Cybersecurity Advisory Consultant (IAM & Endpoint Protection)

Cybersecurity Advisory Consultant (IAM & Endpoint Protection)

Pavia Temporaneo 82800 - 101200 € / anno (stimato) Smart working possibile
L

In sintesi

  • Mansioni: Conduci valutazioni di rischio e migliora la sicurezza informatica per proteggere le informazioni.
  • Azienda: WFP, l'organizzazione umanitaria più grande al mondo, premiata con il Nobel per la Pace.
  • Benefit: Ambiente di lavoro inclusivo, opportunità di sviluppo professionale e pacchetto retributivo competitivo.
  • Altre informazioni: Lavoro remoto con opportunità di crescita in un team diversificato e impegnato.
  • Perché questo lavoro: Fai la differenza nel mondo della sicurezza informatica e contribuisci a salvare vite.
  • Qualifiche: Esperienza in sicurezza IT e gestione dell'identità, con solide competenze tecniche.

La retribuzione prevista è compresa tra 82800 - 101200 € per anno.

DATE LIMITE DE CANDIDATURE 21 September 2026-23:59-UTC+01:00 heure d’Europe centrale (Rome)

WFP celebrates and embraces diversity.

It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender, gender identity and/or expression, sexual orientation, religion or belief, HIV status or disability.

ABOUT WFP The World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity, for people recovering from conflict, disasters and the impact of climate change.

At WFP, people are at the heart of everything we do and the vision of the future WFP workforce is one of diverse, committed, skilled, and high performing teams, selected on merit, operating in a healthy and inclusive work environment, living WFP’s values (Integrity, Collaboration, Commitment, Humanity, and Inclusion) and working with partners to save and change the lives of those WFP serves.

To learn more about WFP, visit our website: https://www. wfp. org

WHY JOIN WFP?

WFP is a 2020 Nobel Peace Prize Laureate.

WFP offers a highly inclusive, diverse, and multicultural working environment.

WFP invests in the personal & professional development of its employees through a range of training, accreditation, coaching, mentorship, and other programs as well as through internal mobility opportunities.

A career path in WFP provides an exciting opportunity to work across the various country, regional and global offices around the world, and with passionate colleagues who work tirelessly to ensure that effective humanitarian assistance reaches millions of people across the globe.

We offer an attractive compensation package (please refer to the Terms and Conditions section of this vacancy announcement).

  • Job Details
  • Type of contract: Consultant
  • Level: II
  • Unit/Division: Technology Division, Information Security
  • Duty station: Remote working
  • Duration: 11 months
  • Background and purpose of the role
  • Authorization to Operate and cyber security compliance
  • Application security
  • Definition, assessment and continuous improvement of authentication, authorization, device security and access management controls.
  • Security architecture
  • Securing critical applications such as beneficiary management systems
  • Azure and Active Directory security
  • Strengthen the organization’s identity security and endpoint protection capabilities
  • Accountabilities/Responsibilities
  • Conduct comprehensive risk assessments and lead the Authorization to Operate (ATO) process for IT systems and services, ensuring that security risks are appropriately identified, evaluated, documented, mitigated and communicated to relevant stakeholders.
  • Design, review and oversee the security architecture of new and existing applications, platforms, cloud services and technology initiatives, ensuring that appropriate security controls are embedded by design and aligned with organizational policies, data classification requirements and industry best practices.
  • Assess and strengthen identity and access management controls across applications, cloud services and enterprise platforms, including authentication, authorization, privileged access, access lifecycle management and periodic access reviews.
  • Define and review endpoint protection requirements and security baselines for corporate endpoints, mobile devices and other managed devices, addressing device compliance, configuration hardening, threat protection, encryption and security monitoring.
  • Provide security guidance on the integration of identity and endpoint controls, ensuring that access decisions appropriately consider user identity, device security posture, privilege level and information sensitivity.
  • Lead the development, implementation and continuous improvement of cybersecurity procedures, services, methodologies and governance frameworks aimed at protecting organizational information assets, systems and services.
  • Research, evaluate and propose innovative technologies, security capabilities and process improvements that strengthen the cybersecurity posture of the organization while demonstrating measurable business value and operational effectiveness.
  • Propose and maintain new security standards, procedures and guidelines to help raise the current security maturity level of the organization.

In close collaboration with the Architecture branch, perform regular baseline and hardening reviews of WFP security solutions and technologies.

