Security Governance Consultant

vor 12 Stunden


Fribourg, Schweiz Vector Synergy Vollzeit

**Location**:
Geneva, Switzerland

**Introduction**:
United Nations International Computing Centre (UNICC), within its Cybersecurity Division, seeks a Security Governance Consultant to facilitate the execution of internal or external projects.

**Skills, knowledge, experience required**:

- A university degree (a Bachelors’ Degree) in computer science, information systems, mathematics, statistics or a related field, or equivalent experience;
- Minimum 10 years’ professional experience in information security, risk management, IT security, security incident response or security testing-related jobs;
- Experience in:

- Developing information security policies and procedures;
- Executing programmes successfully;
- Managing/working in large ICT programmes;
- Producing technical documentation including user requirement documents, proposals in response to project requirements;
- Drafting processes and procedures documentation;
- Working with MS Office tools and MS Project;
- Experience with medium/complex size projects;
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT, etc.;
- Ability to:

- Understand technical and business aspects of IT risk and communicate those risks to management, business, and technical units so that the organization can make informed decisions regarding appropriate levels of information security control;
- Act calmly and competently in high-pressure, high-stress situations;
- Professionally handle confidential matters and show an appropriate level of judgment and maturity;
- Strong analytical and problem-solving skills;
- Excellent written and verbal communication, interpersonal, and collaborative skills;
- High level of personal integrity;
- High degree of initiative, dependability and ability to work with little supervision;
- Expert knowledge of English (oral and written).

**Desirable**:

- 3 years’ experience working in security consulting engagements;
- Experience in achieving and maintaining ISO 27001 certification;
- Project management skills with the ability to manage multiple projects under strict timelines;
- Certifications such as:

- Certified Information Security Manager (CISM);
- Certified in Risk and Information Systems Control (CRISC);
- Certified in the Governance of Enterprise IT (CGEIT);
- Certified Information Systems Security Professional (CISSP);
- Knowledge of another UN language.

**Duties/role**:

- Developing, implementing, and monitoring strategic comprehensive enterprise information security and IT risk management programmes to ensure that the integrity, confidentiality, and availability of information is managed and controlled by the client organizations;
- Providing regular reporting on the current status of the information security program to Senior Management and business units as part of a strategic enterprise risk management program;
- Implementing governance programmes including an information security steering committee or advisory board;
- Creating, communicating, and implementing process for risk management, including the assessment and treatment of identified risks, working directly with business units and stakeholders throughout the organization on identifying acceptable levels of residual risk, and reporting and overseeing treatment efforts;
- Creating and managing information security and risk management awareness training programmes for all employees, contractors, and approved system users;
- Developing, maintaining, and publishing up-to-date information security policies, standards, and guidelines, as well as overseeing the approval, training, and dissemination of security policies and practices;
- Developing and enhancing an information security management framework based on the ISO 27000 standards, and creating a framework for roles and responsibilities with regard to information ownership, classification, accountability, and protection;
- Coordinating information security and risk management projects and providing strategic risk guidance for IT projects;
- Managing security incidents and events to protect corporate IT assets, including intellectual property, sensitive data, and the organization’s reputation;
- Monitoring the external threat environment for emerging threats and advising relevant stakeholders on the appropriate courses of action;
- Developing and overseeing effective disaster recovery policies and standards, coordinating the development of implementation plans and procedures to ensure that business-critical services are recovered in the event of a security event, and providing direction, support, and in-house consulting in these areas;
- Liaising among external and internal stakeholders, including audit, legal, and HR management teams as required, to ensure that the organization maintains an appropriate security posture;
- Managing Information Security Specialists and Consultants;
- Performing other related duties and fulfilling responsibilities as required.

VECTOR S



  • Fribourg, Schweiz iptiQ Vollzeit

    **About Swiss Re** Swiss Re is one of the world’s leading providers of reinsurance, insurance and other forms of insurance-based risk transfer, working to make the world more resilient. We anticipate and manage a wide variety of risks, from natural catastrophes and climate change to cybercrime. Combining experience with creative thinking and cutting-edge...

