In sintesi
- Mansioni: Conduci attività di consulenza sulla sicurezza informatica e supporta l'adozione sicura dell'intelligenza artificiale.
- Azienda: Organizzazione umanitaria globale con un forte impegno per la sicurezza informatica.
- Benefit: Lavoro remoto, pacchetto retributivo competitivo e opportunità di crescita professionale.
- Altre informazioni: Ambiente dinamico con opportunità di apprendimento e sviluppo continuo.
- Perché questo lavoro: Fai la differenza nella sicurezza informatica e nell'adozione di tecnologie emergenti.
- Qualifiche: Esperienza in sicurezza IT e conoscenze di AI sono fondamentali.
Job Title
CYBERSECURITY ADVISORY CONSULTANT (AI Security & Secure by Design)
Type of Contract
CST Level II
Unit/Division
Technology Division, Information Security
Duty Station
Remote work
Duration
11 months
Background and Purpose of the Assignment
Under the general supervision of the Chief Information Security Officer and supervision of the Head of Cybersecurity Advisory Services, the incumbent will conduct consulting activities to the business, including, but not limited to:
- Authorization to Operate and cyber security compliance
- Application security
- Network security
- Secure-by-design principles across the technology lifecycle from solution conception through deployment and operation.
- Securing critical applications such as beneficiary management systems
- Support the secure adoption of artificial intelligence and emerging technologies
- Identity and access management
Accountabilities / Responsibilities
- Conduct comprehensive risk assessments and lead the Authorization to Operate (ATO) process for IT systems and services, ensuring that security risks are appropriately identified, evaluated, documented, mitigated and communicated to relevant stakeholders.
- Design, review and oversee the security architecture of new and existing applications, platforms, cloud services and technology initiatives, ensuring that appropriate security controls are embedded by design and aligned with organizational policies, data classification requirements and industry best practices.
- Develop and maintain security requirements for artificial intelligence solutions, covering the secure handling of data, models, prompts, interfaces and supporting infrastructure throughout the solution lifecycle.
- Conduct security assessments of AI use cases and solutions, identifying risks related to data exposure, unauthorized access, model manipulation, insecure integrations, third‑party dependencies and unintended system behaviour, and recommend proportionate mitigation measures.
- Embed secure‑by‑design principles into solution development and procurement processes, defining reusable security requirements, review checkpoints and design guidance.
- Lead the development, implementation and continuous improvement of cybersecurity procedures, services, methodologies and governance frameworks aimed at protecting organizational information assets, systems and services.
- Research, evaluate and propose innovative technologies, security capabilities and process improvements that strengthen the cybersecurity posture of the organization while demonstrating measurable business value and operational effectiveness.
- Propose and maintain new security standards, procedures and guidelines to help raise the current security maturity level of the organization.
- In close collaboration with the Architecture branch, perform regular baseline and hardening reviews of WFP security solutions and technologies.
- Provide expert cybersecurity advisory services and technical guidance to County Offices, Regional Bureaus and HQ divisions to address cybersecurity challenges and maintain compliance with organizational security standards.
- Provide guidance to IT solution owners across the organization to:
- Design security controls appropriate to the technology and risk landscape.
- Protect information according to its classification and sensitivity
- Implement secure software development lifecycle (SSDLC) practices.
- Integrate security requirements into project and solution lifecycles
- Ensure compliance with cybersecurity standards and requirements.
- Advise stakeholders on cybersecurity risks associated with emerging technologies, including cloud services, artificial intelligence, software‑as‑a‑service (SaaS), digital transformation initiatives and data‑driven solutions.
- Maintain a record of decisions taken and assessments performed, in cooperation with other members of the Advisory team.
- Identify and execute improvements to existing processes, through solutions to address recurring problems and enhancements to existing solutions or documentation.
- Act as Subject Matter Expert (SME) for assigned technologies, platforms, business applications and cybersecurity domains.
- Prepare and present high-quality reports, risk assessments, executive briefings, architecture recommendations and management updates tailored to technical and business audiences.
- Mentor, coach and provide technical leadership to junior team members, contributing to knowledge sharing, capability development and continuous improvement within the Advisory team.
- Represent the Cybersecurity Branch in meetings, working groups, steering committees, audits, assessments and enterprise initiatives as required.
- Perform additional duties and responsibilities as required in support of TECI Cybersecurity objectives.
Qualifications/Experience required
- Education: Degree in the field of Computer Science/Engineering or related STEM disciplines or equivalent working experience.
- Experience: At least 6 years of relevant work experience.
Knowledge & Skills
- Solid IT Security skills, with both academic background and professional experience
- Solid IT SDLC expertise.
- Strong understanding of AI security concepts, threats and risk management practices.
- Ability to define and implement secure‑by‑design principles, security requirements and architectural controls throughout the solution lifecycle.
- Experience conducting security reviews of AI‑enabled solutions, including data protection, model security, third‑party AI services and integration security.
- Understanding of IT architecture and design concepts.
- Ability to manage stakeholder relationships, aligning cybersecurity risk strategies with business objectives.
- Understand cybersecurity risk concepts to assess threats, vulnerabilities and mitigation strategies.
- Good project management skills.
- Experience in multinational organizations
- IT Security and IT Audit certifications
- Security architecture in the cloud.
- Understanding of AI security concepts and framework
- Experience in ISO, NIST, HIPAA or PCI compliance processes.
Languages
Fluency in oral and written English is mandatory with an intermediate knowledge of another official UN language (Arabic, Chinese, French, Russian and Spanish) or Portuguese (one of WFP’s working languages) is desirable.
WFP LEADERSHIP FRAMEWORK
WFP Leadership Framework guides to the common standards of behavior that guide HOW we work together to accomplish our mission.
