INTERPOL is the world’s largest international police organization, with 196 Member Countries. Created in 1923, it facilitates cross-border police cooperation and supports organizations, authorities and services whose mission is to prevent or combat international crime.
JOB TITLE: Information Systems Security Analyst (Reserve List)
REPORTING TO: Security Operations Center Manager
LOCATION: Lyon
CONTRACT: Fixed-term and short-term contracts
DURATION: Different durations depending on future needs, up to 3 years
GRADE: 5
NUMBER OF POSTS: Roster
APPLICATION DEADLINE: 23 August 2026
The selection exercise will generate a reserve list of recommended candidates to address future staffing needs. Any subsequent extension is subject to the Staff Manual, satisfactory performance and availability of funds. Interviews/tests are expected approximately 1–3 weeks after the application deadline. Selected candidates are expected to report for duty approximately 1–3 months after receiving an offer.
SUMMARY OF DUTIES
The Information Systems Security Analyst works within the Security Operations Center (SOC) and is responsible for monitoring, investigating and responding to cybersecurity threats and incidents. The position requires knowledge of sourcing, installing, maintaining and configuring security systems including UTM, messaging gateways, SIEM, encryption systems and endpoint security.
The role includes monitoring server, firewall, intrusion detection, web filtering and antivirus logs for suspicious activity; conducting incident management, Business Impact Analysis (BIA) and Disaster Recovery Planning (DRP); ensuring recovery configurations are regularly updated; monitoring security patches and recommending their implementation; and contributing to security documentation and architecture.
PRINCIPAL DUTIES
- SECURITY OPERATIONS AND COLLABORATION
- Participate in SOC activities, process improvement and on-call/shift duties.
- Monitor security risks, network events and security-tool alerts to identify potential incidents.
- Respond to security incidents, perform alert review and triage, and conduct in-depth investigations.
- Evaluate incidents and attacks, identify root causes, implement countermeasures and restore operations.
- Identify weaknesses and vulnerabilities in IT infrastructure.
- Analyze threats and identify indicators of compromise (IoCs), indicators of attack (IoAs) and advanced persistent threats (APTs).
- Develop containment, eradication and recovery strategies based on the Disaster Recovery Plan.
- Maintain technology watch on developments, trends and techniques in IT security.
- SECURITY ENGINEERING
- Maintain, configure and fine-tune security tools including SIEM, SIM, UEBA, SOAR, reverse proxies, directories, identity management/access, antivirus, vulnerability scanners, PKI, authentication and application firewalls.
- Implement and manage SIEM rules, logic, actions and alerts.
- Create and improve SIEM search queries and detection capabilities while reducing false positives.
- Ensure appropriate use cases, operational controls, procedures, testing and documentation are in place.
- Develop security strategies based on observed events.
- Perform deep data analysis and onboard new data sources into the SIEM.
- Perform automated health checks and ensure effective event and incident detection.
- SECURITY AND RISK MANAGEMENT
- Support the SOC Manager in ensuring coherence between organizational security policies and IS&T Operations policies.
- Propose mitigation measures based on risk assessments.
- Support security awareness and training initiatives.
- Draft and maintain internal Standard Operating Procedures.
- Contribute to the IS Directorate business plan and roadmaps.
- Escalate strategic IT security risks to the SOC Manager.
- Execute security audits, assessments and penetration tests and advise on corrective actions and improvements.
QUALIFICATIONS
- Three-to-four years of university or specialized higher education in software engineering, computer science, information technology, information security, mathematics, engineering or a related field preferred.
- One or more internationally recognized IT security certificates such as CISM, CISSP or CEH.
EXPERIENCE
- At least 3 years of professional experience in IT security is required, preferably including experience in a Security Operations Center (SOC).
LANGUAGES
- Fluency in English, written and spoken.
- French, Arabic or Spanish is an additional asset.
SPECIAL APTITUDES
- Highest integrity, discretion and confidentiality.
- Excellent communication and prioritization skills.
- Ability to maintain objectivity and apply logical reasoning.
- Ability to work independently and in teams, including under pressure.
- Personal and professional maturity.
- Good social skills in a multicultural environment.
- Initiative, creativity, curiosity and ability to develop professional networks.
- Strong synthesis and listening skills.
TECHNICAL ABILITIES
- Defense-in-depth security approach.
- Cryptographic solutions, accreditation/certification and IT security best practices.
- Network and security infrastructure including web servers, reverse proxies, firewalls, WAFs, authentication, SSO, PKI and SIEM.
- Common protocols including HTTP, LDAP, DNS and DHCP.
- Cloud security principles and techniques.
- Server and storage technologies including NAS, SAN, distributed file systems, virtualization, containers, databases, mail servers and backups.
Other duties may be performed as required by the SOC Manager.
Only professional experience supported by official proof of employment will be considered.
INTERPOL’s recruitment process is merit‑based, with hiring decisions based on candidates’ qualifications and organizational needs.