CYBERSECURITY ADVISORY CONSULTANT (IAM & Endpoint Protection)

CYBERSECURITY ADVISORY CONSULTANT (IAM & Endpoint Protection)

World Food Programme (WFP)

September 13, 2026October 13, 2026RomeItaly
Job Description
Job Posting Organization:
The World Food Programme (WFP) is the world’s largest humanitarian organization, established to save lives in emergencies and to use food assistance as a means to build pathways to peace, stability, and prosperity for individuals recovering from conflict, disasters, and the impacts of climate change. WFP operates in numerous countries around the globe, employing thousands of individuals who are dedicated to its mission. The organization emphasizes diversity and inclusion, ensuring equal employment opportunities for all employees, regardless of race, gender, or background. WFP is also recognized for its commitment to professional development, offering various training and mentorship programs to enhance the skills of its workforce. The organization was awarded the Nobel Peace Prize in 2020, highlighting its significant contributions to humanitarian efforts worldwide. For more information, visit their website at https://www.wfp.org and follow them on social media platforms.

Job Overview:
The Cybersecurity Advisory Consultant will play a crucial role in enhancing the cybersecurity posture of the World Food Programme. This position involves conducting consulting activities under the supervision of the Chief security" style="border-bottom: 1px dotted #007bff !important;">security" style="border-bottom: 1px dotted #007bff !important;">Information Security Officer and the Head of Cybersecurity Advisory Services. The consultant will be responsible for a range of tasks including conducting risk assessments, leading the Authorization to Operate (ATO) process, and ensuring compliance with cybersecurity standards. The role requires a deep understanding of security architecture, identity and access management, and endpoint protection. The consultant will also be expected to provide expert guidance on integrating security controls into various technology initiatives, ensuring that security measures are embedded by design. This position is vital for protecting the organization's information assets and ensuring that effective cybersecurity strategies are implemented across all levels of the organization.

Duties and Responsibilities:
  • Conduct comprehensive risk assessments and lead the Authorization to Operate (ATO) process for IT systems and services, ensuring that security risks are appropriately identified, evaluated, documented, mitigated, and communicated to relevant stakeholders.
  • Design, review, and oversee the security architecture of new and existing applications, platforms, cloud services, and technology initiatives, ensuring that appropriate security controls are embedded by design and aligned with organizational policies, data classification requirements, and industry best practices.
  • Assess and strengthen identity and access management controls across applications, cloud services, and enterprise platforms, including authentication, authorization, privileged access, access lifecycle management, and periodic access reviews.
  • Define and review endpoint protection requirements and security baselines for corporate endpoints, mobile devices, and other managed devices, addressing device compliance, configuration hardening, threat protection, encryption, and security monitoring.
  • Provide security guidance on the integration of identity and endpoint controls, ensuring that access decisions appropriately consider user identity, device security posture, privilege level, and information sensitivity.
  • Lead the development, implementation, and continuous improvement of cybersecurity procedures, services, methodologies, and governance frameworks aimed at protecting organizational information assets, systems, and services.
  • Research, evaluate, and propose innovative technologies, security capabilities, and process improvements that strengthen the cybersecurity posture of the organization while demonstrating measurable business value and operational effectiveness.
  • Propose and maintain new security standards, procedures, and guidelines to help raise the current security maturity level of the organization.
  • Provide expert cybersecurity advisory services and technical guidance to Country Offices, Regional Bureaus, and HQ divisions to address cybersecurity challenges and maintain compliance with organizational security standards. 1
  • Advise stakeholders on cybersecurity risks associated with emerging technologies, including cloud services, artificial intelligence, software-as-a-service (SaaS), digital transformation initiatives, and data-driven solutions. 1
  • Maintain a record of decisions taken and assessments performed, in cooperation with other members of the Advisory team. 1
  • Identify and execute improvements to existing processes, through solutions to address recurring problems and enhancements to existing solutions or documentation. 1
  • Act as Subject Matter Expert (SME) for assigned technologies, platforms, business applications, and cybersecurity domains. 1
  • Prepare and present high-quality reports, risk assessments, executive briefings, architecture recommendations, and management updates tailored to technical and business audiences. 1
  • Mentor, coach, and provide technical leadership to junior team members, contributing to knowledge sharing, capability development, and continuous improvement within the Advisory team. 1
  • Represent the Cybersecurity Branch in meetings, working groups, steering committees, audits, assessments, and enterprise initiatives as required. 1
  • Perform additional duties and responsibilities as required in support of TECI Cybersecurity objectives.

Required Qualifications:
Candidates must possess a degree in Computer Science, Engineering, or related STEM disciplines, or equivalent working experience. A solid foundation in IT security, including both academic and professional experience, is essential. Candidates should have strong knowledge of Identity and Access Management (IAM) technologies and concepts, as well as experience with endpoint protection technologies and security controls. Familiarity with IT architecture and design concepts is also required, along with the ability to manage stakeholder relationships effectively. Knowledge of cybersecurity risk concepts, project management skills, and experience in multinational organizations are highly desirable. Relevant IT Security and IT Audit certifications are a plus, as is experience with compliance processes such as ISO, NIST, HIPAA, or PCI.

Educational Background:
A degree in the field of Computer Science, Engineering, or related STEM disciplines is required. Equivalent working experience may also be considered in lieu of formal education. Candidates should have a strong academic background in IT security and related fields, demonstrating a commitment to ongoing professional development and learning.

Experience:
At least 6 years of relevant work experience in the field of cybersecurity is required. Candidates should have a proven track record of successfully implementing security measures and managing cybersecurity risks in a professional setting. Experience in multinational organizations is preferred, as it demonstrates the ability to navigate complex environments and collaborate with diverse teams.

Languages:
Fluency in oral and written English is mandatory. Additionally, an intermediate knowledge of another official UN language (Arabic, Chinese, French, Russian, or Spanish) or Portuguese, which is one of WFP’s working languages, is desirable. Proficiency in multiple languages will enhance communication and collaboration within the organization and with international partners.

Additional Notes:
This position is a Consultant Level II role with a contract duration of 11 months. The duty station is remote, allowing for flexibility in work arrangements. The World Food Programme emphasizes the importance of diversity and inclusion in its workforce and is committed to providing reasonable accommodations for individuals with disabilities throughout the recruitment process. The organization does not charge any fees in connection with the application or recruitment process, ensuring that all candidates have equal access to opportunities. Selected candidates will undergo rigorous reference and background checks to ensure compliance with WFP's standards.
Apply now
Similar Jobs