# IT Governance, Risk & Compliance (GRC) Analyst, Luxembourg

**Company**: Bridge Building S.A. (BBSA), a Stripe company
**Location**: Luxembourg
**Experience**: mid
**Job type**: full-time
**Category**: IT
**Industry**: Finance

**Apply**: https://job-boards.greenhouse.io/stripe/jobs/7587254?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_0512f8a8-faa

## Description

We are seeking an IT Governance, Risk & Compliance (GRC) Analyst to join our team in Luxembourg. As a key member of our IT team, you will play a crucial role in ensuring the compliance and resilience of our regulated fintech platform.

The successful candidate will be responsible for maintaining and evolving our IT Risk Register, driving the local implementation of the DORA framework, and bridging the gap between technical reality and policy.

Key responsibilities include:

- Maintaining and evolving the IT Risk Register

- Driving the local implementation of the DORA framework

- Bridging the gap between technical reality and policy

- Performing periodic control testing

- Acting as primary support to the local Head of IT

- Supporting ICT due diligence and risk assessments of critical vendors and service providers

- Monitoring SLAs and KPIs of critical vendors

- Overseeing the Identity & Access Governance strategy

- Conducting periodic User Access Reviews for critical systems

- Acting as primary liaison for Internal Audit regarding IT topics

- Preparing technical inputs and evidence for CSSF notifications and regulatory reporting

- Monitoring compliance with GDPR/Data Privacy controls

- Coordinating Business Continuity (BCP) and Disaster Recovery (DR) testing documentation and reporting

- Overseeing the IT incident management process

The ideal candidate will have a strong understanding of IT governance, risk, and compliance, as well as excellent communication and analytical skills.

## Skills

### Required
- IT Governance
- Risk Management
- Compliance
- DORA framework
- ICT risk management
- Incident classification
- IT policies and procedures
- Control testing
- Third-party risk management
- Access Governance
- Regulatory Compliance
- Audit Readiness

### Nice to have
- Experience in a regulated sector (Banking, Fintech, Insurance)
- Big 4 Audit (IT Risk advisory)
- CSSF circulars
- EBA guidelines
- DORA
- ISO 27001
- NIST
- COBIT
- Cloud fundamentals (AWS)
- SaaS models
- Modern infrastructure

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/stripe/jobs/7587254?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
