IOM: Senior Information Security Officer – Madrid

  • Location:
  • Salary:
    $0 / YEAR
  • Job type:
    FULL_TIME
  • Posted:
    1 month ago
  • Category:
    Information and Communication Technology, Security
  • Deadline:
    09/07/2025

JOB DESCRIPTION

Description

International Organization for Migration is hiring a Senior Information Security Officer.

Context:

Under the direct supervision of Chief Information Officer (CIO) and in close collaboration with relevant Information and Communications Technology (ICT) Units at Headquarters (HQ) and worldwide ICT Teams, the successful candidate will be responsible for leading the definition and implementation of the Global Cybersecurity Strategy, in the area of Information Security and Risk Management including  application security, data security, threat, vulnerability, risk, and compliance  management.

Lead and manage the cybersecurity Blue Team functions, processes and team members.
Ensure that the information security and risk management functions, processes, procedures, training sessions, and playbooks are developed, implemented, auditable and repeatable, as well as aligned with business and strategic organizational objectives.
Improve the maturity level of data security to the defined higher level, and evaluate and advise on progress, risk monitoring and performance,ensuring the development of Key Performance Indicators (KPI)/metrics.
Provide advice and subject matter expertise for the review, consistent implementation and compliance-monitoring of IOM-wide information security policies, operating procedures standards, and guidelines.
Lead the response to security audit requests and provide advisory services to ensure the implementation of recommendations (including FISMA/NIST 800-53 controls, ISO 27001).
Define and coordinate the implementation of the Global Cybersecurity Strategy, including the formulation of awareness-related activities and delivery of global workshops / webinars.
Create security policies and procedures based on ISO27001, NIST 800-53 and Computer Information System (CIS) controls.
Conduct complex threat, vulnerability, risk and compliance assessments, audit information security controls, simulate cyber-attacks and data breaches, and provide authoritative advice on cybersecurity governance, risk and compliance practices as well as change management.
Lead and manage a variety of cyber security projects, including the management of resources.
Carry out complex and/or sensitive investigations and audits.
Provide authoritative advice to queries/requests/tickets related to data security, risks, rotation, access and other information security matters.
Provide authoritative advisory services for decision-making activities related to information security topics.
Perform such other duties as may be assigned.

Education

Master’s degree in computer science, information systems, mathematics, statistics or related field from an accredited academic institution with seven years of relevant professional experience; or
University degree in the above fields with nine years of relevant professional experience.
Professional certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Chief Information Security Officer (CCISO), Certified Secure Software Lifecycle Professional (CSSLP), Governance, Risk, and Compliance Professional (GRCP), Project Management Professional (PMP), or related will be a distinct advantage in addition to leaders
Information Technology Infrastructure Library (ITIL) and Prince2 Foundation are added advantages.

Accredited Universities are those listed in theUNESCO World Higher Education Database.

Experience

Extensive experience in building a cybersecurity defensive team (BLUE TEAM);
Extensive experience in building a cybersecurity governance, risk, and compliance practices;
Extensive experience in creating policies, standards, and guides;
Extensive experience in all aspects of application / data security (definition, implementation and validation);
Extensive experience in simulating cyber-attacks and data breaches;
Experience managing projects and teams; and,
Experience defining security strategies aligned with business and strategic objectives.

Skills

Strong interpersonal skills;
Solid organization and document, project management;
Strong investigative skills;
Strong ability to continue to learn and grow;
Basic knowledge of reporting tools (e.g., MS Excel, Power BI, Power BI Report Builder);
Ability to translate technical security vulnerabilities into business risk/impact to applications;
Demonstrated skill in creating security policies and procedures based on ISO27001, NIST 800-53 and Computer Information System (CIS) controls;
Strong analytical and problem-solving skills and proactive thinking skills;
Able to articulate complex, technical concepts to non-technical audiences; and,
Strong English oral and written communications skills.

Languages

IOM’s official languages are English, French and Spanish.

For this position fluency in English is required (Oral and Written). Working knowledge of French, Spanish and/or an official UN Language (Arabic, Chinese, and Russian) is an advantage.

Proficiency of language(s) required will be specifically evaluated during the selection process, which may include written and/or oral assessments.

Required Competencies

IOM’s competency framework can be found at thislink. Competencies will be assessed during the selection process.

Values– all IOM staff members must abide by and demonstrate these five values:

Inclusion and respect for diversity: Respects and promotes individual and cultural differences. Encourages diversity and inclusion.
Integrity and transparency: Maintains high ethical standards and acts in a manner consistent with organizational principles/rules and standards of conduct.
Professionalism: Demonstrates ability to work in a composed, competent and committed manner and exercises careful judgment in meeting day-to-day challenges.
Courage: Demonstrates willingness to take a stand on issues of importance.
Empathy: Shows compassion for others, makes people feel safe, respected and fairly treated.

Core Competencies– behavioural indicators Level 3

Teamwork: Develops and promotes effective collaboration within and across units to achieve shared goals and optimize results.
Delivering results: Produces and delivers quality results in a service-oriented and timely manner. Is action oriented and committed to achieving agreed outcomes.
Managing and sharing knowledge: Continuously seeks to learn, share knowledge and innovate.
Accountability: Takes ownership for achieving the Organization’s priorities and assumes responsibility for own actions and delegated work.
Communication: Encourages and contributes to clear and open communication. Explains complex matters in an informative, inspiring and motivational way.

Managerial Competencies– behavioural indicators Level 3

Leadership: Provides a clear sense of direction, leads by example and demonstrates the ability to carry out the Organization’s vision. Assists others to realize and develop their leadership and professional potential.
Empowering others: Creates an enabling environment where staff can contribute their best and develop their potential.
Building Trust: Promotes shared values and creates an atmosphere of trust and honesty.
Strategic thinking and vision: Works strategically to realize the Organization’s goals and communicates a clear strategic direction.
Humility: Leads with humility and shows openness to acknowledging own shortcomings.

Notes

Internationally recruited professional staff are required to be mobile.

Any offer made to the candidate in relation to this vacancy notice is subject to funding confirmation.

This selection process may be used to staff similar positions in various duty stations. Recommended candidates will remain eligible to be appointed in a similar position for a period of 24 months.

The list of NMS countries above includes all IOM Member States which are non-represented in the Professional Category of staff members. For this staff category, candidates who are nationals of the duty station’s country cannot be considered eligible.

Appointment will be subject to certification that the candidate is medically fit for appointment, accreditation, any residency or visa requirements, security clearances.
IOM has a zero-tolerance policy on conduct that is incompatible with the aims and objectives of the United Nations and IOM, including sexual exploitation and abuse, sexual harassment, abuse of authority and discrimination based on gender, nationality, age, race, sexual orientation, religious or ethnic background or disabilities.

IOM does not charge a fee at any stage of its recruitment process (application, interview, processing, training or other fee). IOM does not request any information related to bank accounts.

IOM only accepts duly completed applications submitted through theIOM e-Recruitmentsystem (for internal candidates linkhere). The online tool also allows candidates to track the status of their application.

For further information and other job postings, you are welcome to visit our website:IOM Careers and Job Vacancies

Level of Education: Bachelor Degree

Work Hours: 8

Experience in Months: No requirements

This job has expired.