Senior Information Security Officer (P)
IOM - UN MigrationAbout the role
Job Identification (Reference Number): 16079
Position Title: Senior Information Security Officer
Duty Station City: Valencia
Duty Station Country: Spain
Grade: P-4
Contract Type: Fixed-term (1 year with possibility of extension)
Recruiting Type: Professional
Vacancy Type: Vacancy Notice
Initial duration: 1 year with possibility of extension
Closing date: 11 September 2025
Introduction:
Established in 1951, IOM is a Related Organization of the United Nations, and as the leading UN agency in the field of migration, works closely with governmental, intergovernmental and non-governmental partners. IOM is dedicated to promoting humane and orderly migration for the benefit of all. It does so by providing services and advice to governments and migrants.
IOM is committed to ensuring a workplace where all employees can thrive professionally, while working towards harnessing the full potential of migration. Read more about IOM's workplace culture at IOM workplace culture | International Organization for Migration
Applications are welcome from first- and second-tier candidates, particularly qualified female candidates as well as applications from the non-represented member countries of IOM. For all IOM vacancies, applications from qualified and eligible first-tier candidates are considered before those of qualified and eligible second-tier candidates in the selection process.
For the purpose of this call, the following are considered first-tier candidates:
- Internal candidates
- External female candidates:
- Candidates from the following non-represented member states:
Antigua and Barbuda, Bahamas, Barbados, Comoros, Congo (the), Cook Islands, Dominica, Federated States of Micronesia, Grenada, Guinea-Bissau, Holy See, Iceland, Israel, Kiribati, Lao People's Democratic Republic, Madagascar, Marshall Islands, Namibia, Nauru, Palau, Saint Kitts and Nevis, Saint Lucia, Samoa, Sao Tome and Principe, Seychelles, Solomon Islands, Suriname, Tonga, Tuvalu, Vanuatu
Second tier candidates include:
All external candidates, except candidates from nonrepresented member states of IOM and female candidates.
Context:
Under the direct supervision of Chief Information Officer (CIO) and in close collaboration with relevant Information and Communications Technology (ICT) Units at Headquarters (HQ) and worldwide ICT Teams, the successful candidate will be responsible for leading the definition and implementation of the Global Cybersecurity Strategy, in the area of Information Security and Risk Management including application security, data security, threat, vulnerability, risk, and compliance management.
- Lead and manage the cybersecurity Blue Team functions, processes and team members.
- Ensure that the information security and risk management functions, processes, procedures, training sessions, and playbooks are developed, implemented, auditable and repeatable, as well as aligned with business and strategic organizational objectives.
- Improve the maturity level of data security to the defined higher level, and evaluate and advise on progress, risk monitoring and performance,ensuring the development of Key Performance Indicators (KPI)/metrics.
- Provide advice and subject matter expertise for the review, consistent implementation and compliance-monitoring of IOM-wide information security policies, operating procedures standards, and guidelines.
- Lead the response to security audit requests and provide advisory services to ensure the implementation of recommendations (including FISMA/NIST 800-53 controls, ISO 27001).
- Define and coordinate the implementation of the Global Cybersecurity Strategy, including the formulation of awareness-related activities and delivery of global workshops / webinars.
- Create security policies and procedures based on ISO27001, NIST 800-53 and Computer Information System (CIS) controls.
- Conduct complex threat, vulnerability, risk and compliance assessments, audit information security controls, simulate cyber-attacks and data breaches, and provide authoritative advice on cybersecurity governance, risk and compliance practices as well as change management.
- Lead and manage a variety of cyber security projects, including the management of resources.
- Carry out complex and/or sensitive investigations and audits.
- Provide authoritative advice to queries/requests/tickets related to data security, risks, rotation, access and other information security matter
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s