In sintesi
- Mansioni: Conduci valutazioni di rischio e migliora la sicurezza informatica per proteggere le informazioni.
- Azienda: WFP, l'organizzazione umanitaria più grande al mondo, premiata con il Nobel per la Pace.
- Benefit: Ambiente di lavoro inclusivo, opportunità di sviluppo professionale e pacchetto retributivo competitivo.
- Altre informazioni: Opportunità di crescita in un ambiente dinamico e multiculturale.
- Perché questo lavoro: Fai la differenza nel mondo mentre lavori con tecnologie all'avanguardia in un team appassionato.
- Qualifiche: Esperienza in sicurezza IT e gestione dell'identità, con solide competenze tecniche.
La retribuzione prevista è compresa tra 82800 - 101200 € per anno.
DATE LIMITE DE CANDIDATURE 21 September 2026-23:59-UTC+01:00 heure d’Europe centrale (Rome)
WFP celebrates and embraces diversity.
It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender, gender identity and/or expression, sexual orientation, religion or belief, HIV status or disability.
ABOUT WFP The World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity, for people recovering from conflict, disasters and the impact of climate change.
At WFP, people are at the heart of everything we do and the vision of the future WFP workforce is one of diverse, committed, skilled, and high performing teams, selected on merit, operating in a healthy and inclusive work environment, living WFP’s values (Integrity, Collaboration, Commitment, Humanity, and Inclusion) and working with partners to save and change the lives of those WFP serves.
To learn more about WFP, visit our website: https://www. wfp. org
WHY JOIN WFP?
WFP is a 2020 Nobel Peace Prize Laureate.
WFP offers a highly inclusive, diverse, and multicultural working environment.
WFP invests in the personal & professional development of its employees through a range of training, accreditation, coaching, mentorship, and other programs as well as through internal mobility opportunities.
A career path in WFP provides an exciting opportunity to work across the various country, regional and global offices around the world, and with passionate colleagues who work tirelessly to ensure that effective humanitarian assistance reaches millions of people across the globe.
We offer an attractive compensation package (please refer to the Terms and Conditions section of this vacancy announcement).
- Job Details
- Type of contract: Consultant
- Level: II
- Unit/Division: Technology Division, Information Security
- Duty station: Remote working
- Duration: 11 months
- Background and purpose of the role
- Authorization to Operate and cyber security compliance
- Application security
- Definition, assessment and continuous improvement of authentication, authorization, device security and access management controls.
- Security architecture
- Securing critical applications such as beneficiary management systems
- Azure and Active Directory security
- Strengthen the organization’s identity security and endpoint protection capabilities
- Accountabilities/Responsibilities
- Conduct comprehensive risk assessments and lead the Authorization to Operate (ATO) process for IT systems and services, ensuring that security risks are appropriately identified, evaluated, documented, mitigated and communicated to relevant stakeholders.
- Design, review and oversee the security architecture of new and existing applications, platforms, cloud services and technology initiatives, ensuring that appropriate security controls are embedded by design and aligned with organizational policies, data classification requirements and industry best practices.
- Assess and strengthen identity and access management controls across applications, cloud services and enterprise platforms, including authentication, authorization, privileged access, access lifecycle management and periodic access reviews.
- Define and review endpoint protection requirements and security baselines for corporate endpoints, mobile devices and other managed devices, addressing device compliance, configuration hardening, threat protection, encryption and security monitoring.
- Provide security guidance on the integration of identity and endpoint controls, ensuring that access decisions appropriately consider user identity, device security posture, privilege level and information sensitivity.
- Lead the development, implementation and continuous improvement of cybersecurity procedures, services, methodologies and governance frameworks aimed at protecting organizational information assets, systems and services.
- Research, evaluate and propose innovative technologies, security capabilities and process improvements that strengthen the cybersecurity posture of the organization while demonstrating measurable business value and operational effectiveness.
- Propose and maintain new security standards, procedures and guidelines to help raise the current security maturity level of the organization.
In close collaboration with the Architecture branch, perform regular baseline and hardening reviews of WFP security solutions and technologies.
