DEADLINE FOR APPLICATIONS 21 September 2026-23:59-GMT+01:00 Central European Time (Rome)
WFP celebrates and embraces diversity. It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender, gender identity and/or expression, sexual orientation, religion or belief, HIV status or disability.
The World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity, for people recovering from conflict, disasters and the impact of climate change. At WFP, people are at the heart of everything we do and the vision of the future WFP workforce is one of diverse, committed, skilled, and high performing teams, selected on merit, operating in a healthy and inclusive work environment, living WFP's values (Integrity, Collaboration, Commitment, Humanity, and Inclusion) and working with partners to save and change the lives of those WFP serves.
WFP offers a highly inclusive, diverse, and multicultural working environment. WFP invests in the personal & professional development of its employees through a range of training, accreditation, coaching, mentorship, and other programs as well as through internal mobility opportunities. A career path in WFP provides an exciting opportunity to work across the various country, regional and global offices around the world, and with passionate colleagues who work tirelessly to ensure that effective humanitarian assistance reaches millions of people across the globe.
WFP is a 2020 Nobel Peace Prize Laureate.
Job Title: CYBERSECURITY ADVISORY CONSULTANT (AI Security & Secure by Design)
Type of Contract: CST Level II
Unit/Division: Technology Division, Information Security
Duty Station: Remote work
Duration: 11 months
Background and Purpose of the Assignment
- Authorization to Operate and cyber security compliance
- Application security
- Network security
- Secure-by-design principles across the technology lifecycle from solution conception through deployment and operation.
- Securing critical applications such as beneficiary management systems
- Support the secure adoption of artificial intelligence and emerging technologies
- Identity and access management
Accountabilities / Responsibilities
- Conduct comprehensive risk assessments and lead the Authorization to Operate (ATO) process for IT systems and services, ensuring that security risks are appropriately identified, evaluated, documented, mitigated and communicated to relevant stakeholders.
- Design, review and oversee the security architecture of new and existing applications, platforms, cloud services and technology initiatives, ensuring that appropriate security controls are embedded by design and aligned with organizational policies, data classification requirements and industry best practices.
- Develop and maintain security requirements for artificial intelligence solutions, covering the secure handling of data, models, prompts, interfaces and supporting infrastructure throughout the solution lifecycle.
- Conduct security assessments of AI use cases and solutions, identifying risks related to data exposure, unauthorized access, model manipulation, insecure integrations, third-party dependencies and unintended system behaviour, and recommend proportionate mitigation measures.
- Embed secure-by-design principles into solution development and procurement processes, defining reusable security requirements, review checkpoints and design guidance.
- Lead the development, implementation and continuous improvement of cybersecurity procedures, services, methodologies and governance frameworks aimed at protecting organizational information assets, systems and services.
- Research, evaluate and propose innovative technologies, security capabilities and process improvements that strengthen the cybersecurity posture of the organization while demonstrating measurable business value and operational effectiveness.
- Propose and maintain new security standards, procedures and guidelines to help raise the current security maturity level of the organization. In close collaboration with the Architecture branch, perform regular baseline and hardening reviews of WFP security solutions and technologies.
- Provide expert cybersecurity advisory services and technical guidance to County Offices, Regional Bureaus and HQ divisions to address cybersecurity challenges and maintain compliance with organizational security standards.
- Provide guidance to IT solution owners across the organization to: - Design security controls appropriate to the technology and risk landscape. - Protect information according to its classification and sensitivity - Implement secure software development lifecycle (SSDLC) practices. - Integrate security requirements into project and solution lifecycles - Ensure compliance with cybersecurity standards and requirements.
- Advise stakeholders on cybersecurity risks associated with emerging technologies, including cloud services, artificial intelligence, software-as-a-service (SaaS), digital transformation initiatives and data-driven solutions.
- Maintain a record of decisions taken and assessments performed, in cooperation with other members of the Advisory team.
- Identify and execute improvements to existing processes, through solutions to address recurring problems and enhancements to existing solutions or documentation.
- Act as Subject Matter Expert (SME) for assigned technologies, platforms , business applications and cybersecurity domains.
- Prepare and present high-quality reports, risk assessments, executive briefings, architecture recommendations and management updates tailored to technical and business audiences.
- Mentor, coach and provide technical leadership to junior team members, contributing to knowledge sharing, capability development and continuous improvement within the Advisory team.
- Represent the Cybersecurity Branch in meetings, working groups, steering committees, audits, assessments and enterprise initiatives as required.
- Perform additional duties and responsibilities as required in support of TECI Cybersecurity objectives.
Qualifications & Experience Required
- Solid IT Security skills, with both academic background and professional experience
- Solid IT SDLC expertise.
- Strong understanding of AI security concepts, threats and risk management practices.
- Ability to define and implement secure-by-design principles, security requirements and architectural controls throughout the solution lifecycle.
- Experience conducting security reviews of AI-enabled solutions, including data protection, model security, third-party AI services and integration security.
- Understanding of IT architecture and design concepts.
- Ability to manage stakeholder relationships, aligning cybersecurity risk strategies with business objectives.
- Understand cybersecurity risk concepts to assess threats, vulnerabilities and mitigation strategies.
- Good project management skills.
- Experience in multinational organizations
- IT Security and IT Audit certifications
- Security architecture in the cloud.
- Understanding of AI security concepts and framework
- Experience in ISO, NIST, HIPAA or PCI compliance processes.
Languages
Fluency in oral and written English is mandatory with an intermediate knowledge of another official UN language (Arabic, Chinese, French, Russian and Spanish) or Portuguese (one of WFP’s working languages) is desirable.
WFP is committed to providing an inclusive work environment free of sexual exploitation and abuse, all forms of discrimination, any kind of harassment, sexual harassment, and abuse of authority.