Opening...
Opening...
Information Security Officer (P-3) role at, focusing on information security governance, risk assessments, and policy compliance. International recruitment indicated by P-3 grade. Workplace type not explicitly stated.
Last checked: 2 days ago
Closing date: TBD
Country: Global
Duty station: Detailoffre.aspx
Contract type: Not specified
Grade: Not specified
Open to: Internationals
Ad
Ad
Category : Office of Confidentiality and Security - (0102)/Information Security Officer - (F0812)
Contract Type : Fixed-term Professional
Job Details :
The Office of Confidentiality and Security (OCS) sets the framework, provides the guidelines, institutes the measures and implements the necessary provisions to guarantee and enforce the fulfilment of the stringent OPCW confidentiality regime; operational security of the Secretariat's assets; the security of all its electronic systems; the confidentiality of all classified material and its safeguarding. Under the direct supervision of the Head, Confidentiality and Information Security (H/CIS), the Information Security Officer contributes to the implementation, monitoring and assurance of the OPCW information security programme by supporting information security governance, policy, risk assessment, compliance monitoring, access control review, incident response, investigations, resilience and security testing. Main Responsibilities: 1. OPCW Information Security Governance and Programme Support Coordinates all aspects of the OPCW information security programme and implementation of information and ICT security measures to ensure the preservation of the confidentiality, integrity and availability of OPCW’s information; Serves as focal point for all information security-related programmes and projects, advising the H/CIS, and contributes to information security governance, policy, compliance and management reporting; Contributes to the development, review, maintenance and enforcement of policies, procedures, standards and guidelines for secure Information and Communications Technology (ICT) and information handling; Monitors, assesses, and reports on control implementation and effectiveness for the maintenance of compliance with organisational policies, confidentiality requirements and relevant international information security standards; Conducts and reviews security audits of ICT service providers and the supply chain; Collaborates with staff across OPCW to provide guidance on confidentiality and information security requirements; Contributes to data collection informing senior leadership on the organisation’s information security posture and programme effectiveness. Assists the H/CIS in drafting the Director-General’s Annual Reports requiring OCS/CIS input; Serves as Acting H/CIS when required. 2. Risk, Vulnerability and Control Assessments Performs security risk, vulnerability and control assessments to identify risks to ICT and data systems, and information assets. Recommends appropriate mitigation measures; Identifies, analyses and evaluates risks to a/m systems. Recommends or coordinates mitigation measures in close coordination with stakeholders; Performs regular assessments of the OPCW infrastructure to identify potential vulnerabilities, prioritise and categorise related risks, and supports the development of implementation plans to remediate or mitigate them; Reviews and assesses the security management, monitoring and performance of ICT assets, recommends improvements, and reports identified gaps where required;
Monitors emerging information security threats, standards, products, techniques, and technologies. Advises the H/CIS on relevant and applicable controls and measures; Supports security and confidentiality reviews of new or changed applications, platforms and ICT services prior to procurement, approval or deployment. 3. Security Monitoring, Incident Response and Investigations Conducts security monitoring, incident response, preliminary enquiries, investigations and digital evidence handling related information to security incidents, confidentiality breaches and potential compromise of classified or sensitive information; Performs security monitoring of all networks, to identify critical functions, control weaknesses and potential security events; Monitors user access across all networks, ensuring that access to confidential and sensitive information is in line with authorisations granted; When tasked, coordinates and leads incident response, digital forensic, and investigation activities relating to potential security breaches, working closely with business units and stakeholders to assess and address risks to the integrity and confidentiality of sensitive or classified information; Participates in technical security investigations and security event analysis related to ICT and data systems, networks and devices; Prepares briefings and presentations on the potential impact, response status and remedial measures related to information security incidents to senior management; Collects, documents, and maintains the integrity, custody, and traceability of information and digital evidence related to potential confidentiality breaches or security incidents, supporting preliminary enquiries, incident response, digital forensics, and investigation activities; Reports (potential) violations of the Confidentiality Regime to the Head/CIS. Advises on the conduct of related enquiries and investigations; Advises and assists staff on the proper reporting of (potential) breaches of confidentiality and/or security incidents. Where necessary, ensure such breaches or incidents are highlighted to the H/CIS. 4. Information Security Resilience and Security Testing Supports information security resilience and provides required input to Business Continuity and Disaster Recovery activities. Plans or performs security testing to assess the effectiveness of security controls across ICT systems, data systems and applications; Assess the implementation of resilience strategies across ICT and data systems and applications, recommends improvements, report gaps; Plans and performs vulnerability and security testing activities, including penetration testing, compliance audits and table-top exercises, on ICT and data systems and applications; Supports the identification, review, tracking and follow-up of information security findings. 5. Perform other duties as required
Ad
Ad