Information Security Advisory Specialist

2 giorni fa


Roma, Italia World Food Programme A tempo pieno

DEADLINE FOR APPLICATIONS

5 July 2025-23:59-GMT+01:00 Central European Time (Rome)

ABOUT WFP

The World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity, for people recovering from conflict, disasters and the impact of climate change.

At WFP, people are at the heart of everything we do and the vision of the future WFP workforce is one of diverse, committed, skilled, and high performing teams, selected on merit, operating in a healthy and inclusive work environment, living WFP's values (Integrity, Collaboration, Commitment, Humanity, and Inclusion) and working with partners to save and change the lives of those WFP serves.

To learn more about WFP, visit our website:
WHY JOIN WFP?- WFP is a 2020 Nobel Peace Prize Laureate.- WFP offers a highly inclusive, diverse, and multicultural working environment.- WFP invests in the personal & professional development of its employees through a range of training, accreditation, coaching, mentorship, and other programs as well as through internal mobility opportunities.- A career path in WFP provides an exciting opportunity to work across the various country, regional and global offices around the world, and with passionate colleagues who work tirelessly to ensure that effective humanitarian assistance reaches millions of people across the globe.- We offer an attractive compensation package (please refer to the Terms and Conditions section of this vacancy announcement).

JOB TITLE: INFORMATION SECURITY ADVISORY SPECIALIST

TYPE OF CONTRACT: CST2

UNIT/DIVISION: TECI

DUTY STATION (City, Country): REMOTE WORK

DURATION: 11 months

BACKGROUND AND PURPOSE OF THE ASSIGNMENT:
Under the general supervision of the Chief Information Security Officer and supervision of the Head of Cybersecurity Advisory Services, the incumbent will conduct consulting activities to the business, including, but not limited to:

- Authorization to Operate and security compliance
- Application security
- Network security
- Security architecture
- Third Party Risk Management
- Securing beneficiary management systems
- Azure and Active Directory security
- Identity and access management

ACCOUNTABILITIES/RESPONSIBILITIES:

- Conduct comprehensive risk assessments and manage the Authorization to Operate (ATO) process for IT systems, ensuring that all security controls are effectively implemented and maintained to meet organizational and regulatory requirements.
- Lead the design, implementation and maintenance of cybersecurity procedures and services, aimed at protecting IT systems and sensitive data.
- Produce proposals around technologies to improve the cybersecurity posture of the organization, with sound research to ensure these produce value.
- Propose and maintain new security standards, procedures and guidelines to help raise the current security maturity level of the organization. In close collaboration with the Architecture branch, perform regular baseline and hardening reviews of WFP security solutions and technologies.
- Provide expert support and advisory services to County Offices and Regional Bureaus to address cybersecurity challenges and maintain compliance with organizational security standards.
- Conduct third-party risk assessments, ensuring cybersecurity compliance and effective risk management. Provide guidance to IT solution owners across the organization to:

- Properly design the needed measures to ensure the cybersecurity of the solution.
- Protect data as appropriate for their classification.
- Understand and propose secure software development lifecycle (SDLC) principles.
- Ensure the compliance with Enterprise Architecture and security guidelines.
- Advise the organization on other risk and data classification concerns.
- Consistently find opportunities to innovate, extend and enhance service delivery wherever possible.
- Maintain a record of decisions taken and assessments performed, in cooperation with other members of the Advisory team.
- Identify and execute improvements to existing processes, through solutions to address recurring problems and enhancements to existing solutions or documentation.
- Produce high quality reports.
- Provide leadership and advice to more junior colleagues.
- Manage cybersecurity related projects.
- Additional duties as requested.

DELIVERABLES AT THE END OF THE CONTRACT:

- Comprehensive reports detailing the risk assessments conducted for IT systems, including identified risks, mitigation measures, and residual risks.
- Complete documentation for the Authorization to Operate (ATO) process, including security controls, compliance status, and any necessary remediation actions.
- Well-researched proposals for technologies and strategies to improve the organization's cybersecurity posture.
- Updated security standards, procedures, and guidelines to raise the corporate security maturity level, including baseline and hard



  • Provincia di Roma, Lazio, Italia Novomatic Italia spa A tempo pieno

    Hai mai sentito parlare delle Gaming Technologies e dell’entusiasmante mondo che c’è dietro? Vorresti conoscere uno dei più grandi player internazionali, che ha scritto pagine nella storia dell’innovazione nel campo del gioco? Sei nel posto giusto! NOVOMATIC da oltre 40 anni, in 100 paesi in tutto il mondo, è leader indiscusso del mercato dei...