REASONABLE ACCOMMODATION
WFP is committed to supporting individuals with disabilities by providing reasonable accommodations throughout the recruitment process. If you require a reasonable accommodation, please contact:
WFP celebrates and embraces diversity. It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender, gender identity and/or expression, sexual orientation, religion or belief, HIV status or disability.WFP is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity for people recovering from conflict, disasters and the impact of climate change.We offer an attractive compensation package (please refer to the Terms and Conditions section of this vacancy announcement).Our greatest strength is the people working around the world providing access to nutritious food and promoting lasting solutions to those we serve.We are the world’s largest humanitarian organization, saving lives in emergencies, and using food assistance to build a pathway to peace, stability and prosperity for people recovering from conflict, disasters, and the impact of climate change. Read more about WFP’s history here, and WFP’s mission here. #J-18808-Ljbffr
Cybersecurity Advisory Consultant (AI Security & Secure by Design) datore di lavoro: Logistics Cluster
Il World Food Programme è un datore di lavoro eccezionale, offrendo un ambiente di lavoro collaborativo e innovativo che valorizza le competenze analitiche e tecniche. Con opportunità di crescita professionale e un forte impegno verso la missione umanitaria, i dipendenti possono contribuire a fare la differenza nel mondo, lavorando da remoto in un team diversificato e dinamico. Inoltre, il supporto per lo sviluppo delle competenze in aree come l'IA e il machine learning rende questa posizione particolarmente attraente per chi cerca un impatto significativo nella propria carriera.
Consigli degli esperti StudySmarter🤫
Ecco come pensiamo che potresti ottenere Cybersecurity Advisory Consultant (AI Security & Secure by Design)
✨Unisciti a comunità di cybersicurezza
Inizia a seguire gruppi e forum online dedicati alla cybersicurezza, come quelli su Reddit o i server Discord. Queste comunità possono aiutarti a rimanere aggiornato sulle ultime tendenze, ma anche a scoprire opportunità lavorative temporanee tramite passaparola.
✨Partecipa a eventi e conferenze
Fai un salto a eventi e conferenze locali sulla cybersicurezza. Non solo avrai la chance di incontrare esperti e potenziali datori di lavoro, ma potresti anche ricevere offerte di lavoro temporaneo sul momento. Porta con te le tue card e sii pronto a fare networking!
✨Offri il tuo aiuto a start-up
Molte start-up hanno bisogno di supporto temporaneo in ambito cybersicurezza ma non sempre hanno il budget per assunzioni a lungo termine. Offrire consulenze o assistenza a progetto può aprire porte che nemmeno pensavi di poter esplorare.
✨Fai domanda direttamente su Logistics Cluster
Esplora le opportunità temporanee su Logistics Cluster e candidati direttamente tramite il nostro sito. Qui puoi trovare ruoli che potrebbero non essere pubblicizzati altrove e avere la chance di mostrare il tuo talento nella cybersicurezza!
Pensiamo che ti servano queste competenze per eccellere come Cybersecurity Advisory Consultant (AI Security & Secure by Design)
Alcuni consigli per la tua candidatura 🫡
Mostra il tuo lato tecnico:Nel settore della cybersecurity, eccellere nella scrittura di codici e nell'analisi dei sistemi è fondamentale. Assicurati di includere progetti pertinenti o esperienze passate che dimostrano le tue competenze pratiche. Se hai una presenza su GitHub, linkala nel tuo CV!
Certificazioni e corsi sono la chiave!:Inserisci nel tuo CV eventuali certificazioni di cybersecurity come CompTIA Security+, Certified Ethical Hacker (CEH) o altre che possiedi. Questi attestati possono fare la differenza riportando credibilità e competenza al tuo profilo!
Adatta la tua lettera di motivazione:Poiché si tratta di un lavoro temporaneo, mostra nella tua lettera di motivazione la tua disponibilità a imparare rapidamente e contribuire a progetti specifici. Fai emergere l'entusiasmo di affrontare sfide e di migliorare continuamente le tue competenze nel breve tempo che hai a disposizione.
Richiedi un colloquio per approfondire:Non esitare a chiedere un colloquio per discutere del ruolo e come le tue competenze possono aiutare Logistics Cluster. Dimostra il tuo interesse sui progetti della compagnia e preparati a mostrare come puoi contribuire immediatamente, specialmente in un contratto a tempo determinato!
Come prepararti a un colloquio di lavoro presso Logistics Cluster
✨Fai brillare le tue competenze tecniche!
Preparati a domande tecniche profonde che riguardano la cybersecurity. Potrebbero chiederti di spiegare concetti come l'analisi delle vulnerabilità o la gestione degli incidenti. Non dimenticare di menzionare strumenti con cui hai esperienza come Wireshark o Metasploit!
✨Dimostra la tua voglia di imparare
Per un lavoro temporaneo, i datori di lavoro cercano spesso la motivazione e il potenziale di apprendimento. Sii pronto a parlare di come hai affrontato sfide precedenti e di come ti sei aggiornato sulle nuove minacce e tecnologie nel campo della cybersecurity.
✨Prepara il tuo portfolio di progetti
Se hai realizzato progetti di cybersecurity, anche se sono stati solo lavori universitari o personali, preparati a condividerli. Una buona presentazione dei tuoi lavori precedenti può fare la differenza e dimostrare le tue capacità pratiche.
✨Aspettati scenari pratici
Potrebbero chiederti come affronteresti un attacco informatico in tempo reale. Preparati a discutere la tua strategia per rispondere a un simile scenario e non dimenticare di evidenziare l'importanza della comunicazione in situazioni di crisi.