Overview
The Information Security Lead will develop an effective execution strategy and programme to improve MSF’s overall information security posture and governance of information security in the movement.
Key Responsibilities
- Develop, implement, and maintain MSF’s information security strategy and roadmap
- Define and maintain information security policies, standards, and procedures
- Advise senior management on information security risks and mitigation options
- Support definition of mutualised approaches for selected information security capabilities
- Contribute to organisational risk management and governance processes
- Identify, assess, and prioritise information security risks
- Conduct and support information security risk assessments
- Propose feasible mitigation measures
- Support the documentation and acceptance of residual risks
- Lead responses to movement-wide information security incidents
- Support field missions and headquarters during high‑pressure or sensitive incidents
- Coordinate with relevant functions
- Ensure post‑incident reviews and follow‑up actions are completed
- Advise on matters such as infrastructure, network, cloud, and endpoint security
- Advise on security matters such as identity & access management and remote working
- Ensure security requirements are integrated into system design, procurement, and third‑party arrangements
- Advise on data classification, minimisation, retention, and secure sharing
- Work closely with data protection, legal, safeguarding, and other stakeholders
- Promote digital practices that minimise risks of harm to individuals and communities
- Develop and deliver information security awareness and training programs
- Build information security capacity among staff
- Translate complex security concepts into clear, practical guidance
- Collaborate closely with all relevant functions
- Chair the ISM Information Security Working Group sessions
- Coordinate with external service providers and security experts
- Represent MSF in relevant information security and humanitarian forums
- Monitor emerging threats relevant to humanitarian and medical organisations
Required Experience
- Minimum 7 years’ experience in information security or security risk management.
- Experience developing security policies, standards, and enterprise solutions in complex, decentralised, and international environments.
- Knowledge of business continuity and disaster recovery.
Qualifications
- Minimum Bachelor's degree in a technical discipline (Computer Science, Cybersecurity, Information Technology, etc.) or equivalent
- Certification as a security professional, e.g. Certified Information Systems Security Professional (CISSP) or Certified Information Security Auditor (CISA)