Senior Information Security, Risk & Compliance Officer


Luxembourg
Permanent
Negotiable
Risk Management
PR/553203_1752672556
Senior Information Security, Risk & Compliance Officer

We are seeking a seasoned Information Security, Risk & Compliance Lead to join a fast-paced, innovation-driven crypto firm. This role is ideal for a strategic thinker with a strong generalist background across information security, risk management, and regulatory compliance - particularly within the financial services sector. You will be instrumental in shaping and scaling the information security, risk and compliance frameworks, ensuring alignment with evolving regulations such as DORA, and safeguarding our digital assets and operations.

Key Responsibilities

  • Risk Management: Develop and maintain a comprehensive enterprise risk management framework tailored to the crypto and DeFi landscape.
  • Information Security: Oversee the implementation and continuous improvement of security policies, controls, and incident response plans.
  • Regulatory Compliance: Ensure compliance with relevant regulations including DORA, MiCA, GDPR, and other applicable EU and global standards.
  • Governance & Controls: Establish and monitor internal controls, audit readiness, and governance structures across business units.
  • Cross-functional Collaboration: Partner with engineering, legal, product, and operations teams to embed risk-aware practices into the business lifecycle.
  • Third-party Risk: Assess and manage risks associated with vendors, partners, and smart contract platforms.
  • Training & Awareness: Lead internal training programs to foster a culture of security and compliance.

Key Requirements

  • Several years of experience in risk, compliance, or information security roles within financial services or FinTech.
  • Strong working knowledge of DORA and other EU regulatory frameworks.
  • Proven ability to operate as a generalist across GRC (Governance, Risk, Compliance) functions.
  • Experience with crypto, blockchain, or digital assets is highly desirable.
  • Familiarity with security standards such as ISO 27001, NIST, or CIS Controls.
  • Excellent communication and stakeholder management skills.
  • Strategic mindset with the ability to execute in a fast-moving, ambiguous environment.

FAQs

Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your resume and details on file so when we see similar roles or see skillsets that drive growth in organizations, we will always reach out to discuss opportunities.

Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.

We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business. 

That's why we recommend registering your resume so you can be considered for roles that have yet to be created. 

Yes, we help with resume and interview preparation. From customized support on how to optimize your resume to interview preparation and compensation negotiations, we advocate for you throughout your next career move.

Handpicked roles for you