Verschicke keinen generischen Lebenslauf — erstelle einen Lebenslauf und ein Anschreiben, die genau auf diese Rolle zugeschnitten sind.
International Atomic Energy Agency is seeking an Information Security Officer (MTIT) to lead the development and delivery of a comprehensive information security program. The role includes management of ISMS, risk assessment, and security controls within MTIT division, ensuring alignment with ISO 27001 and agency standards.
The ideal candidate has five+ years in enterprise IT security, strong governance experience, and relevant certifications.
Information Security Officer (MTIT)(P3) (2026/0386 (013916))
MTIT-Division of Information Technology
2026-08-24, 9:34:45 AM
2026-09-14, 9:59:00 PM
Duration in Months : 36
Contract Type : Fixed Term - Regular
Full Competitive Recruitment : Yes
This selection exercise may be used to generate a roster of pre-approved candidates to address future staffing needs for similar functions in any of the Departments and Offices of the Organization.
IMPORTANT NOTICE REGARDING APPLICATION DEADLINE: Please note that the closing date for submission of applications is indicated in local time as per the time zone of the applicant's location.
The Division of Information Technology provides support to the IAEA in the field of information and communication technology (ICT), including information systems for technical programmes and management. It is responsible for planning, developing and implementing an ICT strategy, for setting and enforcing common ICT standards throughout the Secretariat and for managing central ICT services. The IAEA's ICT infrastructure comprises hardware and software platforms, and cloud and externally-hosted services. The Division has implemented an IT service management model based on ITIL (IT Infrastructure Library) and Prince2 (Projects in a Controlled Environment) best practices.
The purpose of the post is to help MTIT define and create repeatable and consistent processes to strengthen IAEA information security. The Information Security Officer participates in the development and delivery of a comprehensive information security program for the IAEA. He/she also manages/participates in implementation of information security projects, and the administration and verification of security controls.
The Information Security Officer is (a) an operator for the Agency Information Security Management System (ISMS); (b) the Departmental information Security Officer (DISO) for the department of Management; (c) a risk manager managing security risks identified through set processes; (d) a project manager/coordinator, soliciting inputs from other specialists and assisting in defining, planning and executing information security projects; and (e) a CISG and MTIT team member.
Contribute as a key player to ensuring the confidentiality, integrity and availability of information systems and data through developing and implementation of mature information security policies, procedures and guidance. Operate the Agency ISMS in order to obtain and maintain the Agency's ISO 27001 certification. Develop, implement and maintain a state-of-the-art risk management system, focusing on latest threat landscape, appropriate mitigating controls on technical and organisational level. Participate in the information security risk assessment program, identify and analyse risks, make recommendations for corrective actions and monitor implementation and remediation. Participate in the comprehensive awareness program, including provision of face-to-face or online training, phishing exercise, ad-hoc newsletter, regular intranet information and other relevant information. Participate in IT projects on behalf of the CISO to ensure that security is embedded. Produce high-quality oral and written reports, presenting complex technical matters clearly and concisely. Maintain proficiency in industry standard tools and practices and in IAEA policies and procedures.
Plans and organizes his/her own work in support of achieving the team or Section’s priorities. Takes into account potential changes and proposes contingency plans.
Communicates orally and in writing in a clear, concise and impartial manner. Takes time to listen to and understand the perspectives of others and proposes solutions.
Takes initiative in defining realistic outputs and clarifying roles, responsibilities and expected results in the context of the Department/Division’s programme. Evaluates his/her results realistically, drawing conclusions from lessons learned.
Actively contributes to achieving team results. Supports team decisions.
Name
Definition
Client orientation Helps clients to analyse their needs. Seeks to understand service needs from the client’s perspective and ensure that the client’s standards are met.
Commitment to continuous process improvement Plans and executes activities in the context of quality and risk management and identifies opportunities for process, system and structural improvement, as well as improving current practices. Analyses processes and procedures, and proposes improvements.
Technical/scientific credibility Ensures that work is in compliance with internationally accepted professional standards and scientific methods. Provides scientifically/technically accepted information that is credible and reliable.
Required Expertise
Function
Name
Information Technology IT Security Experience in the design and architecture of IT security systems, with a strong understanding of secure infrastructure and system integration.
Information Technology Information Security Experience in design, implementation and operation of Identity and Access Management solutions;
Information Technology Information Security and Risk Management Experience in assessing information security risks and delivering effective technical solutions to mitigate identified vulnerabilities. Proven expertise in the design, implementation, and operation of Information and IT Security Risk Management solutions.
Information Technology Information Security and Risk Management Experience in design, implementation and operation of Information and IT Security Risk Management solutions;
Asset Expertise
Function
Name
Information Technology Project Management Experience in IT project management using the established project management methodology; eExperience in managing IT projects using best practice project management methodologies such as PMP and/or Prince2.
Qualifications, Experience and Language skills
Bachelor's Degree - University degree in computer science, information management, IT Security or a related field.
Other - Accredited information or IT security relevant certification, such as CISSP, CISM, CISA or GIAC.
Other - Accredited certification in Project Management such as PMP, Prince2 as an asset.
Minimum of five years of professional experience managing information security programs in enterprise IT environments, applying standardized frameworks, such as ISO/IEC 27000. Demonstrated expertise in IT risk management, policy development, writing and implementation, compliance monitoring, and stakeholder engagement, with a strong background in IT Project Management.
Excellent oral and written command of English.
Knowledge of other official IAEA languages (Arabic, Chinese, French, Russian and Spanish) is an asset.