Cybersecurity Advisory Consultant
Salva questo lavoro e mantieni la tua ricerca organizzata
Crea un account gratuito per salvare lavori, creare avvisi e tornare a questa inserzione dalla tua dashboard.
Job Title
CYBERSECURITY ADVISORY CONSULTANT (AI Security & Secure by Design)
Vuole saperne di più su questo lavoro? Scorra verso il basso per scoprire quali competenze, esperienze e titoli di studio sono necessari.
Type of Contract
CST Level II
Unit/Division
Technology Division, Information Security
Duty Station
Remote work
Duration
11 months
Background and Purpose of the Assignment
Under the general supervision of the Chief Information Security Officer and supervision of the Head of Cybersecurity Advisory Services, the incumbent will conduct consulting activities to the business, including, but not limited to:
- Authorization to Operate and cyber security compliance
- Application security
- Network security
- Secure-by-design principles across the technology lifecycle from solution conception through deployment and operation.
- Securing critical applications such as beneficiary management systems
- Support the secure adoption of artificial intelligence and emerging technologies
- Identity and access management
Accountabilities / Responsibilities
- Conduct comprehensive risk assessments and lead the Authorization to Operate (ATO) process for IT systems and services, ensuring that security risks are appropriately identified, evaluated, documented, mitigated and communicated to relevant stakeholders.
- Design, review and oversee the security architecture of new and existing applications, platforms, cloud services and technology initiatives, ensuring that appropriate security controls are embedded by design and aligned with organizational policies, data classification requirements and industry best practices.
- Develop and maintain security requirements for artificial intelligence solutions, covering the secure handling of data, models, prompts, interfaces and supporting infrastructure throughout the solution lifecycle.
- Conduct security assessments of AI use cases and solutions, identifying risks related to data exposure, unauthorized access, model manipulation, insecure integrations, third‐party dependencies and unintended system behaviour, and recommend proportionate mitigation measures.
- Embed secure‐by‐design principles into solution development and procurement processes, defining reusable security requirements, review checkpoints and design guidance.
- Lead the development, implementation and continuous improvement of cybersecurity procedures, services, methodologies and governance frameworks aimed at protecting organizational information assets, systems and services.
- Research, evaluate and propose innovative technologies, security capabilities and process improvements that strengthen the cybersecurity posture of the organization while demonstrating measurable business value and operational effectiveness.
- Propose and maintain new security standards, procedures and guidelines to help raise the current security maturity level of the organization.
- In close collaboration with the Architecture branch, perform regular baseline and hardening reviews of WFP security solutions and technologies.
- Provide expert cybersecurity advisory services and technical guidance to County Offices, Regional Bureaus and HQ divisions to address cybersecurity challenges and maintain compliance with organizational security standards.
- Provide guidance to IT solution owners across the organization to:
- Design security controls appropriate to the technology and risk landscape.
- Protect information according to its classification and sensitivity
- Implement secure software development lifecycle (SSDLC) practices.
- Integrate security requirements into project and solution lifecycles
- Ensure compliance with cybersecurity standards and requirements.
- Advise stakeholders on cybersecurity risks associated with emerging technologies, including cloud services, artificial intelligence, software‐as‐a‐service (SaaS), digital transformation initiatives and data‐driven solutions.
- Maintain a record of decisions taken and assessments performed, in cooperation with other members of the Advisory team.
- Identify and execute improvements to existing processes, through solutions to address recurring problems and enhancements to existing solutions or documentation.
- Act a