Overview
The Information Security Officer contributes to the implementation, monitoring and assurance of the OPCW information security programme by supporting information security governance, policy, risk assessment, compliance monitoring, access control review, incident response, investigations, resilience and security testing.
Key Responsibilities
- Coordinates all aspects of the OPCW information security programme and implementation of information and ICT security measures.
- Serves as focal point for all information security-related programmes and projects.
- Contributes to the development, review, maintenance and enforcement of policies, procedures, standards and guidelines for secure Information and Communications Technology (ICT) and information handling.
- Monitors, assesses, and reports on control implementation and effectiveness.
- Conducts and reviews security audits of ICT service providers and the supply chain.
- Collaborates with staff across OPCW to provide guidance on confidentiality and information security requirements.
- Contributes to data collection informing senior leadership on the organisation’s information security posture and programme effectiveness.
- Assists the H/CIS in drafting the Director-General’s Annual Reports requiring OCS/CIS input.
- Serves as Acting H/CIS when required.
- Performs security risk, vulnerability and control assessments to identify risks to ICT and data systems, and information assets.
- Recommends or coordinates mitigation measures in close coordination with stakeholders.
- Performs regular assessments of the OPCW infrastructure to identify potential vulnerabilities, prioritise and categorise related risks, and supports the development of implementation plans to remediate or mitigate them.
- Reviews and assesses the security management, monitoring and performance of ICT assets, recommends improvements, and reports identified gaps where required.
- Monitors emerging information security threats, standards, products, techniques, and technologies.
- Advises the H/CIS on relevant and applicable controls and measures.
- Supports security and confidentiality reviews of new or changed applications, platforms and ICT services prior to procurement, approval or deployment.
- Conducts security monitoring, incident response, preliminary enquiries, investigations and digital evidence handling related information to security incidents, confidentiality breaches and potential compromise of classified or sensitive information.
- Performs security monitoring of all networks, to identify critical functions, control weaknesses and potential security events.
- Monitors user access across all networks, ensuring that access to confidential and sensitive information is in line with authorisations granted.
- When tasked, coordinates and leads incident response, digital forensic, and investigation activities relating to potential security breaches.
- Participates in technical security investigations and security event analysis related to ICT and data systems, networks and devices.
- Prepares briefings and presentations on the potential impact, response status and remedial measures related to information security incidents to senior management.
- Collects, documents, and maintains the integrity, custody, and traceability of information and digital evidence related to potential confidentiality breaches or security incidents.
- Reports (potential) violations of the Confidentiality Regime to the Head/CIS.
- Advises on the conduct of related enquiries and investigations.
- Advises and assists staff on the proper reporting of (potential) breaches of confidentiality and/or security incidents.
- Supports information security resilience and provides required input to Business Continuity and Disaster Recovery activities.
- Plans or performs security testing to assess the effectiveness of security controls across ICT systems, data systems and applications.
- Assess the implementation of resilience strategies across ICT and data systems and applications, recommends improvements, report gaps.
- Plans and performs vulnerability and security testing activities, including penetration testing, compliance audits and table-top exercises, on ICT and data systems and applications.
- Supports the identification, review, tracking and follow-up of information security findings.
- Perform other duties as required
Required Experience
- Minimum of 5 years of relevant experience in information security, with significant practical experience in information security operations, incident response, investigations, assurance and control implementation, including:
- Experience with Public Key Infrastructure (PKI), certificate authority management and lifecycle management and related security controls;
- Experience with Microsoft 365 security, cloud security, digital forensics and security monitoring tools;
- Advising on the design and implementation of ICT security solutions;
- Incident monitoring, incident response and security investigations;
- Assisting with and conducting security risk assessments;
- Advising on and testing the security of ICT environments;
- Network security, firewall monitoring and review of related security controls;
- Monitoring and/or supervising operations within secure environments and information processing systems.
Desirable:
- Experience with automated information classification, data-labelling, data loss prevention, intrusion detection/prevention, vulnerability assessment or vulnerability management solutions;
- Experience with chain of custody requirements and technical or procedural measures for maintaining digital evidence integrity;
- Experience contributing to information security aspects of business continuity, disaster recovery or resilience planning;
- Experience analysing security compliance and control effectiveness in large-scale, complex or international organisations;
- Knowledge or experience working with the CWC and Member States is desirable;
- Work experience in the UN Common System.
Qualifications
- Essential: Advanced university degree in information security, cybersecurity, computer science or a related field;
- A first level university degree in a relevant subject in combination with qualifying experience (minimum of 7 years) may be accepted in lieu of the advanced university degree.
- Required Certification:At least one relevant industry certification (e.g., GCIH, GCIA, SSCP, etc.);
- Desirable Certification: Additional relevant industry certifications (e.g., GCFA, GNFA, CCSP, etc.).