  • Provide expert cybersecurity advisory services and technical guidance to County Offices, Regional Bureaus and HQ divisions to address cybersecurity challenges and maintain compliance with organizational security standards.

• Provide guidance to IT solution owners across the organization to

  • Design security controls appropriate to the technology and risk landscape.
  • Protect information according to its classification and sensitivity.
  • Implement secure software development lifecycle (SSDLC) practices.
  • Integrate security requirements into project and solution lifecycles.
  • Ensure compliance with cybersecurity standards and requirements.
  • Advise stakeholders on cybersecurity risks associated with emerging technologies, including cloud services, artificial intelligence, software-as-a-service (Saa S), digital transformation initiatives and data-driven solutions.
  • Maintain a record of decisions taken and assessments performed, in cooperation with other members of the Advisory team.
  • Identify and execute improvements to existing processes, through solutions to address recurring problems and enhancements to existing solutions or documentation.
  • Act as Subject Matter Expert (SME) for assigned technologies, platforms , business applications and cybersecurity domains.
  • Prepare and present high-quality reports, risk assessments, executive briefings, architecture recommendations and management updates tailored to technical and business audiences.
  • Mentor, coach and provide technical leadership to junior team members, contributing to knowledge sharing, capability development and continuous improvement within the Advisory team.
  • Represent the Cybersecurity Branch in meetings, working groups, steering committees, audits, assessments and enterprise initiatives as required.
  • Perform additional duties and responsibilities as required in support of TECI Cybersecurity objectives.

Qualifications and Experience required

• Education

  • Degree in the field of Computer Science/Engineering or related STEM disciplines or equivalent working experience.

• Experience

  • At least 6 years of relevant work experience.

• Knowledge and Skills

  • Solid IT Security skills, with both academic background and professional experience.
  • Solid IT SDLC expertise.
  • Strong knowledge of Identity and Access Management (IAM) technologies and concepts.
  • Experience with endpoint protection technologies and security controls, including endpoint detection and response (EDR), device compliance, configuration hardening and mobile device management (MDM).
  • Ability to assess and design identity-centric and device-based security controls, supporting Zero Trust, conditional access and risk-based access management approaches.
  • Understanding of IT architecture and design concepts.
  • Ability to manage stakeholder relationships, aligning cybersecurity risk strategies with business objectives.
  • Understand cybersecurity risk concepts to assess threats, vulnerabilities and mitigation strategies.
  • Good project management skills.
  • Experience in multinational organizations.
  • IT Security and IT Audit certifications.
  • Security architecture in the cloud.
  • Understanding of AI security concepts and framework.
  • Experience in ISO, NIST, HIPAA or PCI compliance processes.

• Languages

  • Fluency in oral and written English is mandatory with an intermediate knowledge of another official UN language (Arabic, Chinese, French, Russian and Spanish) or Portuguese (one of WFP’s working languages) is desirable.
  • WFP Leadership Framework

WFP Leadership Framework guides to the common standards of behavior that guide HOW we work together to accomplish our mission.

Reasonable Accommodation

WFP is committed to supporting individuals with disabilities by providing reasonable accommodations throughout the recruitment process.

If you require a reasonable accommodation, please contact

WFP celebrates and embraces diversity.

It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender, gender identity and/or expression, sexual orientation, religion or belief, HIV status, physical or mental disability.

#J-18808-Ljbffr

Cybersecurity Advisory Consultant (IAM & Endpoint Protection) datore di lavoro: Logistics Cluster

Il World Food Programme è un datore di lavoro eccezionale, offrendo un ambiente di lavoro collaborativo e innovativo che valorizza le competenze analitiche e tecniche. Con opportunità di crescita professionale e un forte impegno verso la missione umanitaria, i dipendenti possono contribuire a fare la differenza nel mondo, lavorando da remoto in un team diversificato e dinamico. Inoltre, il supporto per lo sviluppo delle competenze in aree come l'IA e il machine learning rende questa posizione particolarmente attraente per chi cerca un impatto significativo nella propria carriera.

