Job Opportunities

Find jobs near you, whether onsite, hybrid, or remote.
  • Similar Jobs to: Security Analyst/Senior Security Analyst (Infrastructure Security) - ITDSGGR (Contractual)
XX
Security Analyst/Senior Security Analyst (Technical cyber risk management) - ITDSGGR (Contractual)International Monetary FundSeattle, Washington, United States
XX

Security Analyst/Senior Security Analyst (Technical cyber risk management) - ITDSGGR (Contractual)

International Monetary Fund
  • US
    Seattle, Washington, United States
  • US
    Seattle, Washington, United States

About

Job Summary
The Information Technology Department (ITD) at the International Monetary Fund (IMF) is seeking to fill four Security Analyst/Senior Security Analyst (Technical Cyber Risk Management) positions. These roles report to an information security risk manager and focus on managing risks and security assessments for Azure cloud services, IT products, platforms, and complex hybrid architectures. Responsibilities
Senior individual contributor for information security risk management projects. Design and assess controls for high‑demand technical areas such as ERP, IT Service Management, Identity and Access Management, IT Resiliency, Cloud, and others. Map and implement compliance frameworks, manage risk remediation, and report on information security risks. Create road maps to mature or advance Information Security strategies, programs, and controls. Design and enable cyber controls functions and processes. Act as a power user of Cybersecurity GRC solutions, specifically ServiceNow and Archer. Coordinate with technical, business, compliance, risk, and audit teams to deliver solutions. Deliver risk assessments for large‑scale IT implementation projects, including threat modeling, tiering of N‑tier products, and design of infrastructure security controls. Consult on authentication, authorization, and cryptography mechanisms within applications. Advise on hardening of both cloud and non‑cloud application and infrastructure components, including LINUX/Windows servers, web servers, app servers, databases, endpoints, and web application firewalls. Collaborate with security functions (architecture, assurance, offensive security, application security) to apply appropriate risk levels. Maintain impartiality in IT system evaluation and produce unbiased reports on information security risks. Develop implementation plans for new security‑related products and services. Conduct quality assurance reviews of security requirements and train staff on risk management throughout project lifecycles. Define and enhance processes for external security service provider management, including scoping, remediation tracking, and exception management. Identify opportunities to improve business practices or IT security‑related processes. Support governance activities for Identity and Access Management as needed. Perform ad‑hoc responsibilities as required. Minimum Qualifications
Education: Bachelor's degree in information security, computer science, engineering, mathematics, business, or related field with a minimum of 10 years of experience as a technical information security risk manager or information security architect; OR Advanced degree in the same fields with a minimum of 4 years of experience. Certifications: Must hold CISSP or CISM. Preferred certifications include CCSP, Microsoft Certified: Cybersecurity Architect Expert, Microsoft cloud security certifications at the Expert level, GIAC certifications, and offensive security certifications. Experience in a technical cybersecurity risk management function at organizations with security‑related regulatory requirements. Practical use of risk management concepts and principles, including assessment, prioritization, delivery of treatment plans, tracking, reporting, and metrics. Familiarity with NIST SP800‑30, ISO 27001/2, ISO 27005, and COBIT. Embedding security into processes such as SDLC, Project Lifecycle, ITIL, etc. Demonstrated expertise with infrastructure, applications, and database system technologies. Basic IT consultancy skills and ability to deliver security hardening of application and infrastructure components. Ability to balance security demands with business reality and quickly grasp new technologies. Knowledge of security solutions, latest threats, and countermeasures. Proficiency with a broad range of security technologies and depth in specific relevant areas. Soft Skills
Analytical skills for synthesizing inputs and strategic thinking. Clear and compelling verbal and written communication with non‑technical stakeholders. Ability to think laterally and propose complex solutions. Interpersonal skills fostering openness, trust, and effective teamwork. Work well under pressure and meet tight deadlines with high motivation, confidence, integrity, and responsibility. Organized, responsive, and capable of multitasking to achieve results. Excellent relationship management and facilitation skills. Contract Details
This is a one‑year contractual appointment. Contractual appointments are renewable for up to four years of cumulative service, contingent on performance, budget availability, and business need. Equal Opportunity
The IMF is guided by the principle that employment, classification, promotion, and assignment of staff shall be made without discrimination against any person. The IMF welcomes requests for reasonable accommodations for disabilities throughout the selection process.
#J-18808-Ljbffr
  • Seattle, Washington, United States

Languages

  • English
Notice for Users

This job comes from a TieTalent partner platform. Click "Apply Now" to submit your application directly on their site.