Information Security Professional

Information Security Professional

World Bank

June 11, 2026June 18, 2026ChennaiIndia
Job Description
Job Posting Organization:
The World Bank Group is a global partnership of five institutions dedicated to ending extreme poverty, increasing shared prosperity, and promoting sustainable development. Established in 1944, it has grown to include 189 member countries and operates in more than 130 offices worldwide. The organization focuses on providing funding and knowledge to developing countries, working with both public and private sector partners to invest in innovative projects that address urgent global challenges. The World Bank Group is committed to using data, research, and technology to develop effective solutions for its clients.

Job Overview:
The security" style="border-bottom: 1px dotted #007bff !important;">security" style="border-bottom: 1px dotted #007bff !important;">Information Security Professional position at the World Bank Group is designed for individuals who are results-oriented and possess a multi-disciplinary background in information security. This role is situated within the Information Technology Solutions (ITS) Vice Presidential Unit, specifically in the Information Security and Risk Management (ITSSR) unit. The primary goal of this position is to provide technical and architectural information security solutions across the organization. The successful candidate will be responsible for evaluating information security controls in various environments, including web, cloud, AI, mobile, and complex business applications. The role requires a proactive approach to security testing and risk management, ensuring that the World Bank Group's systems are secure and resilient against potential threats.

Duties and Responsibilities:
The Information Security Professional will have a diverse set of responsibilities, including but not limited to: reviewing security architecture evaluations of new systems, creating security test plans based on existing controls, and performing security analyses across different layers of systems such as applications, APIs, operating systems, and databases. The role involves conducting source code reviews, manual testing, and automated vulnerability assessments using various scanners. Additionally, the professional will perform security testing for cloud-based solutions and M365 platform applications, engage in Gray-Box/White-Box security testing, and conduct application security testing on both native and web-based mobile applications. The candidate will also be responsible for maintaining detailed documentation of test procedures and findings, performing AI security testing, and staying updated on emerging trends and technologies in application security testing.

Required Qualifications:
Candidates must possess an Associate's degree or a recognized certificate, along with a minimum of 2 years of relevant experience in information security. A proven understanding of security architecture and requirements for enterprise applications is essential, as is hands-on experience in preparing risk-based test plans and conducting security testing. In-depth knowledge of common security vulnerabilities, particularly those outlined in the OWASP Top 10, is crucial. The ideal candidate will have demonstrated experience in web application security manual testing, source code review, and vulnerability analysis, as well as familiarity with cloud technologies and web application technologies. Industry certifications such as Certified Ethical Hacker (CEH), Hack The Box Certified Penetration Testing Specialist (CPTS), and Information Systems Security Professional (CISSP) are highly preferred.

Educational Background:
The educational background required for this position includes an Associate's degree or a recognized certificate in a relevant field. This foundational education should be complemented by practical experience in information security, particularly in roles that involve security testing and risk management.

Experience:
The position requires a minimum of 2 years of relevant experience in information security, with a focus on security testing and risk management. Candidates should have a proven track record of working with enterprise applications and platforms, as well as hands-on experience in preparing risk-based test plans and conducting security assessments across various layers of information systems.

Languages:
The mandatory language for this position is English. Proficiency in additional languages may be considered an asset but is not required.

Additional Notes:
This is an Extended Term Temporary position with a duration of 1 year. The recruitment is local, meaning preference will be given to applicants authorized to work in the duty station. The World Bank Group emphasizes a culture of urgency, thoughtful risk-taking, and accountability, and is committed to being an equal opportunity and inclusive employer.
Similar Jobs