  • Security Engineer

    vor 4 Wochen


    Fribourg, Schweiz badenova Vollzeit

    Du hast Lust darauf...die Architektur, Planung und Konzeptionierung von Netzwerk-Security-Lösungen zu übernehmen und dabei maßgeblich zur Sicherheit unserer IT-Landschaft beizutragenals kompetenter Consultant (m/w/d) für interne und externe Stakeholder zu agieren und Dein Fachwissen in Projekten einzubringenunsere Netzwerk-Security-Services...

  • Security Engineer

    vor 4 Wochen


    Fribourg FR, Schweiz badenova Vollzeit

    Du hast Lust darauf...die Architektur, Planung und Konzeptionierung von Netzwerk-Security-Lösungen zu übernehmen und dabei maßgeblich zur Sicherheit unserer IT-Landschaft beizutragenals kompetenter Consultant (m/w/d) für interne und externe Stakeholder zu agieren und Dein Fachwissen in Projekten einzubringenunsere Netzwerk-Security-Services...

  • Associate Partner

    vor 2 Wochen


    Fribourg, Schweiz Kyndryl Switzerland GmbH Vollzeit

    **Why Kyndryl** At Kyndryl our people are the basis of everything we do, we believe skills drives growth, so we invest in our employees. We want to be known as being fast, flat and focused in how we operate, and we want our people to feel they can be their true self when working for Kyndryl. We design, build, manage and modernize the mission-critical...


  • Fribourg, Schweiz API S.A. Vollzeit

    What if you were the person we've been waiting for? Today we are looking for an Infrastructure Engineer to join us in Fribourg. Your responsibilities: On-Premises & Virtual Infrastructure - Design, install, configure and maintain Citrix environments, including XenApp, XenDesktop, StoreFront, NetScaler and Provisioning Services both on-premise and cloud. -...

  • Security Consultant

    vor 12 Stunden


    Fribourg, Schweiz ROCKEN Vollzeit

    Die ROCKEN Partnerin ist eine führende Anbieterin von Services im Dokumentenmanagement mit Fokus auf neue Digitalisierung und neue Technologien. Mit einer globalen Präsenz in mehr als 20 Ländern bietet sie Dienstleistungen für Kunden aus verschiedenen Branchen wie Versicherungen, Banken sowie aus anderen Dienstleistungssektoren. Ob technische, fachliche...


  • Fribourg, Schweiz Hays Vollzeit

    **Meine Aufgaben** - Sie haben die gesamtverantwortliche Betreuung der strategischen Partnern inne - Sie identifizieren und gewinnen neue Partner bzw. begleiten den Ausbau der vorhandenen Partnerlandschaft - Sie positionieren das gesamtes Hersteller - und Service Portfolio am Markt - Sie sind zuständig für die Analyse von Wachstums - und Cross Selling...

  • M365 Consultant

    vor 4 Wochen


    Fribourg, Schweiz badenova Vollzeit

    Du hast Lust darauf... Geschäftsprozesse und Anforderungen zu analysieren und darauf basierend innovative IT-Lösungen zu konzipieren Kunden zu komplexen digitalen Lösungen im Microsoft Cloud- und Hybrid-Umfeld beraten und maßgeschneiderte Umsetzungsstrategien entwickeln Beratungs- und Design-Workshops mit Kunden durchzuführen, sowie Konzepte zu...


  • Fribourg, Schweiz KPMG Vollzeit

    Do you have experience in the financial sector and want to take action against financial crime and fraud? As a future member of our regulation team, you will advise financial service providers in particular on a wide range of regulatory issues with a focus on fraud prevention issues. Zurich Immediately or by appointment 100 % Your contribution to...


  • Fribourg, Schweiz Avanade Vollzeit

    Who are we? Talent Community Analytics The roles are very broad in the Analytics Talent Community. From data analysts and data engineers to IoT and AI experts, there are many overlaps on the one hand, but also many unique selling points on the other hand. As a talent community, we see ourselves as a melting pot to bring these areas of expertise in one team...