Information Systems Security Officer

INTERPOL

Lyon

Sur place

EUR 70 000 - 95 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

INTERPOL seeks an Information Systems Security Officer in Lyon to oversee governance, risk, and compliance for the IS Directorate. The role bridges the CISO office and IS teams, ensuring security standards and SOPs align with policies and industry practices.

The ISSO will lead risk management, audits, and advising across projects, coordinating with departments to meet deadlines while safeguarding information security across the organization.

Qualifications

  • Three to four years’ education at a University or specialized higher education establishment.
  • One or more internationally recognized IT Security Certifications (CISM, CISSP, CEH, etc.).
  • Other certifications including ITIL foundation are appreciated.

Responsabilités

  • Governance and Compliance: Implement security strategy within the IS Directorate; act as entry point for audits and assessments.
  • Risk Management: Maintain risk register and conduct IT security risk assessments and analyses.
  • Advisory and Awareness: Provide guidance on IT security aspects of projects and train colleagues on security best practices.
  • Reporting and Performance Management: Collect KPIs and report on security performance and compliance.
  • Perform any other duties as required by the supervisor.

Connaissances

Governance & Compliance
Risk Management
Audits & Assessments
CISOs liaison
ISO 27001
GDPR
SIEM
Communication

Formation

University degree
CISM/CISSP/CEH certifications

Outils

SIEM systems
Audit management software
GDPR compliance tools

Description du poste

1930

Vacancy Notice 1930 INTERPOL is the world’s largest international police organization, with 196 Member Countries. Created in 1923, it facilitates cross-border police co-operation, and supports and assists all organizations, authorities, and services whose mission is to prevent or combat international crime.

INTERPOL actively encourages applications from women and nationals of member countries that are currently unrepresented among our staff (please click on this link to access the list of countries). Candidates from these countries are particularly encouraged to apply.

INTERPOL’s recruitment process is merit-based hence all hiring decisions are made considering the applicant’s qualifications and the needs of the Organization.

Job Title: Information Systems Security Officer

Reporting To: Chief IT Governance Officer

Location: Lyon

Type of contract: Fixed-term Contract

Duration (in months): 36.00

Grade: 5

Number of post: 1

Level of Security screening: Enhanced

Deadline for application: 23 August 2026

Conditions applying for all candidates

Only professional experience for which candidates can provide official proof of employment will be considered. Candidates could be requested to provide copies of such official documents prior to interviews/test.

  • Subsequent extension to this post will be subject to the terms of the Organization’s Staff Manual, to satisfactory performance and to availability of funds.

Tests/interviews in connection to this selection procedure will take place approximately 1/3 weeks after the deadline for applications. Applicants are kindly requested to plan their availability during this period accordingly, in case they are short-listed.

Selected candidates will be expected to report for duty approximately one to three months after receiving an offer of employment at the latest.

This selection exercise may be used to generate a reserve list of suitable candidates that may be used to address Organization's similar staffing needs in the future.

SUMMARY OF THE ASSIGNED DUTIES, INCLUDING GOALS AND OBJECTIVES OF THE POST

The post-holder reports to the Head of Department, IT Governance and Directorate Executive Office, within the Executive Directorate Technology and Innovation, Information Systems and Technology Directorate (IS).

The Information Systems Security Officer (ISSO) is responsible for ensuring the effective implementation of the Organization's information security strategy within the Information Systems and Technology (IS) Directorate. The ISSO acts as a bridge between the Chief Information Security Officer (CISO) office and the IS Directorate, focusing on governance, risk, and compliance aspects of IT security.

The ISSO collaborates with all IS Sub-Directorates and Departments to implement guidelines based on CISO policies and ensures that Standard Operating Procedures (SOPs) are developed and maintained by relevant IS teams, with a focus on identifying and mitigating risks and managing exceptions to ensure compliance with organizational security standards and policies.

