Talent.com
Luxembourg Institute of Science and Technology (LIST)
FA-26021 SENIOR INFORMATION SECURITY & GRC EXPERTLuxembourg Institute of Science and Technology (LIST) • Esch-sur-Alzette, Esch-sur-Alzette, LU
FA-26021 SENIOR INFORMATION SECURITY & GRC EXPERT

FA-26021 SENIOR INFORMATION SECURITY & GRC EXPERT

Luxembourg Institute of Science and Technology (LIST) • Esch-sur-Alzette, Esch-sur-Alzette, LU
Il y a plus de 30 jours
Description de poste

Permanent contract | Belval

Are you passionate about research? So are we! Come and join us


The Luxembourg Institute of Science and Technology (LIST) is a Research and Technology Organization (RTO) active in the fields of materials, environment and IT. By transforming scientific knowledge into technologies, smart data and tools, LIST empowers citizens in their choices, public authorities in their decisions and businesses in their strategies.

Do you want to know more about LIST? Check our website: https://www.list.lu/

How will you contribute?

The Information Security & GRC Expert supports the implementation, maintenance, and continuous improvement of the organization’s Information Security Management System (ISMS). The role focuses on governance, risk management, compliance, and security policy frameworks while ensuring alignment between business objectives, regulatory requirements, and evolving cyber threats.

You will be mainly in charge of:

  • Support the implementation and continuous improvement of the Information Security Management System (ISMS) in alignment with the business strategy, internal and external contexts, legal, regulatory, and contractual requirements, and international standards (e.g., NIS2, GDPR, ISO/IEC 27001).

  • Develop, review, and maintain information security policies, standards, procedures, and guidelines.

  • Conduct information security risk assessments and support risk treatment planning, ensuring risks are identified, analysed, evaluated, and mitigated appropriately following a risk-based approach.

  • Support and operate the security exception management process, including documenting, assessing, approving, and tracking risk-based exceptions to security policies and controls.

  • Define, implement, and monitor administrative, organizational, and technical security controls aligned with regulatory and internal requirements.

  • Coordinate with internal stakeholders to ensure security requirements are integrated into projects, processes, and IT services, supporting secure-by-design practices.

  • Define and track information security KPIs/KRIs, metrics, and dashboards to support risk-informed decision-making and management reporting.

  • Contribute to the identification, assessment, and monitoring of internal and external information security risks, maintaining relevant risk registers and documentation.

  • Produce and maintain security documentation, including procedures, risk registers, control frameworks, and governance artefacts.

  • Support governance processes such as risk committees, security reviews, and compliance monitoring activities.

  • Contribute to security awareness initiatives across the organization.

  • Provide expert guidance and recommendations on information security governance, risk management, and compliance topics.

  • Support and contribute to the security incident management and response process, ensuring lessons learned are integrated into the ISMS improvement cycle.

Is Your profile described below? Are you our future colleague? Apply now!


Education

  • Bac+5, graduated in Information security/cyber security

Experience and skills

  • At least 5 years of professional experience in Information Security Governance, Risk Management, and Compliance (GRC).

  • Strong experience in defining, documenting, and maintaining information security policies, standards, procedures, and security requirements aligned with regulations (e.g., NIS2), legal frameworks (e.g., GDPR, AI Act), and recognized standards (e.g., ISO/IEC 27000 series), with hands-on experience in implementing and operationalizing these frameworks.

  • Proven experience in conducting information security risk assessments, risk analysis, and risk treatment planning.

  • Experience in the definition, implementation, and monitoring of security controls to ensure compliance with internal policies and regulatory requirements.

  • Familiarity with the definition, monitoring, and reporting of security KPIs and KRIs to support governance and risk oversight.

  • Strong analytical, documentation, and stakeholder communication skills, with the ability to translate security requirements into practical controls and processes.

  • Knowledge of IT security technologies, tools, and infrastructure.

  • Understanding of information security audit mechanisms, as well as penetration testing and vulnerability assessment methodologies.

  • Knowledge of project management practices, progress tracking tools, and reporting methodologies.

  • Relevant certifications such as ISO/IEC 27001 Lead Implementer or Lead Auditor are considered an advantage.

