making
Organizational fluency
Personal effectiveness
Results-driven
Client service mindset
Strategic vision
Leadership
What we offer
A permanent contract based in Capellen - Luxembourg
A competitive salary, in accordance with your education and experience.
Attractive benefits and advantages including an employee benefit plan, a gym, meal vouchers and additional holidays.
A healthy work-life balance including flex work arrangements.
Parking spaces for all employees.
An open and transparent career path.
Development and growth opportunities in a state-of-the art digital company.
Our company is committed to fair recruitment, based on the skills of each candidate, regardless of gender nationality, sexual orientation, religion, or any other discriminatory criterion.
Please note that in order to comply with our regulatory requirements an extract of the criminal record is requested upon entry into service.
