This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Sopra Steria Luxembourg operates within a consortium and matrix-driven organization, delivering large-scale, mission-critical IT services to institutional and private-sector clients. Security is a strategic pillar of our delivery model. To strengthen our security governance and operational excellence, we are looking for a Security Chapter Lead – Head of Security Office to provide leadership, structure, and strategic direction across squads and chapters.
Job Responsibility:
Define, maintain, and execute the security strategy and roadmap
Lead and organize the Security Office
Ensure effective use of project management, ticketing, and planning tools to manage security activities
Establish, maintain, and enforce security policies, standards, and procedures
Provide strategic security guidance and risk-based recommendations to senior leadership
Define and maintain security architecture principles
Embed security-by-design and security-by-default principles
Collaborate with architecture and engineering teams to evaluate, select, and implement security tools
Conduct security architecture reviews, risk assessments, and audits
Design and deliver security awareness and training programs
Promote a strong security culture
Provide guidance on secure coding practices, threat mitigation, and security best practices
Work closely with audit, compliance, and legal teams to ensure alignment with requirements
Maintain security documentation, evidence, and artifacts
Oversee security operations, including monitoring, detection, and incident response
Lead the Security Incident Response Team (SIRT)
Develop and maintain incident response plans, playbooks, and procedures
Organize and lead regular tabletop exercises and simulations
Requirements:
Bachelor’s degree in Information Security, Computer Science, or a related field
Relevant certifications such as CISSP, CISM, CISA are a strong asset
Minimum 5 years of proven experience in information security, covering governance, strategy, operations, and compliance
Demonstrated experience leading cross-functional or matrix-based security teams in complex environments
Strong knowledge of security frameworks and standards (e.g. NIST CSF, CIS Controls, OWASP Top 10)
Solid understanding of modern IT architectures, cloud environments, and secure development practices
Strong analytical and problem-solving capabilities with a risk-based and strategic mindset
Excellent communication and stakeholder management skills, with the ability to influence at all organizational levels
Fluency in English (written and spoken) is mandatory
Knowledge of any other European language is considered an advantage
Nice to have:
Knowledge of any other European language
What we offer:
Access to our Sopra Steria training and personal development academy