job · indexed from ReliefWeb Jobs RSS
Information Security Lead
Médecins Sans Frontières
- Published
- 01 Oct 2026
Organization: Médecins Sans FrontièresClosing date: 18 Oct 2026Location: Any MSF office within +/-3 hours CETContract: Fixed term at 100% position - The term of this assignment is intended to be for a period of two (2) years, nevertheless, the duration of the contract may be subject to the employment regulations and labor laws of the country where the selected candidate is based.Starting date: 15th of November 2026Deadline to apply: 18th of October 2026Compensation and Benefits: MSF practice is to offer the compensation and benefits package in line with the MSF entity offering the contract.I. MSF INTERNATIONALMédecins Sans Frontières (MSF) is an international, independent, medical humanitarian organisation that delivers emergency aid to people affected by armed conflict, epidemics, healthcare exclusion and natural disasters. MSF offers assistance to people based only on need and irrespective of origins, religion, gender or political affiliation. MSF International provides coordination, information and support to the MSF Movement, as well as implements international projects/programmes and initiatives as requested.II. POSITION BACKGROUNDThe Information Systems Management (ISM), one of the international platforms of MSF gathering all the Heads of IT/IS from key MSF entities, has been mandated by MSF’s executive governance body, the Full Excom, to lead the development of an international information systems management strategy seeking to optimise interoperability across MSF in priority areas. The ISM Platform is responsible for setting standards for IT/IS architecture and technology development and aims to promote targeted innovation in information technology/information systems (IT/IS).Critical to this role, and in response to an increasingly complex cyber and global regulatory landscape, the ISM Platform spearheaded the development of a global information security policy framework back in 2020, which has continued to evolve.In its strategic ambitions, the ISM Platform has committed to prioritising information security and incident resilience as a cross-cutting theme across all its initiatives. The role of the Information Security Lead is to develop an effective execution strategy and a programme to improve MSF’s overall information security posture and governance of information security in the movement.III. PLACE IN THE ORGANISATIONThe Information Security Lead will:Report hierarchically to the International Information Systems Coordinator (who chairs the ISM Platform), with functional oversight provided by the ISM PlatformWork closely with the members of the ISM Platform, InfoSec focal points in each section, ISM InfoSec WG, MSF SITS (Shared IT Services) and other MSF stakeholders to ensure the information security initiatives, working group(s) and/or task force(s) created/sponsored/guided by the ISM are all aligned to the evolving needs of the organisation and the ISM’s strategic visionWork in collaboration with the ISM Coordination team to ensure a consistent approach to programme and project management within the ISM portfolio and Working Group (WG) initiativesIV. OBJECTIVES OF THE POSITIONThe Information Security Lead will lead the development of the roadmap for information security governance, risk & compliance in MSF under the guidance of the ISM platform and in close collaboration with the Info Sec WG. The Information Security Lead will provide strategic guidance, operational support, and incident response expertise across headquarters and field missions, balancing security requirements with the realities of medical and humanitarian operations.The Information Security Lead will establish the governance mechanisms necessary to ensure better identification, monitoring and mitigation of information security risks in MSF. This role will recommend planning and allocation of infosec resources, and develop the necessary processes/frameworks to do so.Specific ObjectivesAn effective global information security framework, strategy, and roadmap are in place to guide MSF’s short-, medium-, and long-term security priorities.Priority information security risks are proactively managed through a shared and structured organisational approach.Security incidents requiring intersectional coordination are responded to effectively, limiting impact and supporting resilience.Technical information security decisions across MSF are informed by reliable expert guidance.Sensitive information is managed securely and in line with relevant governance requirements.Organisational information security awareness and capability are strengthened on an ongoing basis.Emerging threats and external developments relevant to MSF are monitored and reflected in a stronger overall security posture.V. KEY RESPONSIBILITIESInformation Security Strategy and GovernanceDevelop, implement, and maintain MSF’s information security strategy and roadmapDefine and maintain information security policies, standards, and proceduresAdvise senior management on information security risks and mitigation options, including new resourcing and delivery modelsSupport definition of mutualised approaches for selected information security