WFP
Network Detection & Security Engineer
Organizational Context
The World Food Programme (WFP) is the world's largest humanitarian organization, dedicated to saving lives and building a pathway to peace, stability, and prosperity. We operate in emergencies and support recovery from conflict, disasters, and climate change impacts. WFP values diversity, inclusion, and invests in employee development, offering a rewarding career path in a global, multicultural environment.
Job Purpose
The Network Detection & Security Engineer will be instrumental in defining and implementing WFP's network and IoT security strategy. This role focuses on establishing robust Network Detection and Response (NDR) capabilities across priority sites by developing policies, standards, and telemetry requirements. The incumbent will shape the design authority for telemetry architecture and operational reporting, focusing on IoT trust tiers, Network Access Control (NAC) posture, segmentation patterns, and DNS security baselines. Responsibilities include specifying telemetry requirements for SIEM, SOAR, and XDR platforms, building detection packs for network-borne threats, and managing change governance to ensure the successful and secure rollout of NDR solutions.
Responsibilities
The Network Detection & Security Engineer role at WFP involves defining and implementing policies, standards, and telemetry requirements for network and IoT security. This includes shaping the design authority, telemetry architecture, and operational reporting for WFP’s Network Detection and Response (NDR) capability. Key responsibilities include developing IoT trust tiers, Network Access Control (NAC) posture, segmentation patterns for high-value zones, and DNS security baselines. The engineer will specify telemetry and profiling requirements for SIEM, SOAR, XDR, and NDR sensors, build detection packs and playbooks for network-borne threats, and manage change governance for the NDR rollout. They will also validate and monitor security policies, develop and tune detection logic for various network threats, oversee vulnerability assessments for IoT devices, and create dashboards and reports on coverage, trends, and response performance. The role requires maintaining governance for approvals, exception handling, and audit trails, as well as coordinating with relevant teams for vulnerability scans and remediation tracking. This position is crucial for enhancing WFP's security posture across its network infrastructure.
Work Experience
Requires at least 5 years of experience in cybersecurity, network architecture, or security policy network engineering. Proven track record in designing and implementing network and IoT security controls is essential. Preferred experience includes defining NAC posture, segmentation patterns, and DNS layer policies. Experience with network telemetry pipelines or Network Detection and Response (NDR) tooling, including sensor deployment and analysis, is highly desirable.
Skills
Network Security, IoT Security, Cybersecurity, Network Architecture, Security Policy, Network Engineering, NAC (Network Access Control), Segmentation, DNS Security, Telemetry, SIEM, SOAR, XDR, NDR (Network Detection and Response), Vulnerability Assessment, Risk Management, Reporting, Stakeholder Management, Communication
Required Languages
English, Arabic, Chinese (Mandarin), French, Russian, Spanish, Portuguese
Desired Languages
English, Arabic, Chinese (Mandarin), French, Russian, Spanish, Portuguese
Summary based on official posting. Please verify all details on the official website.Official Posting ↗
Explore related opportunities