ORGANIZATIONAL CONTEXT
Under the supervision and delegated authority of the Head of the ICT Security Unit, Information Services Department, the Cybersecurity Operations Manager leads the hands-on operational management of ITU’s cybersecurity infrastructure, security services, and security projects. The incumbent is a technically competent manager who combines deep practical expertise in cybersecurity technologies with the ability to manage contractors, vendors, and external security service providers.The role is accountable for the day-to-day operation of security infrastructure and the 24/7 Security Operations Center (SOC), managed through an external MSSP. The Cybersecurity Operations Manager also serves as Program/Project Manager for major security initiatives including acquisition and implementation of new security products and services, SOC modernization, and security architecture improvements. The incumbent provides operational oversight of emerging technology security risks, including AI/ML, Large Language Models (LLMs), and agentic AI systems—and ensures alignment of security operations with ITU’s digital transformation strategy and applicable international cybersecurity frameworks.
DUTIES AND RESPONSIBILITIES
1. Manage the full lifecycle of complex cybersecurity projects and security infrastructure, from feasibility studies and architecture design to procurement, implementation, testing and commissioning of security technologies, including Security Information and Event Management (SIEM) platforms, Intrusion Prevention Systems/Intrusion Detection Systems (IPS/IDS), Next Generation Firewalls (NGFW), Secure Web Gateways and Endpoint Protection/EDR platforms. Oversee network security solutions across LAN/WAN, physical, virtual, on-premises, hybrid and multi-cloud environments, ensuring integration across Unix, Windows and Linux operating environments at ITU Headquarters, Field Offices, events and conferences. Prepare technical documentation, security assessments and bid evaluations, and support the Head of ICT Security with contract administration, including calls for bids, Service Level Agreement (SLA) definition, vendor performance monitoring and cost-effectiveness reporting.
2. Serve as ITU’s primary technical interface with the external Managed Security Service Provider (MSSP) operating the 24/7 SOC and threat detection. Lead SLA validation and manage detection gap resolution. Direct SIEM use-case development and tuning, ensuring context-aware correlation rules for mission-critical servers, applications and users. Drive SOC modernization with automation pipelines and extended detection coverage, AI/ML-based threat detection, behavioral analytics, next-generation endpoint and identity protection. Manage ITU’s internal incident response workflow (impact assessment, escalation, containment, eradication, post-incident review) in close coordination with the MSSP. Develop and stress-test incident response playbooks, disaster recovery procedures, and cyber-drill scenarios to ensure organizational resilience.
3. Operate and maintain security infrastructure and cloud security while driving cost-effective improvements. Deliver hands-on oversight of security stack: NGFW, IPS/IDS, Endpoint Protection Platform/Endpoint Detection and Response (EPP/EDR), Identity and Access Management (IAM), email security, storage, and information management systems. Continuously monitor events and directly troubleshoot complex incidents across network, systems, and applications. Manage multi-cloud security across Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS) by enforcing security architecture, governance, and provider-specific controls. Oversee the identity lifecycle including passwordless authentication, Multi-Factor Authentication (MFA), biometrics, andPrivileged Access Management (PAM).
4. Lead organization-wide cybersecurity awareness and training at Headquarters and in Field Offices. Update content for evolving threats, including social engineering, phishing, ransomware, and Artificial Intelligence (AI)-enabled attacks. Design and execute phishing simulations, then analyse results to target remediation efforts. Coordinate tabletops and cyber drills. Track effectiveness via metrics and feedback and report outcomes to senior management.
CORE COMPETENCIES
Applying Expertise; Effective Communication; Learning and Knowledge Sharing; Organizational Commitment; Results-Focused, and; Teamwork and Collaboration.
TECHNICAL COMPETENCIES
- Strong knowledge of NGFW, IPS/IDS, segmentation, zero-trust, and SIEM correlation rules (Splunk/Sentinel/QRadar). Familiarity with EDR across endpoints, IAM, MFA, PAM, Zero Trust, and email security (DMARC/DKIM/SPF).
- Capacity to lead incident response, forensics, and vulnerability management. Familiarity with threat intelligence operationalization, SOC/MSSP SLAs, NIST CSF, and ISO 27001.
- Strong knowledge of multi-cloud security (AWS/Azure/GCP), AI/ML security (training data, model inference, adversarial defense), and LLM risks (prompt injection, data leakage). Familiarity with agentic AI security, encryption, and DLP.
- Ability to deliver cybersecurity projects (procurement, bids). Strong knowledge of vendor/SLA/contract performance management.
QUALIFICATIONS REQUIRED
Education:
Advanced university degree in Computer Science, Information Security, Cybersecurity, Information Systems or a related field OR education from a reputed college of advanced education with a diploma of equivalent standard to that of an advanced university degree in one of the fields above.For internal candidates, a first university degree in one of the fields above in combination with ten years of qualifying experience may be accepted in lieu of an advanced university degree for promotion or rotation purposes.
Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager (CISM) are strongly preferred.GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), Certified Ethical Hacker (CEH), GIAC Security Essentials (GSEC), and Certified Information Systems Auditor (CISA), are desired.
Certified Cloud Security Professional (CCSP), Amazon Web Services (AWS) Certified Security – Specialty, Microsoft
Certified: Azure Security Engineer Associate, and Google Professional Cloud Security Engineer, are desired.
Experience:
At least seven years of progressively responsible experience in cybersecurity operations and security management, including at least three at the international level. A Doctorate in a related field can be considered as a substitute for three years of working experience.
Experience in SIEM, IPS/IDS, NGFW, EPP/EDR, network security; SOC/MSSP oversight with SLA management.
Experience in incident response, digital forensics, large-scale ICT security (DR, business continuity).
Experience with multi-cloud security (SaaS/IaaS/PaaS) and security assessments of AI/ML and LLM systems.
Experience in vulnerability management, threat intelligence, and cybersecurity project delivery (procurement, implementation, vendor management).
Languages:
Knowledge of one of the six official languages of the Union (Arabic, Chinese, English, French, Russian, Spanish) at advanced level and knowledge of a second official language at intermediate level. Knowledge of a third official language would be an advantage. (Under the provisions of Resolution No. 626 of the Council, a relaxation of the language requirements may be authorized in the case of candidates from developing countries: when candidates from such countries possess a thorough knowledge of one of the official languages of the Union, their applications may be taken into consideration.)
BENEFITS AND ENTITLEMENTS
Salary:
Total annual salary consists of a net annual salary (net of taxes and before medical insurance and pension funddeductions) in US dollars and a post adjustment (PA) (cost of living allowance). The PA is variable and subject to change without notice in accordance with the rates set within the UN Common System for salaries and allowances.
Annual salary from $ 86,027 + post adjustment $ 72,004
Other allowances and benefits subject to specific terms of appointment, please refer to: What We Offer