capabilities across MSF (e.g. baseline policies/standards, security monitoring / SIEM-SOC options, incident coordination, third-party security assurance, etc.)Contribute to organisational risk management and governance processesRisk ManagementIdentify, assess, and prioritise information security risks in the movementConduct and support information security risk assessments for existing and new initiativesPropose feasible mitigation measuresSupport the documentation and acceptance of residual risksIncident Response and Crisis ManagementLead responses to movement-wide information security incidentsSupport field missions and headquarters during high‐pressure or sensitive incidentsCoordinate with relevant functions (IT, legal, communications, HR, security, etc.)Ensure post‐incident reviews and follow‐up actions are completedTechnical and Operational Security OversightAdvise on matters such as infrastructure, network, cloud, and endpoint securityAdvise on security matters such as identity & access management and remote workingEnsure security requirements are integrated into system design, procurement, and third‐party arrangementsData Protection, Ethics, and SafeguardingAdvise on data classification, minimisation, retention, and secure sharingWork closely with data protection, legal, safeguarding, and other stakeholdersPromote digital practices that minimise risks of harm to individuals and communitiesAwareness and Capacity BuildingDevelop and deliver information security awareness and training programsBuild information security capacity among staffTranslate complex security concepts into clear, practical guidanceCoordination and RepresentationCollaborate closely with all relevant functionsChair the ISM Information Security Working Group sessionsCoordinate with external service providers and security expertsRepresent MSF in relevant information security and humanitarian forumsMonitor emerging threats relevant to humanitarian and medical organisationsVI. REQUIREMENTSEducation:Minimum Bachelor's degree in a technical discipline (Computer Science, Cybersecurity, Information Technology, etc.) or equivalentCertification as a security professional, e.g. Certified Information Systems Security Professional (CISSP) or Certified Information Security Auditor (CISA)Experience and skills:Minimum 7 years’ experience in information security or security risk management.Strong expertise in cloud, network, and cybersecurity, including incident response, vulnerability management, DLP, IDS/IPS, and penetration testing.Good knowledge of security frameworks, risk management, and compliance requirements (e.g. NIST, ISO 27001, CIS, GDPR, PCI DSS).Experience developing security policies, standards, and enterprise solutions in complex, decentralised, and international environments.Knowledge of business continuity and disaster recovery.Strong leadership, communication, analytical, and cross-cultural collaboration skills, with high ethical standards and alignment with MSF values.Languages:Fluent spoken and written EnglishOther:International travel may be required a few times a yearOccasional availability outside normal working hours during incidentsOnly shortlisted candidates will be contacted.At MSF, we are committed to an inclusive culture that encourages and supports the diverse voices of our employees. We welcome applications from individuals of all genders, ages, sexual orientations, nationalities, races, religions, beliefs, ability status, and all other diversity characteristics.MSF is committed to preventing abuse, inappropriate behaviour, lack of integrity and financial misconduct in its work and care spaces. MSF expects all staff to share this commitment and promote an environment where abuse and misconduct is not tolerated.We are committed to removing barriers for people with specific accessibility needs. If you need an adjustment to the recruitment process to be considered for the role, please let us know from the beginning of the selection process.Note: All offers of employment will be subject to reference checks and to appropriate screening checks. By submitting an application, the job applicant confirms his/her/their understanding of these recruitment procedures.How to applyApply here
Provenance
- Publisher
- ReliefWeb Jobs RSS
- Source system
- ReliefWeb Jobs RSS — Official API or feed
- Verification
- Verified — the publisher's own channel
- Published
- — stated by the source
- Last seen at source
- Indexed by GLODA
- Last updated
- Record version
- c1e8032bc963
How GLODA knows this — Source-backed · 1 fieldData quality: Source-backed
| Field | How we know | State | Confidence |
|---|---|---|---|
| Publication date | Official API or feed | Data quality: Source-backed | 100 |
- Source
- ReliefWeb Jobs RSS · Official API or feed · official-feed
- Retrieval
- seen · indexed
- Record
- c1e8032bc963 · source id https://reliefweb.int/job/4232205/information-security-lead
- Computed
- provenance-v1
States describe GLODA's confidence in its own fields, never a judgement on the notice or its parties. Methodology
Open this job in the GLODA terminal
The notice above is the public record. Signing in adds the analysis: saved views and alerts on searches like this one, workflow and pipeline, exports and full workspace tooling.