Cybersecurity Consultant - Threat Exposure & Vulnerability Management Specialist

Cybersecurity Consultant - Threat Exposure & Vulnerability Management Specialist

World Food Programme (WFP)

October 10, 2026November 10, 2026RomeItaly
Job Description
Job Posting Organization:
The World Food Programme (WFP) is the world’s largest humanitarian organization, dedicated to saving lives in emergencies and using food assistance to build pathways to peace, stability, and prosperity for people recovering from conflict, disasters, and extreme weather shocks. Established in 1961, WFP operates in over 80 countries, employing thousands of staff members who work tirelessly to ensure effective humanitarian assistance reaches millions of people globally. WFP is committed to diversity and inclusion, encouraging qualified candidates from all backgrounds to apply, and it has been recognized as a 2020 Nobel Peace Prize Laureate.

Job Overview:
The Cybersecurity Consultant - Threat Exposure & Vulnerability Management Specialist will play a crucial role in enhancing WFP's cybersecurity posture by leading initiatives focused on threat exposure and vulnerability management. This position involves coordinating adversarial validation activities such as penetration testing and threat exposure assessments to identify and assess exploitable vulnerabilities within the organization's IT infrastructure. The consultant will work closely with various teams to integrate findings into existing processes, ensuring that vulnerabilities are prioritized and addressed in alignment with business objectives. The role requires continuous monitoring and refinement of validation practices to minimize organizational risk and enhance overall security" style="border-bottom: 1px dotted #007bff !important;">security effectiveness.

Duties and Responsibilities:
The main responsibilities of the Cybersecurity Consultant include designing and coordinating adversarial validation activities, such as penetration tests and threat exposure assessments, to identify detection gaps and exploitable vulnerabilities. The consultant will validate findings to confirm exploitability and assess risk levels, guiding the prioritization of remediation efforts. Collaboration with relevant teams is essential to ensure timely mitigation of validated vulnerabilities. The consultant will also develop clear reports and dashboards that communicate key findings, including critical vulnerabilities and remediation progress, to stakeholders. Continuous refinement of validation techniques based on emerging threats and vulnerabilities is expected, as well as prioritizing vulnerabilities based on risk assessments and coordinating team efforts accordingly. Additional cybersecurity-related duties may be assigned as needed.

Required Qualifications:
Candidates must possess a University Degree in Information Technology, Information Systems, Cybersecurity, or related fields, or a combination of relevant education and experience. A minimum of 5-7 years of experience in cybersecurity, particularly in vulnerability management and threat exposure management, is required. Candidates should have sound IT security skills, both academic and practical, with an in-depth understanding of vulnerability management frameworks and best practices. Familiarity with security concepts such as threat modeling and risk-based decision-making is essential, along with experience in penetration testing and adversarial emulation activities. Previous experience in international or UN environments is valued but not essential. IT Audit and/or PM certifications are desirable, though equivalent hands-on experience is equally appreciated. Strong organizational and communication skills are also necessary.

Educational Background:
A University Degree in Information Technology, Information Systems, Cybersecurity, or related fields is required. Candidates with a combination of relevant education and experience may also be considered. The educational background should provide a solid foundation in IT security principles and practices, enabling the candidate to effectively manage vulnerabilities and threats.

Experience:
Candidates should have at least 5-7 years of experience in the field of cybersecurity, with a specific focus on vulnerability management and threat exposure management. This experience should include practical hands-on work in identifying and mitigating cybersecurity risks, as well as familiarity with various tools and processes related to vulnerability scanning and remediation workflows. Experience in international or UN environments is a plus, but not mandatory.

Languages:
Fluency in English (level C) is mandatory for this position. Additionally, intermediate knowledge (level B) of a second official UN language is desirable, which may include Arabic, Chinese, French, Russian, Spanish, or Portuguese, WFP’s working language. Proficiency in multiple languages can enhance communication and collaboration within the diverse WFP environment.

Additional Notes:
This position is a Regular Consultant (CST2) role with a duration of 11 months. The duty station is remote, allowing for flexibility in work location. WFP offers an attractive compensation package and is committed to providing a diverse and inclusive work environment. The organization emphasizes the importance of personal and professional development through various training and mentorship programs. All applications must be submitted through WFP's online recruiting system, and candidates are advised to ensure their profiles are complete and accurate before applying.
Apply now
Similar Jobs