Associate Information Security Officer – based in Luxembourg
Join to apply for the Associate Information Security Officer – based in Luxembourg role at European Investment Bank (EIB).
Location : Luxembourg headquarters – regular office presence required. Relocation support offered.
Department : Group Risk & Compliance Directorate-Office of the Group Chief Compliance Officer (GR&C‑OCCO), Group Non‑Financial Risk Department (GNFR), Project Management & Information Security Division (PMI), Information Security Risk Unit (InfoSec).
Position : Full‑time, grade 4, permanent contract.
Purpose : The Associate Information Security Officer will be instrumental in safeguarding the Bank’s information, systems, and overall operational integrity by conducting risk‑management activities and ensuring compliance with security policies and regulations.
Responsibilities :
- Support the implementation of an Information Security Management System (ISMS) consistent with requirements and regulations.
- Assist with the development and maintenance of the bank’s information‑security policies, standards, and procedures in close collaboration with IT security, IPAQ, physical security, data protection, and other services.
- Participate in the implementation and monitoring of the EIB’s risk assessment process.
- Contribute to the development of key risk indicators and reporting dashboards, and implement consequent controls in collaboration with relevant services.
- Support business owners in carrying out information‑security risk assessments.
- Monitor the implementation of agreed information‑security controls.
- Identify and perform due diligence in line with EIB group processes for the implementation of adequate tooling.
- Collaborate with IS for the development of a work plan and agreed actions to protect the bank’s information assets.
- Provide support for internal and external audit requests.
- Contribute to information‑security incident management responses.
- Coordinate information‑security awareness programme actions via training and communication programmes.
Qualifications :
University degree (minimum bachelor level), ideally in risk management, IT or information management. Post‑graduate studies and / or certifications such as CISA, CISSP, CISM, GCIH are advantageous.Minimum 3 years of relevant experience in information security, preferably in the financial services domain.Experience supporting information‑security implementation and / or audit.Understanding of the financial services sector and its interdependence with cybersecurity.Presentation and documentation drafting skills.Knowledge of ethical hacking techniques and ability to test and validate defences (hands‑on or oversight).Experience with cloud service providers.Excellent knowledge of English and / or French (level 5 / B1.2); other EU languages are an advantage.Equity and Inclusion : We value diversity and encourage applications from all suitably qualified and eligible candidates, including those with disabilities, neurodivergent profiles, or chronic conditions. Reasonable accommodations can be requested at any stage of the recruitment process.
Application Deadline : 12 December 2025.
#J-18808-Ljbffr