Key responsibilities:
- Lead and drive the implementation and execution of information security measures, certifications and audits;
- Establish appropriate standards and associated risk controls;
- Create, review, and approve of updates and implementation of information security policies, concepts, and standards;
- Supervise information security and investigations with regard to incidents;
- Initiate and monitor efforts for regular training of relevant personnel with information security and privacy;
- Provide day-to-day expertise in commercial aspects, such as revising and drafting information security and data protection related clauses in contracts and RFPs;
- Support the Sales and Front Office Operations with information security and data protection questionnaires (e.g. contracts, tenders, RFPs, SLAs);
- Cooperation with the Data Protection Officer on the requirements related to technical and organisation measures for secure processing of personal data;
- Contribute to building an in-house information security and data protection knowledge focused on supporting and facilitating commercial and legal processes;
- Work in a small team composed of information security, legal, privacy, and risk management experts.
Must-have qualifications:
- Hold a bachelor level degree or equivalent in information security, law, privacy, or similar with proven experience in the field, ideally as a consultant or as part of an in-house team;
- Thorough knowledge of international information security standards;
- Knowledge of information security risk management (such as ISO 27005);
- Strong knowledge of privacy principles and GDPR;
- Strong negotiation skills;
- Fluency in English;
- Creative, self-motivated, and willingness to try things;
- Strategic thinker, an excellent communicator (both written and verbal), and a keen problem solver who knows how to assess risk and recommend solutions that balance business and risk perspectives in order to meet strict deadlines;
- Flexible and have an eagerness to work on a broad range of activities combining information security and privacy with legal matters.
Nice-to-have qualifications:
- Additional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), or Certified Information Privacy Professional (CIPP);
- Experience or knowledge of security practices and compliance requirements specific to the SaaS industry;
- Prior involvement in handling and managing information security incidents, including incident response planning, incident handling, and forensic investigation, would be desirable;
- A second language is a plus.
What we offer [in Luxembourg]:
- Competitive base salary and opportunity for bonus;
- Optional health insurance;
- 3 Volunteering Day per year;
- 26 days of vacation + Bonus holidays;
- Lunch vouchers.
What you can expect from the interview process:
- 1st interview with Zach, our Talent & Culture Business Partner - 30 minutes
- 2nd interview with our Legal Counsel - 60 minutes
- 3rd interview with our Director of Privacy & Legal and our Information Security Specialist - 60 minutes
- Final interview with the hiring manager, our Head of Legal - 60 minutes