- Provide expert cybersecurity advisory services and technical guidance to County Offices, Regional Bureaus and HQ divisions to address cybersecurity challenges and maintain compliance with organizational security standards.
• Provide guidance to IT solution owners across the organization to
- Design security controls appropriate to the technology and risk landscape.
- Protect information according to its classification and sensitivity.
- Implement secure software development lifecycle (SSDLC) practices.
- Integrate security requirements into project and solution lifecycles.
- Ensure compliance with cybersecurity standards and requirements.
- Advise stakeholders on cybersecurity risks associated with emerging technologies, including cloud services, artificial intelligence, software-as-a-service (Saa S), digital transformation initiatives and data-driven solutions.
- Maintain a record of decisions taken and assessments performed, in cooperation with other members of the Advisory team.
- Identify and execute improvements to existing processes, through solutions to address recurring problems and enhancements to existing solutions or documentation.
- Act as Subject Matter Expert (SME) for assigned technologies, platforms , business applications and cybersecurity domains.
- Prepare and present high-quality reports, risk assessments, executive briefings, architecture recommendations and management updates tailored to technical and business audiences.
- Mentor, coach and provide technical leadership to junior team members, contributing to knowledge sharing, capability development and continuous improvement within the Advisory team.
- Represent the Cybersecurity Branch in meetings, working groups, steering committees, audits, assessments and enterprise initiatives as required.
- Perform additional duties and responsibilities as required in support of TECI Cybersecurity objectives.
Qualifications and Experience required
• Education
- Degree in the field of Computer Science/Engineering or related STEM disciplines or equivalent working experience.
• Experience
- At least 6 years of relevant work experience.
• Knowledge and Skills
- Solid IT Security skills, with both academic background and professional experience.
- Solid IT SDLC expertise.
- Strong knowledge of Identity and Access Management (IAM) technologies and concepts.
- Experience with endpoint protection technologies and security controls, including endpoint detection and response (EDR), device compliance, configuration hardening and mobile device management (MDM).
- Ability to assess and design identity-centric and device-based security controls, supporting Zero Trust, conditional access and risk-based access management approaches.
- Understanding of IT architecture and design concepts.
- Ability to manage stakeholder relationships, aligning cybersecurity risk strategies with business objectives.
- Understand cybersecurity risk concepts to assess threats, vulnerabilities and mitigation strategies.
- Good project management skills.
- Experience in multinational organizations.
- IT Security and IT Audit certifications.
- Security architecture in the cloud.
- Understanding of AI security concepts and framework.
- Experience in ISO, NIST, HIPAA or PCI compliance processes.
• Languages
- Fluency in oral and written English is mandatory with an intermediate knowledge of another official UN language (Arabic, Chinese, French, Russian and Spanish) or Portuguese (one of WFP’s working languages) is desirable.
- WFP Leadership Framework
WFP Leadership Framework guides to the common standards of behavior that guide HOW we work together to accomplish our mission.
Reasonable Accommodation
WFP is committed to supporting individuals with disabilities by providing reasonable accommodations throughout the recruitment process.
If you require a reasonable accommodation, please contact
WFP celebrates and embraces diversity.
It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender, gender identity and/or expression, sexual orientation, religion or belief, HIV status, physical or mental disability.
#J-18808-Ljbffr
Cybersecurity Advisory Consultant (IAM & Endpoint Protection) datore di lavoro: Logistics Cluster
Il World Food Programme è un datore di lavoro eccezionale, offrendo un ambiente di lavoro collaborativo e innovativo che valorizza le competenze analitiche e tecniche. Con opportunità di crescita professionale e un forte impegno verso la missione umanitaria, i dipendenti possono contribuire a fare la differenza nel mondo, lavorando da remoto in un team diversificato e dinamico. Inoltre, il supporto per lo sviluppo delle competenze in aree come l'IA e il machine learning rende questa posizione particolarmente attraente per chi cerca un impatto significativo nella propria carriera.
