This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Supporting the ‘AD, Senior Risk Officer, Information Security’, in the management and technical aspects of Information Security (IS) across the EBRD; Information Security Consultant will be responsible for helping to deliver key IS (and Cybersecurity) projects and performing risk identification and mitigation activities.
Job Responsibility:
Supporting the ‘AD, Senior Risk Officer, Information Security’, in the management and technical aspects of Information Security (IS) across the EBRD
Identify, mitigate and managing IS and Cybersecurity risks posed to the EBRD and its clients
Provide independent IS and Cybersecurity oversight, technical assessment and consultancy in accordance with good practice
Assess and advise on technical risk mitigation measures, review identified risks, analyse security incidents and communicate risk mitigation actions, plans and activities to management and peers for strategic decision-making
Act as the primary Subject Matter Expert (SME) for Risk Management on Cybersecurity oversight and assurance
Work closely with the IT Department on technical aspects of IS and Cybersecurity risk
Pro-actively encourage ‘good’ IS practice across the Bank, as embodied in ISO27001 and NIST
Author IS policies and procedures
Project manage elements of the Bank’s Business-As-Usual (BAU) activities
Perform detailed risk assessments of the Bank’s information assets and IT Facilities using industry accepted methodologies
Design and undertake risk assessments related to the Bank’s Cybersecurity Resilience Programme
Undertake Business Impact Assessments and Information Security risk assessments across the business
Be accountable for compliance to regulatory, statutory and contractual Information Security requirements
Track risk mitigation actions
Perform oversight of first-line (IT) remediation activities
Develop and enhance the Bank’s InfoSec Framework
Develop and enhance the Bank’s InfoSec risk reporting
Work with external security consultants and consultancies
Requirements:
Bachelor's Degree (2:1 or equivalent)
Hold at least one industry recognised security qualification/accreditation (CISM, CISA, CISSM, ISO 27001 Lead Auditor/Implementer)
Knowledge of Information and IT Security Frameworks, in particular NIST and ISO27001
Excellent report writing, communication and presentation skills are a must
Ability to take technical information and present in risk and business language is a must
Good project management skills, ability to develop well thought out solutions and have strong relationship management skills are a must
Effective communication skills and the ability to influence challenge and engage EBRD people at all levels are essential
Strong written and spoken communication skills in English language
Able to work autonomously
Good attention to detail and accuracy
Strong presentation skills
Ability to guide projects to apply appropriate security standards and policies
Working knowledge of technologies and tools to drive observability and infrastructure insight (monitoring / telemetry / logging)
Nice to have:
Good technical knowledge of the following is desirable: secure email, cloud & network security data leakage controls, identity and access management
Ethical hacking background is advantageous
What we offer:
Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts
A working culture that embraces inclusion and celebrates diversity
An environment that places sustainability, equality and digital transformation at the heart of what we do
The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, sexual orientation or disabilities
As an inclusive employer, we promote flexible working and expecting our employee to attend the office 50% of their working time