
Stripe · Luxembourg
WHO WE ARE ABOUT STRIPE Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ...
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the
most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission
is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented
opportunity to put the global economy within everyone's reach while doing the most important work of your career.
Bridge Building S.A. (BBSA) is the Luxembourg regulated entity of Bridge, a Stripe company. We operate as an EMI and future CASP
in one of Europe's most demanding regulatory environments (CSSF, DORA, MiCA).
BBSA is building a local regulated platform powered by a global-first technology model.
In this context, we're looking for an IT GRC Analyst to act as the bridge between strict European regulations and high-velocity
global engineering.
This role is the control and risk right hand of the Bridge Global CISO. While our global teams build the tech, you ensure it is
compliant, resilient, and audit-ready. You'll translate requirements like DORA and MiCA into tangible IT controls, oversee
third-party risks, and maintain the integrity of our governance framework.
This is not a tick-the-box compliance role. It is an operational position for a professional who understands technology well
enough to govern it effectively. You'll have high visibility, owning the frameworks that allow us to scale securely.
IT governance and risk management • Maintain and evolve the IT Risk Register, ensuring risks are identified, assessed, and treated
in line with the company's risk appetite. • Drive the local implementation of the DORA (Digital Operational Resilience Act)
framework, including ICT risk management and incident classification. • Bridge the gap between technical reality and policy by
drafting, reviewing, and updating IT policies and procedures. • Perform periodic control testing to ensure global engineering
practices align with local regulatory requirements. • Act as the primary support to the local Head of IT.
Third-party risk management (TPRM) • Support ICT due diligence and risk assessments of critical vendors and service providers,
while assisting with Developer and Customer Oversight. • Monitor service level agreements and performance metrics of critical
vendors, challenging performance where necessary. • Act as the primary support to the outsourcing manager regarding technical
vendor oversight.
Access governance and control (IAG) • Oversee the identity and access governance strategy, including adherence to Segregation of
Duties, principle of least privilege, and others. • Conduct periodic user access reviews for critical systems.
Regulatory compliance and audit readiness • Act as the primary liaison for internal audit regarding IT topics. • Prepare technical
inputs and evidence for CSSF notifications and regulatory reporting. • Monitor compliance with GDPR and data privacy controls
(e.g., DLP oversight, data residency). • Coordinate business continuity (BCP) and disaster recovery (DR) testing documentation and
reporting.
Incident governance • Oversee the IT incident management process to ensure proper classification, reporting, and root cause
analysis (RCA). • Ensure major incidents are reported to regulators within mandated timeframes, in collaboration with Compliance.
Job Title: Lead Assurance Architect Job Type: Permanent Clearance Requirements: SC & NPPV3 We are the Information Intelligence Group (IIG) of CACI UK, a specialist technical consultancy providing bespoke solutions to solve complex operational problems. Due to growth within our Central Government businesses, we are looking for an experienced Solutions/Assurance Architect to join our growing team. We’re looking for a senior Governance and Assurance Architecture lead to shape and drive high‑assurance design across complex, regulated environments. You’ll lead architectural decisions, embedding governance, risk and compliance into every layer, while defining standards and assuring secure, scalable and auditable outcomes across critical public sector programmes. Due to the industries this role will be associated with, we require the successful candidate to be eligible for security clearance & NPPV3. To qualify for this, you must be a British Citizen only and have lived permanently in the UK for the last 5 years. Responsibilities: * Deliver Technical Design Authority level technical and infrastructure architecture oversight to solution development and implementation. * Provide guidance and assurance of supplier designs and technical implementation plans. * Provide technical assurance of supplier documents. * Identify key technical integration risks and issues along with recommendations for resolution and/or mitigation. * Provide technical input to test phases, connectivity validation activities, and assure technical resolution of issues raised during these activities. * Provide technical input to the spoke Technical Design Authority. * Deliver technical designs and ongoing architectural input to delivery of the environmen. * Provide technical assurance related to designs and workflow of the service gateway and IDENT1 components of the system. * Run monthly system level Security Working Groups. * Provide security architecture, risk assessment, design and delivery assurance public sector projects. Knowledge & Skills Required: * Strong expertise in Governance, Risk, and Compliance (GRC), with the ability to embed controls and assurance processes into architecture and delivery. * Proven experience leading architecture assurance and design governance, including participation in design authorities and technical review boards. * Solid background in solution and/or enterprise architecture, delivering secure, scalable systems aligned to business and regulatory needs. * Experience working within public sector or highly regulated environments, with knowledge of relevant standards (e.g. NCSC guidance, ISO frameworks, GDPR). * Background in consulting or professional services, with the ability to engage clients, shape solutions and influence senior stakeholders. * Strong understanding of secure-by-design principles, including identity, data protection, and risk mitigation. * Working knowledge of AWS and cloud governance models, including guardrails and secure landing zone concepts. * Excellent communication and leadership skills, with the ability to articulate complex assurance concepts to both technical and non-technical audiences. Equal Opportunities: CACI is proud to be an equal opportunities employer. Embracing the diversity of our people, we are on a journey to build a truly inclusive work environment where no one is treated less favourably due to ethnic origin, age, gender, veteran status, religion or belief, sexual orientation, marital status, and disability or health condition, actively working to prevent discrimination. As a Disability Confident employer, we will: * Provide reasonable adjustments in the recruitment process where requested (contact a member of the recruitment team on 020 7602 6000 to discuss individual requirements further). * Offer people with health conditions and disabilities, meeting the minimum criteria for a role, an interview. Our people are unique and we encourage, and support them, to be confident in contributing to our inclusion journey.