PRINCIPAL DUTIES AND ACTIVITIES
Mission 1: Governance and Compliance
  • Collaborate with the CISO to ensure the implementation of organizational information security strategy within the IS Directorate. Act as an entry point within IS for OIO audits and Assessments of IS IT Security compliance.
  • Develop and maintain IS security Standards and guidelines in alignment with organizational security policies.
  • Ensure compliance with relevant laws, regulations, and industry standards related to IT security.
  • Participate in the development of the IS security roadmap and ensure its alignment with the organizational security strategy.
  • Report on progress towards compliance with security policies, procedures, and standards to management and stakeholders.
Mission 2: Risk Management
  • Maintain the IS Directorate's security risk register and perform IT security risk assessments and analysis.
  • Liaise with the CISO to elevate strategic IT security risks linked to technology or within the scope of work of the IS Directorate.
  • Assist in security audits, assessments, and penetration tests, in collaboration with the IS Security Department, by reviewing and analyzing findings, and advise the IS Directorate on corrective actions or enhancements to IT products or projects.
  • Develop and maintain a risk management framework for the IS Directorate.
Mission 3: Advisory and Awareness
  • Where relevant, provide advice and guidance on specific IT security aspects of projects and products.
  • Participate in initiatives to inform and train colleagues about security awareness and best practices.
  • Act as the IS Directorate point of contact for security or IT-related investigations and other security matters.
  • Collaborate with teams to ensure they meet deadlines and comply with security requirements, providing guidance and support as needed.
Mission 4: Reporting and Performance Management
  • Collect and report on relevant KPIs to measure the effectiveness of IS security governance, risk, and compliance activities.
  • Prepare and present regular reports to management and stakeholders on IS security performance, risks, and compliance.
  • Identify areas for improvement and propose corrective actions to enhance IS security governance, risk, and compliance.
Mission 5: Perform any other duties as required by the supervisor
Qualifications, Competencies And Skills
Education and qualification required/FORMATION
  • Three to four years’ education at a University or specialized higher education establishment.
  • One or more internationally recognized IT Security Certifications (CISM, CISSP, CEH, etc.)
  • Other certifications including ITIL foundation are appreciated.
Experience required/EXPÉRIENCE
  • At least 5 years of experience in a large and complex IT enterprise environment.
  • Experience in developing and maintaining information security policies, standards, procedures, and guidelines, and ensuring their alignment with organizational security standards and industry best practices.
  • Proven track record of identifying and mitigating IT security risks and developing and implementing risk management plans to minimize potential impacts on the organization.
  • Experience in conducting security audits, assessments, and compliance reviews, and providing recommendations for remediation and improvement to ensure adherence to organizational security policies and industry standards.
languages/langues
  • Fluency in English is required.
  • Knowledge of another working language of the Organization (French, Arabic or Spanish) would be an additional asset
Abilities required/COMPéTENCES TECHNIQUES
  • Knowledge of IT security governance frameworks and standards (e.g., ISO 27001, NIST)
  • Understanding of risk management principles and methodologies
  • Familiarity with IT security regulations and laws (e.g., GDPR)
  • Knowledge of security information and event management (SIEM) systems and other security tools.
  • Ability to develop and maintain information security policies, standards, procedures, and guidelines.
  • Knowledge of industry security standards and best practices.
  • Experience with compliance reviews and audits.
  • Ability to identify and mitigate IT security risks.
  • Experience with risk management plans and strategies.
  • Knowledge of risk assessment and analysis techniques.
  • Excellent communication and interpersonal skills.
  • Ability to work with technical and non-technical stakeholders.
  • Experience with collaboration and teamwork in a multicultural environment.
  • Ability to prioritize and manage multiple tasks and projects.
  • Ability to maintain confidentiality and handle sensitive information.
  • Strong attention to detail and organizational skills.
  • Ability to work under pressure and meet deadlines.

As part of our commitment to transparency throughout our recruitment process, INTERPOL's Staff Manual Regulation 11.4: Age-limit, which states that:

'Officials of the Organization shall not normally be retained in service beyond the age of 65 years. The Secretary General may, in exceptional cases and in the interests of the Organization, extend this age limit, in which case he shall inform the official concerned sufficiently in advance.'

Given this Regulation and in case candidates reach the age of 65 during the potential duration of the appointment, should they be selected for the position and the process proceed to appointment, the employment period may be affected by this regulatory limit and may therefore not extend for the full standard contract duration as published in the vacancy notice.

We are sharing this information to ensure transparency at this stage of the process.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Information Systems Security Analyst (Reserve List)
Information Systems Security Analyst (Reserve List)

INTERPOL • Lyon

Sur place
EUR 55 000 - 75 000
IT Business Analyst - AI Transformation
IT Business Analyst - AI Transformation

INTERPOL • Lyon

Sur place
EUR 55 000 - 90 000
Product Engineer
Product Engineer

OECD - OCDE • Paris

Sur place
Staff Administration Team Lead
Staff Administration Team Lead

OECD - OCDE • Paris

Sur place
EUR 67 000 - 81 000
Head of IT Infrastructure and Client Services Section
Head of IT Infrastructure and Client Services Section

European Directorate for the Quality of Medicines & HealthCare (EDQM), Council of Europe • Strasbourg

Sur place
EUR 70 000 - 110 000
Principal Assistant, Personnel, Administration and Logistics
Principal Assistant, Personnel, Administration and Logistics

NATO • France

Sur place
30 days annual leave
Life and medical insurance
Retirement pension plan
CIS senior technician
CIS senior technician

NATO • France

Sur place
EUR 5 000 - 64 000
30 days of annual leave
Life and medical insurance
Retirement pension plan
Staff Officer - Capability Coordination Group (Air)
Staff Officer - Capability Coordination Group (Air)

NATO • France

Sur place
30 days annual leave
Life and medical insurance
Retirement pension plan
+1
Executive Officer Kinetic Effects
Executive Officer Kinetic Effects

NATO • France

Sur place
30 days annual leave
Life and medical insurance
Retirement pension plan
+2
Administrative Assistant
Administrative Assistant

EUROCONTROL • Brétigny-sur-Orge

Hybride
EUR 32 000 - 50 000