It Governance, Risk & Compliance (grc) Analyst, Luxembourg

Stripe Stripe · Fintech · Luxembourg, Luxembourg · 8505 Bridge - G&A

IT GRC Analyst for a regulated Luxembourg fintech entity (Stripe company) focusing on ensuring IT controls, risk management, and compliance with regulations like DORA and MiCA. The role involves translating regulatory requirements into tangible IT controls, overseeing third-party risks, and maintaining the governance framework, requiring a good understanding of technology but not coding.

What you'd actually do

  1. Maintain and evolve the IT Risk Register, ensuring risks are identified, assessed, and treated in line with the company’s risk appetite.
  2. Drive the local implementation of the DORA (Digital Operational Resilience Act) framework, including ICT risk management and incident classification.
  3. Bridge the gap between technical reality and policy by drafting, reviewing, and updating IT policies and procedures.
  4. Perform periodic control testing to ensure global engineering practices align with local regulatory requirements.
  5. Support ICT due diligence and risk assessments of critical vendors and service providers, while assisting with Developer / Customer Oversight.

Skills

Required

  • IT Governance
  • Risk Management
  • GRC
  • Information Security
  • ISO 27001
  • NIST
  • COBIT
  • Cloud fundamentals (AWS)
  • SaaS models
  • modern infrastructure
  • English (Fluent professional)

Nice to have

  • Banking
  • Fintech
  • Insurance
  • Big 4 Audit (IT Risk advisory)
  • CSSF circulars
  • EBA guidelines
  • DORA
  • French

What the JD emphasized

  • DORA
  • MiCA
  • regulated environment
  • CSSF
  • ICT risk management
  • third-party risks
  • governance framework
  • IT controls
  • regulatory requirements
  • GDPR
  • Data Privacy
  • Business Continuity
  • Disaster Recovery
  • incident management
  • regulators