Information Security Lead

Information Security Lead

Médecins Sans Frontières (MSF)

October 3, 2026November 17, 2026GenevaSwitzerland
Job Description
Job Posting Organization:
Médecins Sans Frontières (MSF) is an international, independent, medical humanitarian organization that provides emergency aid to individuals affected by armed conflicts, epidemics, healthcare exclusion, and natural disasters. Established to deliver assistance based solely on need, MSF operates without regard to origins, religion, gender, or political affiliation. The organization is dedicated to providing coordination, information, and support to the MSF Movement, as well as implementing international projects and initiatives as required. MSF has a global presence, with numerous offices and operations in various countries, employing thousands of staff members who are committed to humanitarian principles and the mission of delivering medical aid to those in need.

Job Overview:
The security" style="border-bottom: 1px dotted #007bff !important;">security" style="border-bottom: 1px dotted #007bff !important;">Information Security Lead position is a critical role within the Information Systems Management (ISM) platform of MSF, which is responsible for developing and implementing an international information systems management strategy. This strategy aims to enhance interoperability across MSF's various entities. The ISM Platform has been tasked with setting standards for IT and information systems architecture and technology development, while also promoting innovation in these areas. Given the increasing complexity of the cyber landscape and global regulatory requirements, the ISM Platform has developed a global information security policy framework that continues to evolve. The Information Security Lead will be responsible for creating an effective execution strategy and program to enhance MSF's overall information security posture and governance. This role will involve providing strategic guidance, operational support, and incident response expertise across both headquarters and field missions, ensuring that security requirements are balanced with the realities of medical and humanitarian operations.

Duties and Responsibilities:
The Information Security Lead will have a variety of key responsibilities, including: developing, implementing, and maintaining MSF's information security strategy and roadmap; defining and maintaining information security policies, standards, and procedures; advising senior management on information security risks and mitigation strategies; supporting the definition of mutualised approaches for selected information security capabilities across MSF; identifying, assessing, and prioritizing information security risks; conducting risk assessments for existing and new initiatives; leading responses to information security incidents; advising on infrastructure, network, cloud, and endpoint security; ensuring security requirements are integrated into system design and procurement; promoting digital practices that minimize risks; developing and delivering information security awareness and training programs; and collaborating with relevant functions and external service providers.

Required Qualifications:
Candidates must possess a minimum of a Bachelor's degree in a technical discipline such as Computer Science, Cybersecurity, or Information Technology, or an equivalent qualification. Additionally, certification as a security professional, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Auditor (CISA), is required. Candidates should have a strong understanding of security frameworks, risk management, and compliance requirements, as well as experience in developing security policies and standards in complex, decentralized environments. Strong leadership, communication, analytical, and cross-cultural collaboration skills are essential, along with a commitment to MSF's ethical standards and values.

Educational Background:
The educational background required for this position includes a minimum of a Bachelor's degree in a relevant technical field, such as Computer Science, Cybersecurity, or Information Technology. Candidates are also expected to hold professional certifications in information security, which demonstrate their expertise and commitment to the field.

Experience:
The position requires a minimum of 7 years of experience in information security or security risk management. Candidates should have strong expertise in cloud, network, and cybersecurity, including incident response, vulnerability management, data loss prevention (DLP), intrusion detection/prevention systems (IDS/IPS), and penetration testing. Experience in developing security policies, standards, and enterprise solutions in complex, decentralized, and international environments is also essential.

Languages:
Fluency in spoken and written English is mandatory for this position. Proficiency in additional languages may be considered an asset, but English is the primary language of communication within MSF.

Additional Notes:
This is a fixed-term position at 100%, with a contract duration intended for two years, subject to the employment regulations and labor laws of the country where the selected candidate is based. The starting date for this position is set for the 15th of November 202
  • International travel may be required a few times a year, and candidates should be prepared for occasional availability outside normal working hours during incidents. Compensation and benefits will be aligned with MSF's practices and the entity offering the contract.
Apply now
Similar Jobs