ABOUT ARTEFACT Artefact is a global data and AI consultancy that helps organizations create value from data, technology, and artificial intelligence. Artefact Netherlands works with clients on data-driven transformation, analytics, AI, digital marketing, and technology implementation. As our organization continues to grow, information security is becoming increasingly important for our clients, partners, and internal operations. To strengthen our security posture and meet regulatory and customer requirements, Artefact Netherlands is preparing to implement an Information Security Management System, or ISMS, and work towards ISO 27001 certification. ABOUT THE ASSIGNMENT Artefact Netherlands is looking for a motivated graduation intern who will support the implementation of an Information Security Management System and help prepare the organization for ISO 27001 certification. The goal of the internship is to help Artefact Netherlands reduce information security risks, improve governance, and become demonstrably compliant with relevant regulations and customer requirements. A key part of this objective is achieving readiness for ISO 27001 certification. You will work closely with the Artefact project manager and will have access to relevant policies, systems, documentation, and internal stakeholders. In addition, a sounding board from Artefact’s headquarters in France will be available to provide knowledge, feedback, and alignment with the broader Artefact organization. The scope and timelines of the project are clearly defined. Dedicated time for mentorship and guidance will be provided throughout the internship. YOUR RESPONSIBILITIES During the internship, you may work on activities such as: * Performing an ISO 27001 gap analysis against the current situation. * Supporting the definition of the ISMS scope. * Mapping relevant assets, processes, stakeholders, and information flows. * Supporting the setup of a risk assessment methodology. * Creating or improving the information security risk register. * Identifying required ISO 27001 controls and assessing their applicability. * Supporting the development of a draft Statement of Applicability. * Reviewing and improving information security policies and procedures. * Helping define evidence requirements for certification readiness. * Supporting awareness and communication activities within the organization. * Preparing a practical implementation roadmap towards ISO 27001 certification. * Documenting findings and recommendations in a graduation thesis. The exact scope of the assignment will be aligned with the student’s study program, interests, and graduation requirements. YOUR PROFILE We are looking for a proactive and curious student who is interested in the intersection of information security, business processes, risk management, governance, and organizational change. You are currently studying in a relevant field such as Business IT & Management, HBO-ICT, Cyber Security, Information Security, Information Management, Business Information Technology, IT Service Management, Information Science, or Risk Management/IT Governance. You do not need to be an ISO 27001 expert yet, but you are motivated to learn and enjoy working on topics where technology, organization, risk, and compliance come together. To be successful in this role, you bring: * Analytical skills: You can understand complex processes, identify gaps, structure information, and translate findings into practical recommendations. * Affinity with information security: You are interested in cybersecurity, risk management, compliance, governance, or related topics. Knowledge of ISO 27001 is a plus. * A structured way of working: You can organize your work, document findings clearly, and manage your own deliverables. * Strong communication skills: You are comfortable engaging with different stakeholders and translating complex topics into clear language. * Critical thinking and pragmatism: You can assess risks, challenge assumptions, and balance security requirements with business needs. * Availability: You are available for a 5-6 month graduation internship and are able to work in a hybrid setup from our Utrecht office. WHAT YOU WILL LEARN This internship offers the opportunity to gain hands-on experience with a real ISO 27001 implementation trajectory in a professional consultancy environment. During the internship, you will learn how to: * Set up and structure an Information Security Management System. * Understand the practical application of ISO 27001. * Conduct a security gap analysis. * Perform or support information security risk assessments. * Translate security risks into concrete improvement actions. * Work with governance, policies, procedures, controls, and evidence. * Prepare an organization for certification readiness. * Engage with stakeholders across business, technology, and management. * Balance compliance, risk reduction, and practical implementation. * Work in an international organization with support from both local and global stakeholders. * Develop a graduation thesis with direct practical value. You will gain valuable experience in information security governance, risk management, and compliance. These are highly relevant skills for future roles such as information security officer, security consultant, IT risk consultant, privacy/security analyst, business IT consultant, or GRC specialist. WHAT WE OFFER * A competitive internship salary, an NS Business Card to travel to the office, great office lunches, a strong company culture, and other employee benefits. * A clearly scoped graduation assignment with practical business relevance. * Close collaboration with an Artefact project manager. * Dedicated mentorship and guidance throughout the internship. * Access to relevant policies, systems, documentation, and stakeholders. * A sounding board from Artefact headquarters in France. * Exposure to a professional data, AI, and technology consultancy environment. * Dedicated time to work on your graduation thesis (approximately two days per week). * A hybrid working environment from our Utrecht office. * The opportunity to make a visible contribution to Artefact Netherlands’ information security maturity. INTERESTED? Are you looking for a graduation internship in information security, ISO 27001, risk management, and IT governance? We would like to hear from you. Please send your CV and a short motivation explaining why this assignment interests you. POSSIBLE RESEARCH QUESTION A possible graduation research question could be: How can Artefact Netherlands implement an effective and pragmatic Information Security Management System in order to reduce information security risks and become ready for ISO 27001 certification? This research question can be further refined together with the student and the educational institution to ensure it meets graduation requirements.
