Job Posting Organization: The United Nations Office on Drugs and Crime (UNODC) is a global leader in the fight against illicit drugs and international crime. Established in 1997, UNODC aims to assist Member States in their efforts to combat drug trafficking, organized crime, and corruption, while promoting justice and the rule of law. The organization operates in over 150 countries and employs thousands of professionals dedicated to these causes. UNODC's mission is to strengthen the rule of law and promote human rights, ensuring that justice systems are fair, humane, and accountable.
Job Overview: The National Consultant - ICT Systems security" style="border-bottom: 1px dotted #007bff !important;">Security Expert will play a crucial role in enhancing the cybersecurity posture of the Judiciary in Kenya. This position involves conducting a comprehensive assessment of the current ICT systems, identifying vulnerabilities, and implementing a robust training program for various stakeholders within the Judiciary. The consultant will be responsible for developing a security by design capacity-building model aimed at empowering system developers, administrators, and network engineers with the necessary skills to secure digital justice infrastructure. The consultant will also facilitate capacity-building training sessions, focusing on secure development practices, incident response, and cybersecurity awareness, thereby ensuring that the Judiciary's ICT workforce is well-equipped to handle cyber threats effectively. The expected duration of the assignment is 30 working days, from October 1 to November 30, 2025.
Duties and Responsibilities: The consultant will undertake several key responsibilities, including:
Conducting an inception meeting with Judiciary stakeholders to finalize the scope, timelines, and methodology of the project.
Developing and delivering capacity-building training sessions for four distinct groups: developers/database administrators, cybersecurity teams, system administrators, and network administrators.
Providing specialized training on secure system development, data center security, secure software development lifecycle reviews, and data privacy compliance.
Training cybersecurity teams on ethical hacking, system audits, and incident response planning.
Equipping system administrators with skills in server and infrastructure hardening, cloud security, and container security.
Training network administrators on network security architecture, including firewalls, IDS/IPS, and Zero Trust Architecture recommendations.
Preparing and submitting an inception report to UNODC detailing the findings and proposed training methodologies.
Required Qualifications: Candidates must possess an advanced university degree in Cybersecurity, Computer Science, Computer Engineering, or a related field. A first-level university degree in Civil Engineering or similar fields, combined with two additional years of qualifying experience, may be accepted in lieu of the advanced degree. Additionally, candidates should have a minimum of five years of progressively responsible professional experience in ICT Security/cybersecurity, with a strong background in penetration testing, vulnerability assessments, and enterprise security documentation. Experience in developing Business Continuity Plans and Disaster Recovery is desirable, as is experience in designing and delivering employee security awareness training.
Educational Background: An advanced university degree (Master’s or equivalent) in Cybersecurity, Computer Science, Computer Engineering, or a related field is required. Alternatively, a first-level university degree in Civil Engineering or similar fields, combined with two additional years of qualifying experience, may be accepted in lieu of the advanced university degree.
Experience: Candidates should have at least five years of progressively responsible professional experience in ICT Security/cybersecurity. This includes experience in penetration testing, vulnerability assessments, and administration of IDS/Firewalls/VPNs. Experience in enterprise security documentation and developing employee security awareness training is also required. Familiarity with Business Continuity Plans and Disaster Recovery processes is desirable.
Languages: Fluency in oral and written English is required for this position. Knowledge of French and other United Nations Secretariat languages is considered an advantage, as English and French are the working languages of the United Nations Secretariat.
Additional Notes: The position is a consultancy role with an expected duration of 30 working days, from October 1 to November 30, 202
The United Nations does not charge a fee at any stage of the recruitment process, including application, interview, or training. The organization is committed to ensuring a fair and transparent recruitment process.
Info
Job Posting Disclaimer
This job posting is provided for informational purposes only. The accuracy of the job description, qualifications, and other details mentioned is the sole responsibility of the employer or the organization listing the job. We do not guarantee the validity or legitimacy of this job posting. Candidates are advised to conduct their own due diligence and verify the details directly with the employer before applying.
We are not liable for any decisions or actions taken by applicants in response to this job listing. By applying, you agree that all application processes, interviews, and potential job offers are managed exclusively by the listed employer or organization.
Beware of fraudulent job offers. Do not provide sensitive personal information or make any payments to secure a job.