  • Ability to collaborate effectively with both technical and non-technical stakeholders across the organization.

Language skills

  • Good level both written and spoken English and French

Your LIST benefits


  • An organization with a passion for impact and strong RDI partnerships in Luxembourg and Europe that works on responsible and independent research projects

  • Sustainable by design, empowering our belief that we play an essential role in paving the way to a green society

  • Innovative infrastructures and exceptional labs occupying more than 5,000 square metres, including innovations in all that we do

  • An environment encouraging curiosity, innovation and entrepreneurship in all areas

  • Personalized learning programme to foster our staff’s soft and technical skills

  • Multicultural and international work environment with more than 50 nationalities represented in our workforce

  • Diverse and inclusive work environment empowering our people to fulfil their personal and professional ambitions

  • Gender-friendly environment with multiple actions to attract, develop and retain women in science

  • 32 days’ paid annual leave, 11 public holidays, 13-month salary, statutory health insurance

  • Flexible working hours, home working policy and access to lunch vouchers

Apply online

Your application must include:

  • A motivation letter oriented towards the position and detailing your experience

  • A CV with contact details

  • Contact details of 2 references

Please apply ONLINE formally through the HR system. Applications by email will not be considered.

Application procedure and conditions
  • We kindly request applicants to provide their nationality for statistical purposes only, as part of our commitment to promoting diversity and ensuring equal opportunities in our workforce. This information will be kept confidential and will not be used for any discriminatory purposes.

  • LIST is dedicated to maintaining an inclusive work environment and is an equal opportunity employer. We are committed to attracting, hiring, and retaining a diverse workforce. All applicants will be considered for employment without discrimination based on national origin, race, colour, gender, sexual orientation, gender identity, marital status, religion, age, or disability.

  • Applications will be continuously reviewed until the position is filled. An assessment committee will thoroughly evaluate applications, adhering to guidelines designed to ensure equal opportunities. The primary criteria for selection will be the alignment of the applicant's existing skills and expertise with the requirements mentioned above.

Créer une alerte emploi pour cette recherche

FA-26021 SENIOR INFORMATION SECURITY & GRC EXPERT • Esch-sur-Alzette, Esch-sur-Alzette, LU

Offres similaires

APPLICATION HARDENING / SECURITY SPECIALIST

BlackRidge GroupLuxembourg, Luxembourg, LU

Application Hardening / Security Specialist.We are looking for an experienced Application Security and Hardening Specialist to assess, strengthen, and advise on the security posture of enterprise a... Voir plus

AKAMAI GUARDICORE SEGMENTATION SPECIALIST

BlackRidge GroupLuxembourg, Luxembourg, LU

Akamai Guardicore Segmentation Specialist.We are looking for a specialist with hands-on expertise in Akamai Guardicore Segmentation to support the design, implementation, and ongoing operation of m... Voir plus

Responsable IT Security & Risk Management (M/F/D) - Livange - CDI - 40h (6319)

Croix-Rouge luxembourgeoiseLuxembourg, Luxembourg, LU

Responsable IT Security & Risk Management (M/F/D) - 6319.Pour son service Informatique à Livange en CDI à 40h/semaine.En tant que Responsable IT Security & Risk Management, vous prenez la responsab... Voir plus

NSI - Experienced Cyber - Security Officer

NSIluxembourg, Luxembourg

As part of our growth, we are currently looking for an.Experienced Cyber-Security Officer.Your main responsibilities as a Consultant.Ensure security compliance for all assets hosted in our Luxembou... Voir plus

 • Offre sponsorisée

SD -26101- POST DOC ON LOW TEMPERATURE ELECTROCALORIC EFFECT IN CERAMICS

Luxembourg Institute of Science and Technology (LIST)Esch-sur-Alzette, Esch-sur-Alzette, LU

Fixed term contract | Belval | Up to 24 Months.Are you passionate about research? So are we! Come and join us.The Luxembourg Institute of Science and Technology (LIST) is a leading Research and Tec... Voir plus

SecOps Engineer

LuxtrustCapellen, Capellen, LU

We are a multicultural and forward-thinking qualified Trust Services Provider based in Capellen, Luxembourg, with over 110 professionals and actively expanding our business internationally.We provi... Voir plus