  • Information Security

    2 settimane fa


    Roma, Italia Open Fiber A tempo pieno

    Ti piacerebbe lavorare in un ambiente di lavoro stimolante e in costante crescita? Entra a far parte del nostro Team e costruisci con noi l’Autostrada Digitale del Futuro. All’interno della funzione Funzione Security, QHSE, Energy Management & Sustainability presidierai i temi di Information Security in generale e Cyber Security e Resilience in...

  • Security Specialist

    1 settimana fa


    Roma, Italia Intersistemi Italia S.p.A. A tempo pieno

    **Intersistemi Italia S.p.A**. azienda operante nel mercato ICT ricerca specialisti di security con le seguenti caratteristiche: - Anzianità > anni 5 nel ruolo - Ottima conoscenza apparati di sicurezza(Fortinet, Arbor, McAfee ESM, etc.) - Ottima esperienza in ambito SOC e/o CIRT/CERT - Ottima conoscenza appliance di sicurezza(firewall, antivirus, SIEM, DLP,...


  • Roma, Italia World Food Programme A tempo pieno

    DEADLINE FOR APPLICATIONS 5 July 2025-23:59-GMT+01:00 Central European Time (Rome) ABOUT WFP The World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity, for people recovering from conflict, disasters and the impact of climate...


  • Roma, Italia DXC Technology A tempo pieno

    **Essential Job Functions**: - Assist in security assessments, audits, and vulnerability scans, providing detailed reports and recommendations. - Monitor security events and incidents, escalating and responding to threats as necessary. - Support policy implementation, ensuring that security policies are understood and followed. - Collaborate with the...


  • Roma, Italia Evaluating srl A tempo pieno

    Siamo alla ricerca di un ICT Security Specialist da inserire su un nostro progetto presso un importante cliente su Roma con presenza full on site. Il profilo ideale assicura le implementazioni della politica del sistema informativo, propone e implementa gli aggiornamenti di sicurezza necessari, consiglia, supporta ,informa e fornisce formazione e...

  • Data Protection

    2 settimane fa


    roma, Italia We Do Advisory A tempo pieno

    Siamo We.Do Advisory, una boutique di Management Advisory del gruppo DGS. Ci occupiamo di Consulenza Strategica, ICT Strategy e Governance, Data Protection & Cybersecurity.Siamo nati nel 2019 e conserviamo le caratteristiche in un luogo disteso ma professionale, chi lavora con noi trova ascolto, autonomia e un team con cui crescere. Un’azienda che cerca...


  • Roma, Italia agap2 Italia A tempo pieno

    AGAP2 è un gruppo europeo di consulenza ingegneristica e operativa facente parte del Gruppo MoOngy.Presente in 14 paesi europei con oltre 7.500 dipendenti, abbiamo aperto, da sette anni, la prima sede italiana a Milano e, vista la continua crescita, stiamo rafforzando e ampliando il nostro team con persone che condividano gli stessi valori della nostra...


  • roma, Italia agap2 Italia A tempo pieno

    AGAP2 è un gruppo europeo di consulenza ingegneristica e operativa facente parte del Gruppo MoOngy.Presente in 14 paesi europei con oltre 7.500 dipendenti, abbiamo aperto, da sette anni, la prima sede italiana a Milano e, vista la continua crescita, stiamo rafforzando e ampliando il nostro team con persone che condividano gli stessi valori della nostra...


  • Roma, Italia Vantea SMART A tempo pieno

    Vantea SMART è una holding IT quotata su Euronext Growth Milan (EGM). In ambito Information Technology offriamo servizi, prodotti proprietari e consulenza, principalmente nel settore della Cybersecurity. Da 30 anni siamo al fianco del cliente su tutto il ciclo della Digital Transformation. Siamo alla ricerca di un Cyber Security Specialist da inserire...