Associate Cybersecurity Operations Officer (DevSecOps)

28 September, 2022

...

Position Summary

Job CategoryVacancy
Vacancy Notice NumberICC/22/VAL/745
Position TitleAssociate Cybersecurity Operations Officer (DevSecOps)
Position TypeTemporary
Number of Positions1
Date of Issue28/09/2022
Date of Closing19/10/2022
GradeP2
Annual Salary EstimationUSD 61,863 (net, single rate, including post adjustment)
Duty StationValencia, Spain
Organizational Location/UnitCybersecurity Operations Unit (CSO)

Position Description

The UNICC workforce consists of many diverse nationalities, cultures, languages and opinions. UNICC seeks to sustain and strengthen this diversity by ensuring equal opportunity and an inclusive working environment for its entire workforce. Applications are encouraged from all qualified candidates from any race, ethnicity, sex, national origin, age, religion, disability, sexual orientation and gender identity.

Purpose of the Position:

Provide front line support to UNICC’s Partners in the area of information/cyber security and risk management consulting and in security operations activities in collaboration with a team of information and cyber security professionals who collaborate with multiple UN agencies, IT professionals, and International Organizations.

Objectives of the Programme:

The objectives of the Centre, as stated by its mandate, are to provide information and communication technology (ICT) services (including training) on an inter-organizational basis.

Main duties and responsibilities:

The incumbent will work under the direct supervision and guidance of the Head of Cybersecurity Operations within the Cybersecurity Operation division. The incumbent could be requested to do any others tasks of similar level in related fields:

  • Under guidance, perform cybersecurity architecture review of new or existing technical solutions
  • Provide code review across all platforms and consultations for developers to ensure appropriate processes and considerations are integrated in SDLCs (topics can cover authentication, authorization, encryption, logging, and more)
  • Contribute to develop policies, security standards and procedures for a variety of security technologies and related controls
  • Identify and share of the discovering of security vulnerabilities and propose  mitigation plans and tooling, including libraries and frameworks
  • Support a diverse environment including customer facing applications and large-scale data processing infrastructure and APIs
  • Implement and produce KPIs for cybersecurity operations capabilities
  • Prepare presentations as well as technical reports for different type of audience
  • Contribute to the identification and promotion of security champions inside developers’ team
  • Provide other ad hoc support either within Operational Excellence Unit or other units as required — this includes the participation in special projects or support to service deliver for short period of time basis upon request from the senior management

Recruitment Profile

Experience and Skills required:

Essential:

  • A minimum of three (3) years of relevant experience in one or more of the following fields:

  • Delivering an end-to-end automation of deployment, monitoring and infrastructure management in a cloud environment
  • Experience in planning, researching, and developing security standards and procedures
  • Experience and expertise in application and security testing technologies including static code analysis and dynamic analysis
  • Experience in building and configurating delivery environments supporting CD/CI tools
  • Experience in securing Kubernetes and related orchestration technologies
  • Proven programming/scripting skills in of these languages Python, Java, or .Net
  • Experience with CI/CD tools
  • Experience in using Git and GitFlow
  • Knowledge and experience with OWASP top 10 and SANS CWE 25

Desirable:

  • Experience in developing, documenting, and implementing CI/CD strategy for management of Infrastructure as Code baseline
  • Familiarity with API security, container security, AWS cloud security, Azure DevOps
  • Knowledge in attack simulation and vulnerability management using automated and manual processes

Education*:

Essential:

  • First university degree in Computer Engineering, Computer Science, or any related field
  • At least one of the following technical certifications: OSCP, network security (Cisco, Fortinet, Palo Alto, etc.)

Languages:

  • English: Expert knowledge is required
  • Spanish: Beginner knowledge is desirable

UNICC Global Competencies:

  • Teamwork: Develops and promotes effective relationships with colleagues and team members. Deals constructively with conflicts.
  • Communicating: Expresses oneself clearly in conversations and interactions with others; listens actively. Produces effective written communications. Ensures that information is shared.
  • Respecting and promoting individual and cultural differences: Demonstrates the ability to work constructively with people of all backgrounds and orientations. Respects differences and ensures that all can contribute.
  • Producing results: Produces and delivers quality results. Is action oriented and committed to achieving outcomes.
  • Moving forward in a changing environment: Is open to and proposes new approaches and ideas. Adapts and responds positively to change.

Other Information

Compensation:

Annual Salary Estimation (net of tax at single rate): 

  • Valencia, (Spain), including post adjustment (25.6% on September 2022): US$ 61,863.

UNICC also offers generous leave and absence allowances, flexible working hours, overtime compensation, teleworking, access to training, and depending on eligibility other benefits such as relocation grant, dependency allowance, language allowance, or education grant.

Closing date for applications:

Applications will be accepted until midnight (Geneva Time) on 19th October 2022.

Notes:

  • Technical and/or personality tests may be carried out as part of the selection process
  • Only short-listed candidates will be contacted
  • Though you may not be selected for this advertised position, the UNICC will keep your application in a roster if your profile is deemed to be of potential interest for the Centre. You may thus be solicited by our HR department to participate in an interview for another position

* For UNICC staff members who do not meet the minimum educational qualifications, please refer to the applicable WHO e-Manual Annex 6 – Guidelines on Standard Minimum Experience Exposure and Education Requirements

The UNICC workforce consists of many diverse nationalities, cultures, languages and opinions. UNICC seeks to sustain and strengthen this diversity by ensuring equal opportunity and an inclusive working environment for its entire workforce. Applications are encouraged from all qualified candidates from any race, ethnicity, sex, national origin, age, religion, disability, sexual orientation and gender identity. 

Apply Online

A valid email address is required.