ABOUT WFP
The World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity, for people recovering from conflict, disasters and the impact of climate change.
At WFP, people are at the heart of everything we do and the vision of the future WFP workforce is one of diverse, committed, skilled, and high performing teams, selected on merit, operating in a healthy and inclusive work environment, living WFP's values (Integrity, Collaboration, Commitment, Humanity, and Inclusion) and working with partners to save and change the lives of those WFP serves.
To learn more about WFP, visit our website: https://www.wfp.org and follow us on social media to keep up with our latest news: YouTube, LinkedIn, Instagram, Facebook, Twitter, TikTok.
WHY JOIN WFP?
- WFP is a 2020 Nobel Peace Prize Laureate.
- WFP offers a highly inclusive, diverse, and multicultural working environment.
WFP invests in the personal & professional development of its employees through a range of training, accreditation, coaching, mentorship, and other programs as well as through internal mobility opportunities.
- A career path in WFP provides an exciting opportunity to work across the various country, regional and global offices around the world, and with passionate colleagues who work tirelessly to ensure that effective humanitarian assistance reaches millions of people across the globe.
- We offer an attractive compensation package (please refer to the Terms and Conditions section of this vacancy announcement).
Unit/Division: Technology Division, Information Security
Duration: 11 months
Background and purpose of the role:
Under the general supervision of the Chief Information Security Officer and supervision of the Head of Cybersecurity Advisory Services, the incumbent will conduct consulting activities to the business, including, but not limited to:
• Authorization to Operate and cyber security compliance
• Application security
• Definition, assessment and continuous improvement of authentication, authorization, device security and access management controls.
• Security architecture
• Securing critical applications such as beneficiary management systems
• Azure and Active Directory security
• Strengthen the organization's identity security and endpoint protection capabilities
Accountabilities/Responsibilities:
2. Design, review and oversee the security architecture of new and existing applications, platforms, cloud services and technology initiatives, ensuring that appropriate security controls are embedded by design and aligned with organizational policies, data classification requirements and industry best practices.
3. Assess and strengthen identity and access management controls across applications, cloud services and enterprise platforms, including authentication, authorization, privileged access, access lifecycle management and periodic access reviews.
4. Define and review endpoint protection requirements and security baselines for corporate endpoints, mobile devices and other managed devices, addressing device compliance, configuration hardening, threat protection, encryption and security monitoring.
5. Provide security guidance on the integration of identity and endpoint controls, ensuring that access decisions appropriately consider user identity, device security posture, privilege level and information sensitivity.
6. Lead the development, implementation and continuous improvement of cybersecurity procedures, services, methodologies and governance frameworks aimed at protecting organizational information assets, systems and services.
7. Research, evaluate and propose innovative technologies, security capabilities and process improvements that strengthen the cybersecurity posture of the organization while demonstrating measurable business value and operational effectiveness.
8. Propose and maintain new security standards, procedures and guidelines to help raise the current security maturity level of the organization. In close collaboration with the Architecture branch, perform regular baseline and hardening reviews of WFP security solutions and technologies.
Design security controls appropriate to the technology and risk landscape.
Protect information according to its classification and sensitivity
Implement secure software development lifecycle (SSDLC) practices.
Integrate security requirements into project and solution lifecycles
Ensure compliance with cybersecurity standards and requirements.
11. Advise stakeholders on cybersecurity risks associated with emerging technologies, including cloud services, artificial intelligence, software-as-a-service (SaaS), digital transformation initiatives and data-driven solutions.
12. Maintain a record of decisions taken and assessments performed, in cooperation with other members of the Advisory team.
13. Identify and execute improvements to existing processes, through solutions to address recurring problems and enhancements to existing solutions or documentation.
14. Act as Subject Matter Expert (SME) for assigned technologies, platforms , business applications and cybersecurity domains.
15. Prepare and present high-quality reports, risk assessments, executive briefings, architecture recommendations and management updates tailored to technical and business audiences
16. Mentor, coach and provide technical leadership to junior team members, contributing to knowledge sharing, capability development and continuous improvement within the Advisory team
17. Represent the Cybersecurity Branch in meetings, working groups, steering committees, audits, assessments and enterprise initiatives as required.
18. Perform additional duties and responsibilities as required in support of TECI Cybersecurity objectives.
Qualifications and Experience required:
- Solid IT SDLC expertise.
- Strong knowledge of Identity and Access Management (IAM) technologies and concepts.
- Experience with endpoint protection technologies and security controls, including endpoint detection and response (EDR), device compliance, configuration hardening and mobile device management (MDM).
- Ability to assess and design identity-centric and device-based security controls, supporting Zero Trust, conditional access and risk-based access management approaches.
- Understanding of IT architecture and design concepts.
- Ability to manage stakeholder relationships, aligning cybersecurity risk strategies with business objectives.
- Understand cybersecurity risk concepts to assess threats, vulnerabilities and mitigation strategies.
- Good project management skills.
- Experience in multinational organizations
- IT Security and IT Audit certifications
- Security architecture in the cloud.
- Understanding of AI security concepts and framework
- Experience in ISO, NIST, HIPAA or PCI compliance processes.
WFP LEADERSHIP FRAMEWORK
WFP Leadership Framework guides to the common standards of behavior that guide HOW we work together to accomplish our mission.
REASONABLE ACCOMMODATION
NO FEE DISCLAIMER
The United Nations does not charge any application, processing, training, interviewing, testing or other fee in connection with the application or recruitment process. Should you receive a solicitation for the payment of a fee, please disregard it. Furthermore, please note that emblems, logos, names and addresses are easily copied and reproduced. Therefore, you are advised to apply particular care when submitting personal information on the web.
REMINDERS BEFORE YOU SUBMIT YOUR APPLICATION
- All applications must be submitted exclusively through our online recruiting system. We do not consider CVs or applications sent by email, LinkedIn, or any other channel.
- We strongly recommend that your Workday profile is accurate and complete, and that all sections are filled in, including your employment history, academic qualifications, language skills, and UN grade (if applicable). Once your profile is completed, please apply, and submit your application.
- If you experience technical issues while submitting your application, you may contact us at global.hrerecruitment@wfp.org. Please note that this email is only for technical issues with an application - unsolicited applications or documents sent to this inbox will not receive a reply.
- At the application stage, the only required documents are your CV and Cover Letter. Additional documents (passport, certificates, recommendation letters, etc.) may be requested later in the process.
- Only shortlisted candidates will be contacted and invited to proceed to the next stage of the recruitment process.
No appointment under any kind of contract will be offered to members of the UN Advisory Committee on Administrative and Budgetary Questions (ACABQ), International Civil Service Commission (ICSC), FAO Finance Committee, WFP External Auditor, WFP Audit Committee, Joint Inspection Unit (JIU) and other similar bodies within the United Nations system with oversight responsibilities over WFP, both during their service and within three years of ceasing that service.