Digital Security Lead (Consultant Role) jobs in United States
info-icon
This job has closed.
company-logo

Global Initiative against Transnational Organized Crime · 3 months ago

Digital Security Lead (Consultant Role)

The Global Initiative Against Transnational Organized Crime (GI-TOC) is seeking a Digital Security Lead to oversee its Information Security and Digital risk approach. This role involves implementing an information security framework, engaging with staff to promote good data governance, and managing cybersecurity risks effectively across the organization.

Non-profit Organization Management

Responsibilities

Maintain a threat assessment rooted in GI’s work and programs, and communicate the key facets of this assessment to relevant stakeholders
Based on this threat assessment, implement and operate an Information Security Management System (ISMS), reporting as relevant into GI’s management team
Maintaining ‘scoring’ and an improvement backlog based on this ISMS and a Cyber Security Framework (CSF)
Working with the management team to align investment and strategy with GI’s risk appetite, costing and funding constraints and priorities - aiming to right-size cybersecurity investment and obtain funding as needed for sustainable risk management
Engaging with GI’s staff to drive a culture of risk and data-based practice, embedding appropriate cyber security skills, supporting effective governance across the organisation, and enabling researchers and program staff to respond as appropriate to suspected breaches or intrusion
Designing and rolling out technical controls as needed based on GI’s budget and risk appetite, and overarching information security management system
Handling and respond to suspected breaches, targeted attacks, or ‘incidents’, developing over time a more formal incident handling process
Drafting and validating an overall strategy rooted in appropriate policies, frameworks, and an understanding of GI’s threat landscape, and which works within GI’s risk appetite to design an effective program of work, and adopts tools and approaches which allow the integration of ongoing technology, operational cyber and information security cost into operational budgets
Implementing appropriate policies and frameworks, including Drafting an appropriate Information Security Policy; Adopting an appropriate Cyber Security Framework (e.g. NIST CSF, CIS CSC); Drafting and rolling out a retention policy and protective marking policy; Drafting and communicating relevant training and guidance to users, likely including guidance on Use of Burner Phones, Use of secure messaging apps, Source and Informant Protection
Designing and rolling out permission structures in Dropbox relevant to GI’s work, including Finalising a ‘draft structure’, Running appropriate training and engagement with staff
Drafting a roadmap / rollout plan and strategy in line with GI’s risk appetite and business model & costing approach for Dropbox End to End Encryption, Single Sign On, Device Management, Appropriate Detection and Response tools, An incident response framework
Exploring the procurement of cyber insurance

Qualification

Cybersecurity programsInformation Security Management SystemRisk managementBudget managementPolicy implementationGovernance changesTeam engagementLeadership experienceCommunication skills

Required

At least 5 years of experience running and implementing cybersecurity programs in an organisation of similar size, including both leadership and operational / hands-on experience in role that included security operations, governance, and/or risk management
Experience managing budgets or funding models for technology or cybersecurity investment
Demonstrable experience in a Civil Society or similar environment which is subject to sophisticated state or non-state threat actors
Experience rolling out policy, technology, and governance changes to a diverse, global team
Experience working with managers, leaders, and broader constituents in decentralised, distributed organisations with minimal central governance

Company

Global Initiative against Transnational Organized Crime

twittertwitter
company-logo
A network to counter networks. 500+ experts building an inclusive, global strategy against transnational organized crime.