L

Dettagli di contatto:

Team di recruiting di Logistics Cluster

Consigli degli esperti StudySmarter🤫

Ecco come pensiamo che potresti ottenere Cybersecurity Advisory Consultant (IAM & Endpoint Protection)

Collegati ai Meetup di Cybersecurity

Un ottimo modo per entrare nel mondo della cybersecurity è partecipare a eventi e meetup del settore. Cerca conferenze locali e hackathon dove puoi fare networking e incontrare potenziali datori di lavoro come Logistics Cluster. Questo può essere un modo fantastico per dimostrare le tue competenze e farti notare.

Prendi Parte a Progetti Open Source

Il mondo della cybersecurity è pieno di progetti open-source dove puoi mostrare le tue abilità. Inizia a contribuire a progetti su piattaforme come GitHub, cercando iniziative che ti interessano. È un ottimo modo per costruire un portfolio visibile e essere incluso in comunità che possono aiutarti nel tuo percorso!

Utilizza Career Center Universitari

Se sei ancora legato all'università, non dimenticare di sfruttare i career center. Molte aziende cercano studenti per ruoli temporanei o stagistici e, sicuramente, troverai opportunità legate a società come Logistics Cluster attraverso questi canali. Non esitare a chiedere consiglio e assistenza!

Candidati Diretto su Siti Specializzati

Quando cerchi ruoli temporanei in cybersecurity, applicare direttamente sui siti web delle aziende può essere molto efficace. Visita il sito di Logistics Cluster e controlla le loro offerte di lavoro. Potresti trovarti di fronte a opportunità che non vengono pubblicizzate altrove!

Pensiamo che ti servano queste competenze per eccellere come Cybersecurity Advisory Consultant (IAM & Endpoint Protection)

Cybersecurity
Identity and Access Management (IAM)
Endpoint Protection
Risk Assessment
Security Architecture
Cloud Security
Endpoint Detection and Response (EDR)

Alcuni consigli per la tua candidatura 🫡

Crea un CV orientato alla cybersecurity:Nel tuo CV, mettiti in evidenza con le competenze specifiche del settore, come la gestione delle vulnerabilità, la crittografia, e l'analisi dei rischi. Assicurati di includere qualsiasi certificazione pertinente, come la CompTIA Security+ o altre, che possano far brillare la tua candidatura.

Mostra la tua esperienza pratica:Se hai fatto dei progetti legati alla cybersecurity, come partecipare a CTF (Capture The Flag) o a workshop, includili nel tuo portfolio. Queste esperienze pratiche possono realmente fare la differenza e dimostrare il tuo impegno nel campo.

Scrivi una lettera di motivazione convincente:Dato che questo è un ruolo temporaneo, evidenzia nella tua lettera di motivazione perché sei interessato a questo progetto specifico con Logistics Cluster. Spiega come questa esperienza può aiutarti a crescere nel campo della cybersecurity e quali nuove competenze speri di acquisire.

Preparati a discutere di trending topics:Fai un po' di ricerca sugli ultimi trend in cybersecurity. Essere aggiornato sulle minacce attuali e le best practices può impressionare il team di Logistics Cluster. Potresti anche voler includere qualche citazione interessante o articolo che hai trovato utile nel tuo CV o nella lettera di motivazione.

Come prepararti a un colloquio di lavoro presso Logistics Cluster

Impara i tool di cybersecurity

Nel campo della cybersecurity, è cruciale avere familiarità con strumenti come Wireshark, Metasploit o Nessus. Durante il colloquio, potresti essere messo alla prova su come utilizzare questi strumenti per risolvere situazioni reali: preparati a discutere dei tuoi progetti passati dove li hai utilizzati!

Parla delle tue esperienze pratiche

Essendo un lavoro temporaneo, i datori di lavoro nella cybersecurity cercano qualcuno che possa subito mettersi al lavoro. Racconta di progetti o stage precedenti in cui hai affrontato vulnerabilità o attacchi: mostra come le tue esperienze ti hanno preparato per il ruolo che vuoi.

Preparati a domande tecniche specifiche

Aspettati domande approfondite sulla tua conoscenza di protocolli di sicurezza, firewall e crittografia. Potrebbero anche chiederti di risolvere problemi di sicurezza in tempo reale o di analizzare scenari di attacco: smanettaci un po' prima del colloquio!

Porta un portfolio di progetti

Anche se è un'opportunità temporanea, è importante avere un portfolio che mostri i tuoi risultati. Includi case study, progetti di sicurezza che hai fatto e, se hai blog o articoli scritti, portali con te. Questo dimostra il tuo impegno e il tuo interesse per il settore!