Cybersecurity Advisory Consultant (AI Security & Secure by Design)
Organizational Context
The World Food Programme (WFP) is the world's largest humanitarian organization, dedicated to saving lives and building a pathway to peace, stability, and prosperity. WFP operates in emergencies and supports people recovering from conflict, disasters, and climate change impacts. The organization values diversity, inclusion, and invests in employee development.
Job Purpose
The Cybersecurity Advisory Consultant will provide expert consulting services to WFP's business units, focusing on Authorization to Operate (ATO), cyber compliance, and application security. This role is crucial for embedding secure-by-design principles across the technology lifecycle, from solution conception to deployment and operation. The consultant will support the secure adoption of artificial intelligence and emerging technologies, ensuring critical applications like beneficiary management systems are protected. Key responsibilities include conducting risk assessments, designing security architectures, developing security requirements for AI solutions, and advising stakeholders on cybersecurity risks associated with new technologies. The aim is to strengthen WFP's cybersecurity posture, protect information assets, and maintain compliance with organizational standards and industry best practices.
Responsibilities
The Cybersecurity Advisory Consultant will conduct comprehensive risk assessments and lead the Authorization to Operate (ATO) process for IT systems, ensuring security risks are identified, evaluated, and mitigated. This role involves designing and reviewing security architectures for applications, platforms, and cloud services, embedding secure-by-design principles throughout the technology lifecycle. A key responsibility is developing and maintaining security requirements for artificial intelligence (AI) solutions, covering data handling, model security, and infrastructure. The consultant will assess AI use cases to identify risks like data exposure and unauthorized access, recommending proportionate mitigation measures. They will also lead the development and improvement of cybersecurity procedures, methodologies, and governance frameworks to protect organizational assets. Additionally, the role requires researching and proposing innovative technologies to strengthen the cybersecurity posture, providing expert advisory services to various WFP offices, and guiding IT solution owners on designing appropriate security controls and implementing secure software development practices. The consultant will advise on risks associated with emerging technologies like AI and cloud services, maintain records of assessments, and act as a Subject Matter Expert, mentoring junior team members and representing the cybersecurity branch in relevant meetings and meetings.
Work Experience
Requires solid IT security and SDLC expertise, with a strong understanding of AI security concepts, threats, and risk management. Must be able to implement secure-by-design principles and conduct security reviews of AI-enabled solutions. Experience in IT architecture, stakeholder management, and cybersecurity risk assessment is essential. Cloud security architecture and familiarity with compliance frameworks like ISO, NIST, HIPAA, or PCI are also important. Project management skills and experience in multinational organizations are beneficial.
Skills
Cybersecurity risk assessment, Authorization to Operate (ATO) process, Application security architecture, Network security, Secure-by-design principles, AI security, Identity and access management, IT security compliance, Cloud security architecture, Security requirements definition, Vulnerability management, Threat modeling, Security governance frameworks, IT audit, Project management, Stakeholder relationship management, Technical leadership, Mentoring junior team members