Information Security Officer (MTIT)
Organizational Context
The Division of Information Technology (MTIT) supports the IAEA with information and communication technology (ICT), managing its ICT strategy, standards, and central services. The division oversees the IAEA's ICT infrastructure, including hardware, software, and cloud services, operating under ITIL and Prince2 best practices to ensure efficient and secure operations.
Job Purpose
The Information Security Officer's primary role is to enhance the IAEA's information security by developing and implementing repeatable, consistent processes. This involves contributing to a comprehensive information security program, managing and participating in security projects, and overseeing the administration and verification of security controls. The position is crucial for maintaining the confidentiality, integrity, and availability of the IAEA's information systems and data.
Responsibilities
Key responsibilities include developing and implementing mature information security policies, procedures, and guidance to ensure data confidentiality, integrity, and availability. The role involves operating the Agency's Information Security Management System (ISMS) to maintain ISO 27001 certification, and developing/maintaining a state-of-the-art risk management system aligned with the latest threat landscape. This includes participating in risk assessments, identifying and analyzing risks, recommending corrective actions, and monitoring remediation. Additionally, the officer will contribute to awareness programs, participate in IT projects to embed security, and produce high-quality reports, while maintaining proficiency in industry standards and IAEA procedures.
Work Experience
A minimum of five years of professional experience is required, specifically in managing information security programs within enterprise IT environments. This experience should include applying standardized frameworks like ISO/IEC 27000. Demonstrated expertise in IT risk management, policy development and implementation, compliance monitoring, stakeholder engagement, and IT project management is also necessary.
Skills
Proficiency in IT Security and IT Project Management. Skills include planning and organizing work, clear and concise communication, achieving results, client orientation, commitment to continuous process improvement, and maintaining technical/scientific credibility. Experience in IT risk management, policy development, compliance monitoring, and stakeholder engagement is essential.