Jobs and Careers
IN

Product/Platform Security Engineer (Zero Trust) - ITDIOCS (Contractual)

International Monetary Fund
Washington, United Statesfull_timeVerifiedPosted 13 Feb 2025

About the role

Work for the IMF. Work for the World.

 

Background 

The Information Technology Department (ITD) at the IMF is more than just a support function; it is a critical catalyst for change. We champion the seamless integration of cutting-edge technology solutions, ensuring the IMF's mission is propelled by innovation and efficiency.  

Our commitment is to:  

  • Maintain and elevate the performance of pivotal IT systems and infrastructure.  

  • Fortify and mature the IMF’s cybersecurity posture, safeguarding the integrity and resilience of global financial and economic systems.  

  • Align IT initiatives with the IMF's strategic objectives, maximizing the impact of technology on global economic policies.  

  • Deliver unparalleled value, optimizing the blend of quality, cost-effectiveness, and stakeholder satisfaction in every project.  

  • Empower the IMF's business technology strategy, ensuring it aligns with both current needs and future visions.  

As we expand our capabilities, we seek experts in cybersecurity ready to dive deep into the complexities of capabilities that enable global finance and economics. Your expertise is vital in securing the future of international economic stability. 

Job Summary 

The Information Technology Department (ITD) Infrastructure and Operations (IO) division of the International Monetary Fund (IMF) is seeking to fill a Product/Platform Security Engineer (Zero Trust). 

  

Under the general supervision of the Section Chief- Cybersecurity Platforms, this role will be responsible for the solution design, engineering, implementation, operations, and maintenance of the IMF’s zero trust capabilities as part of the IMF’s Zero Trust architecture, including Secure Web Gateway, CASB, ZTNA, and DLP. The role will also provide support to broader network security solutions and will play an essential role in ensuring that the IMF’s network is secured from both internal and external threat landscape.  

Minimum Qualifications 

Advanced degree in information security, computer science, engineering, mathematics or related field of study or equivalent, plus a minimum of 4 years of relevant professional experience; or a bachelor’s degree in computer science or a related field of study plus a minimum of 10 years of relevant professional experience, is required. 

  •  Candidate should possess one or more (preferred) of the following certifications— CISSP, CISM, SABSA, CEH, GCSA, GDSA, GCIH, ITIL, Cisco/Microsoft advanced security certifications. Certifications from OEMs like Netskope, Zscaler, and/or Palo Alto are an added advantage. 

  • Must have a minimum of 3 years’ experience managing enterprise-wide network and cloud security services based on zero-trust.   

Knowledge and/or experience (preferred) in: 

  • Engineering, implementation and operations of networking technologies and protocols (routing, switching), and on-prem and cloud security tools such as Secure Service Edge (Zscaler, Netskope, Palo Alto), network proxy, firewalls (Checkpoint, Palo Alto), web application firewalls, NDR, network analyzers, Network Access Control, micro segmentation, container security (Kubernetes preferred), logging and alerting with SIEM, strong authentication, IPS/IDS, VPNs, DDoS etc.  

  • Implementing Zero Trust at scale across hybrid environments.  

  • Managing SASE, CASB, ZTNA, SWG technologies in distributed and decentralized hybrid environments.  

  • Hands-on experience with SSE enhanced functionalities like Remote Browser Isolation, DLP, Deep Packet Inspection, Advanced Threat Protection, Agentless Access, Remote User Protection, Remote User Protection, User Behavioral Analysis, and Identity Based Security Policy. 

  • Ability to engineer solutions and workarounds specific to the IMF’s requirements (agentless endpoints, routed traffic, IOT devices and guest Wi-Fi protection). 

  • Cloud Native Application Protection Platforms (CNAPP) including CSPM, CWPP, CSNS, DevSecOps for protecting multi-cloud environments (Microsoft preferred).   

  • Infrastructure security automation, capacity monitoring and automated scaling solutions. Security Orchestration and Automated Response solution (Palo Alto SOAR) to enhance security toolsets.  

  • Using cloud technologies to provide data protection, container security, networking, system administration and zero-trust architectures.  

  • Scripting languages (e.g., PowerShell, Python, Terraform, Ansible, Bash).  

  • MITRE ATT&CK, NIST CSF, CVSS and CWE criteria, enumeration, and scoring.  

  • Enterprise level IT service management, including continuous service improvement.  

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

International Monetary Fund

View company profile →