IT SECURITY OFFICER

BlackRidge GroupLuxembourg, Luxembourg, LU

En tant qu'IT Security Officer, vous contribuez activement au renforcement de la posture de cybersécurité de l'organisation.Vous intervenez sur la mise en œuvre et le contrôle des mesures de sécuri... Voir plus

Senior IT Operational Security Administrator – CDI

Nomura Bank (Luxembourg) S.A.Hesperange, Hesperange, LU

The Department acts as IT first line of defense, and is responsible of administration and setup of the internal and external security systems, and network infrastructure.In order to support our tea... Voir plus

Chief Information Security Officer (CISO)

Luxembourg Stock ExchangeLuxembourg, Luxembourg, LU

Located in the heart of Luxembourg city, the Luxembourg Stock Exchange (LuxSE) is home to over 51,000 international securities and gathers diverse and committed teams covering listing, trading, inf... Voir plus

IT-SICHERHEITSSPEZIALISTEN (m/w/d)

Société Nationale des Habitations à Bon Marché (SNHBM)Luxembourg, Luxembourg, LU

Als einer von zwei öffentlichen Bauträgern haben wir uns im Rahmen der aktuellen Politik zur Förderung des sozialen Wohnungsbaus ehrgeizige Ziele gesetzt.In unserem Unternehmen mit rund 200 Mitarbe... Voir plus

IT-SICHERHEITSSPEZIALISTEN (m/w/d)

Société Nationale des Habitations à Bon Marché S.A.Luxembourg, Luxembourg, LU

Als einer von zwei öffentlichen Bauträgern haben wir uns im Rahmen der aktuellen Politik zur Förderung des sozialen Wohnungsbaus ehrgeizige Ziele gesetzt.In unserem Unternehmen mit rund 200 Mitarbe... Voir plus

Dionys - Security Officer Senior - EndPoint Security & Hardening

Dionysluxembourg, Luxembourg

Vos principales responsabilités.Définir et mettre en œuvre les politiques de sécurité des endpoints (postes de travail et serveurs).Piloter les activités de hardening des systèmes (Windows / Linux)... Voir plus

 • Offre sponsorisée

C-25009 SENIOR BUSINESS DEVELOPER BIOTECH, GREENTECH AND AGRI-ENVIR INNOVATION

Luxembourg Institute of Science and Technology (LIST)Esch-sur-Alzette, Esch-sur-Alzette, LU

Are you passionate about research valorisation and business development ? So are we! Come and join us.The Luxembourg Institute of Science and Technology (LIST) is a Research and Technology Organiza... Voir plus

Senior Risk Analyst

Axis LuxembourgLuxembourg, Luxembourg, LU

Contribute to the development and implementation of the risk management strategy and annual risk plan aligned with business objectives.Maintain and embed an effective risk management framework cove... Voir plus

IT Systems Administrator & Security Manager (m/f/d)

Schroeder & AssociésKockelscheuer, Kockelscheuer, LU

Engineering the future together » - chez Schroeder & Associés, nous construisons l'avenir avec passion et expertise.Situé près de la Cloche d’Or, notre bureau d’ingénieurs-conseils prône des valeur... Voir plus

Hays - Information Security Officer

Haysluxembourg, Luxembourg

Nous sommes à la recherche d'un Information Security Officer pour l'un de nos clients basé à Luxembourg.Solide connaissance en sécurité des systèmes d'information (GRC, gestion des risques, opérati... Voir plus

 • Offre sponsorisée

IT Security Expert (m/f/n)

EnovosEschsurAlzette, EschsurAlzette, LU

You design, implement and maintain cutting-edge security measures across network, application, and monitoring assets, aligning with the current state-of-the-art practices in the industry.You analys... Voir plus

Senior Operational Risk Manager (M/F/X)

Banque Raiffeisen S.C.Leudelange, Leudelange, LU

Première banque coopérative au Luxembourg, la Banque Raiffeisen a su évoluer au fil des années de manière constante et autonome tout en gardant à l'esprit les valeurs fondamentales qui la caractéri... Voir plus