Consigli degli esperti StudySmarter🤫
Ecco come pensiamo che potresti ottenere Cybersecurity Advisory Consultant (IAM & Endpoint Protection)
✨Unisciti a comunità di cybersicurezza
Inizia a seguire gruppi e forum online dedicati alla cybersicurezza, come quelli su Reddit o i server Discord. Queste comunità possono aiutarti a rimanere aggiornato sulle ultime tendenze, ma anche a scoprire opportunità lavorative temporanee tramite passaparola.
✨Partecipa a eventi e conferenze
Fai un salto a eventi e conferenze locali sulla cybersicurezza. Non solo avrai la chance di incontrare esperti e potenziali datori di lavoro, ma potresti anche ricevere offerte di lavoro temporaneo sul momento. Porta con te le tue card e sii pronto a fare networking!
✨Offri il tuo aiuto a start-up
Molte start-up hanno bisogno di supporto temporaneo in ambito cybersicurezza ma non sempre hanno il budget per assunzioni a lungo termine. Offrire consulenze o assistenza a progetto può aprire porte che nemmeno pensavi di poter esplorare.
✨Fai domanda direttamente su Logistics Cluster
Esplora le opportunità temporanee su Logistics Cluster e candidati direttamente tramite il nostro sito. Qui puoi trovare ruoli che potrebbero non essere pubblicizzati altrove e avere la chance di mostrare il tuo talento nella cybersicurezza!
Pensiamo che ti servano queste competenze per eccellere come Cybersecurity Advisory Consultant (IAM & Endpoint Protection)
Alcuni consigli per la tua candidatura 🫡
Mostra il tuo lato tecnico:Nel settore della cybersecurity, eccellere nella scrittura di codici e nell'analisi dei sistemi è fondamentale. Assicurati di includere progetti pertinenti o esperienze passate che dimostrano le tue competenze pratiche. Se hai una presenza su GitHub, linkala nel tuo CV!
Certificazioni e corsi sono la chiave!:Inserisci nel tuo CV eventuali certificazioni di cybersecurity come CompTIA Security+, Certified Ethical Hacker (CEH) o altre che possiedi. Questi attestati possono fare la differenza riportando credibilità e competenza al tuo profilo!
Adatta la tua lettera di motivazione:Poiché si tratta di un lavoro temporaneo, mostra nella tua lettera di motivazione la tua disponibilità a imparare rapidamente e contribuire a progetti specifici. Fai emergere l'entusiasmo di affrontare sfide e di migliorare continuamente le tue competenze nel breve tempo che hai a disposizione.
Richiedi un colloquio per approfondire:Non esitare a chiedere un colloquio per discutere del ruolo e come le tue competenze possono aiutare Logistics Cluster. Dimostra il tuo interesse sui progetti della compagnia e preparati a mostrare come puoi contribuire immediatamente, specialmente in un contratto a tempo determinato!
Come prepararti a un colloquio di lavoro presso Logistics Cluster
✨Fai brillare le tue competenze tecniche!
Preparati a domande tecniche profonde che riguardano la cybersecurity. Potrebbero chiederti di spiegare concetti come l'analisi delle vulnerabilità o la gestione degli incidenti. Non dimenticare di menzionare strumenti con cui hai esperienza come Wireshark o Metasploit!
✨Dimostra la tua voglia di imparare
Per un lavoro temporaneo, i datori di lavoro cercano spesso la motivazione e il potenziale di apprendimento. Sii pronto a parlare di come hai affrontato sfide precedenti e di come ti sei aggiornato sulle nuove minacce e tecnologie nel campo della cybersecurity.
✨Prepara il tuo portfolio di progetti
Se hai realizzato progetti di cybersecurity, anche se sono stati solo lavori universitari o personali, preparati a condividerli. Una buona presentazione dei tuoi lavori precedenti può fare la differenza e dimostrare le tue capacità pratiche.
✨Aspettati scenari pratici
Potrebbero chiederti come affronteresti un attacco informatico in tempo reale. Preparati a discutere la tua strategia per rispondere a un simile scenario e non dimenticare di evidenziare l'importanza della comunicazione in situazioni di crisi.