Overview

Information Security & IT Operations Officer Jobs in Luxembourg, Luxembourg at LUXUAV

Title: Information Security & IT Operations Officer

Company: LUXUAV

Location: Luxembourg, Luxembourg

LUXUAV is an innovative technology company headquartered in Luxembourg, shaping next generation airspace security for defence, civil, firefighting and police missions. We build a fully integrated Unmanned Aerial Vehicles (UAVs) ecosystem that connects mission systems across ground, air, and stratosphere into one coherent governmental and commercial architecture.

The integrity of what we ship depends on the integrity of how we build it. This is primarily an Information Security role with operational responsibility for the parts of IT closest to security: network and endpoint. You own the cybersecurity strategy, policies, and ISMS, and you keep the corporate network and user devices secure and running day-to-day. Hands-on by design.

Key Responsibilities

Information Security (primary focus):

  • Strategy and policy – Own LUXUAV's cybersecurity strategy and policy stack (acceptable use, access control, data handling, incident response, third-party risk).
  • ISMS – Design, operate, and improve the Information Security Management System aligned to ISO/IEC 27001.
  • Cyber risk management – Maintain the risk register. Run risk assessments across assets, processes, and suppliers. Drive treatment decisions with leadership.
  • Executive reporting – Report cyber risk, incidents, and posture to senior management in clear, actionable terms.
  • Compliance – Ensure compliance with European cybersecurity laws applicable to the organisation (i.e. GDPR, NIS2) and customer-imposed security requirements.
  • External authorities and audits – Manage relationships with relevant Luxembourg and EU cybersecurity authorities and lead customer security questionnaires and audits.
  • Identity and access – Operate SSO, MFA, joiner-mover-leaver workflows, periodic access reviews, and privileged access for sensitive systems.
  • Incident response – Own the incident response plan and lead execution when incidents occur. Run tabletop exercises and post-incident reviews.
  • Security culture – Run the security awareness programme (onboarding, ongoing campaigns, role-based training).

Network & Endpoint Security:

  • Secure network design – Design and operate corporate and lab networks: segmentation by trust zone, VLAN architecture, enterprise wireless, guest isolation. Keep architecture documented and current.
  • Firewall and remote access – Own firewall configuration and change management. Operate VPN or zero-trust access with device posture, identity, and MFA on every connection.
  • Endpoint security baseline – Define and enforce hardened baselines across Windows, macOS, and Linux: EDR, disk encryption, host firewall, removable-media controls.
  • Endpoint lifecycle – Own corporate devices end-to-end: secure provisioning, MDM/UEM enrolment, patching, and secure disposal. Maintain an accurate asset inventory.
  • Vulnerability and patch management – Run scanning, prioritisation, and remediation across endpoints and network infrastructure with measurable SLAs.

IT Support:

  • User support – Be the face of IT. Define and resolve user issues across hardware, OS, productivity tooling, and remote access.
  • Onboarding and offboarding – Provision new starters end-to-end (account, device, software, access). Revoke cleanly on exit.
  • Software and licensing – Maintain the approved software catalogue, request and approval workflow, and license tracking.
  • Productivity stack – Administer the corporate stack (mail, calendar, chat, file storage) with security configuration: sharing controls, anti-phishing, and conditional access.

Experience & Skills

Required:

  • BS/MS in Computer Science, Information Security, IT, or equivalent practical experience.
  • 5+ years in information security, with explicit ownership of cybersecurity policy, ISMS, or risk programmes.
  • Policy and ISMS – Hands-on experience designing or operating an ISMS aligned to ISO/IEC 27001.
  • One recognised certification: CISSP, CISM, ISO 27001 Lead Implementer/Auditor, or equivalent.
  • Network security – Strong grasp of segmentation, firewall management, and remote access (VPN or zero-trust).
  • Endpoint security – Production experience with MDM/UEM, EDR, and disk encryption across mixed Windows/macOS/Linux fleets.
  • Identity and access – Production experience with SSO, MFA, and access lifecycle management.
  • Incident response – Have actually led incidents, not just written the plan.
  • User-facing maturity – Patient, clear communication; able to translate between technical and non-technical audiences.
  • English – Upper-intermediate or above.
  • Free criminal record.

Preferred:

  • Experience in a defence, aerospace, dual-use, or critical-infrastructure environment.
  • Familiarity with Luxembourg's regulatory landscape (CNPD, ILR, national CERTs).
  • Exposure to NIS2 implementation or export-control-adjacent obligations.
  • Familiarity with the EU Cyber Resilience Act and ability to support product-engineering teams on its implementation.
  • Hands-on experience with tooling in one or more relevant categories (specific products illustrative; our stack is still being decided): MDM (e.g. Intune, Jamf), SSO/IAM (e.g. Keycloak, Entra ID), network security (e.g. pfSense, Fortinet), zero-trust access (e.g. Tailscale, Cloudflare Access), SIEM (e.g. Wazuh, Sentinel), vulnerability scanning (e.g. Trivy, Nessus).
  • Experience administering Microsoft 365 or Google Workspace with conditional access and DLP.
  • Additional certifications: CISA, GIAC, CCSP, or comparable.
  • National from a NATO member country or one of the following NATO Indo-Pacific partners: Australia, Japan, South Korea, New Zealand or Ukraine.

If you meet the outlined requirements and feel this role is a strong fit for your experience, we warmly encourage you to apply. We look forward to learning more about you and your qualifications. *Please note that only shortlisted candidates will be contacted.

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.