About this role
Job title: ICT Operations Lead (Luxembourg)
About the Role
Ripple is expanding its Information Security function and seeking experienced professionals to join us in building a world-class program. This role is based in our Luxembourg entity and strengthens local operational presence and governance to support Ripple's growing regulated activities in Europe.
What You'll Do
-
Ensure operational implementation and maintenance of EU / Luxembourg security frameworks (including DORA) and supporting technical standards.
-
Lead day-to-day management and oversight of outsourced ICT and security services, ensuring service delivery meets local regulatory standards and SLAs.
-
Collaborate with global Engineering and IT teams to evaluate future infrastructure, application, and architectural changes with operational resilience and regional compliance in mind.
-
Coordinate the implementation of technical security controls across infrastructure and application environments in line with Ripple's internal controls and regulatory guidelines (EBA, ESMA, CSSF).
-
Localize and maintain InfoSec Policies, Standards, and Procedures for EU compliance in collaboration with global teams.
-
Directly access systems to pull evidence (logs, settings, access reports) to support monitoring, incident response, and compliance.
-
Act as operational subject matter expert during internal audits, customer audits, and regulatory exams by providing technical evidence and demonstrating knowledge of infrastructure and security processes.
-
Partner with Engineering, Compliance, Finance, Product, Legal, and Sales to provide operational security guidance and impact Ripple’s product security and customer trust.
-
Support regional customer-facing activities by responding to security questionnaires and reviewing technical aspects of customer contracts.
-
Attend local and regional industry events to stay current on evolving regulations, threats, and best practices.
-
What We're Looking For
-
5+ years of information security infrastructure experience, preferably in a regulated industry.
-
Bachelor's degree in a relevant discipline or equivalent professional experience.
-
Experience in Luxembourg financial or technology sector with understanding of local regulatory landscape.
-
Knowledge of DORA operational requirements (resilience testing, third-party management, incident response).
-
Familiarity with EU frameworks including MiCA and EBA/ESMA technical standards.
-
Proficiency with information security frameworks (ISO 27001, SOC2, NIST) and cloud-native environments (AWS).
-
Ability to gather and analyze technical evidence from systems (logs, configuration data, database queries).
-
Strong documentation and SOP creation skills.
-
Experience collaborating with engineers, product managers, and compliance experts.
-
Familiarity with tools: Jira, Confluence, JupiterOne, Okta, AWS, Tines, and integrated GRC platforms is a plus.
-
Desirable certifications: CISSP, CISA, AWS Certified Security, PMP.
-
Proficiency in French is desirable; English proficiency is required.
-
Nice to Have
-
Certifications such as CISSP, CISA, AWS Certified Security, PMP.
-
Experience using Jira, Confluence, JupiterOne, Okta, AWS, Tines, and integrated GRC platforms.
-
Compensation & Benefits
-
Competitive salary, bonuses, and equity.
-
Competitive benefits covering physical and mental healthcare, retirement, family forming, and family support; employee giving match; mobile phone stipend.
-
R&R days to rest and recharge; generous vacation policy; industry-leading parental leave policies; family planning benefit.
-
In-office collaboration is valued; 10+ days a month in the office with flexible scheduling decided by managers and teams.
-
Bi-weekly all-company meetings with Leadership Team.