Location: London, UK Weekly office requirement: Hybrid – 2 days per week Employment type: Permanent Seniority level: Mid-Senior At GWI we're always looking for extraordinary people who thrive on making an extraordinary impact. Right now we're looking for an Information Security GRC Specialist to play a key role in our Legal team in London. If that's you, and making a difference gets you out of bed in the morning, keep reading. It could be the start of something, well, extraordinary. SOUNDS GREAT, WHAT WILL I BE DOING? 🤔 As our Information Security GRC Specialist you'll play a pivotal role in shaping the future of security compliance at GWI. Reporting into our General Counsel and working closely with our Information Security, Product, and Technology teams, you'll own our compliance posture across security frameworks, vendor risk, and client-facing security requirements — while building a security-conscious culture across the business. A few things you'll be responsible for: 👉 Own and maintain GWI's ISO 27001 certification and compliance across relevant security frameworks, keeping our posture sharp as the threat landscape evolves. 👉 Develop, implement, and maintain information security policies and procedures aligned with industry best practices. 👉 Lead vendor risk management and client security assessments — including responding to client security questionnaires and onboarding requirements. 👉 Build and maintain GWI's security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta. 👉 Drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture. It's also fun; shaking things up is what working for GWI is all about. You'll need to be flexible, comfortable with continuous change, and working in a high-tempo environment. WHAT DO I NEED TO BRING WITH ME? 🧳 You'll need to be able to demonstrate the core skills this role requires. You don't have to tick all the boxes right away; the important thing is that you're willing to learn. Here's what the team will be looking for in you: 👉 In-depth, practical experience obtaining and maintaining ISO 27001 certification, with solid knowledge of frameworks such as NIST — typically 3–5 years in an information security compliance role, though other experience levels will be considered. 👉 Proven ability to develop and maintain security policies and procedures that align with industry best practice. 👉 Experience conducting vendor security assessments and managing client security onboarding requirements, balancing risk against commercial objectives. 👉 Hands-on experience building or maintaining a security trust portal; familiarity with tools such as Drata or Vanta is a plus. 👉 Knowledge of SaaS and AI environments, with experience implementing and managing cloud security best practices. 👉 Strong communication skills — able to translate complex GRC topics into clear internal guidance and keep the wider business informed and engaged on security matters. Equally important is attitude. We want people who think big (to make an impact), ask why (to find a better way), and show respect (to everyone, at every level, all the time). Those are our values, and they're a big part of what we're looking for in you. WHAT WE OFFER 🧘 At GWI, you’ll find meaningful work, visible impact, and a culture that empowers you to do your best. Our package includes: * Time to recharge – 25 days’ annual leave, plus office closures over the holidays. * Health & wellbeing – Health cash plan, enhanced family benefits, carer days, and mental health support. * Financial benefits – Competitive salary, 4% pension matching, and recognition programs that celebrate success. * Flexibility & balance – Flexitime, early Friday finishes, hybrid and remote options, plus a “work from home” budget. * Career growth – Accredited learning, leadership development, and global career mobility. * Community & impact – DE&I initiatives, volunteering opportunities, donation matching, and payroll giving. Put all that together and GWI is the friendliest, most fulfilling place any of us has ever worked. DIVERSITY, EQUITY & INCLUSION 🫶 Diversity is fundamental to who we are—both as a data company and as a workplace. Our data reflects global realities, and so must our teams. We strive to ensure our workforce is as diverse and inclusive as the insights we provide to our clients. As a Disability Confident employer, we welcome applications from disabled candidates and are committed to providing all necessary adjustments during the hiring process. We also actively encourage applications from underrepresented and marginalized communities. At GWI, you will find a place where you can contribute meaningfully, grow professionally, and belong fully. #li-hybrid #LI-NIKOSSS1