About The Position

IREX is an independent nonprofit organization dedicated to building a more just, prosperous, and inclusive world by empowering youth, cultivating leaders, strengthening institutions, and extending access to quality education and information. POSITION SUMMARY The Cybersecurity Specialist, under the supervision of the Project Senior Technical Advisor, will be hired as a consultant to perform some or all activities including (1) conducting and writing organizational cybersecurity risk assessments, following Center for Internet Security Controls Framework (CIS Controls v8.1), (2) Open Source Intelligence Analysis (OSINT) (3) vulnerability assessments, (4) penetration testing (black box), (5) and developing and delivering Security Awareness Programs (SAP) and ad-hoc trainings in coordination with beneficiary organizations’ needs. IREX will prioritize candidates whose native language(s) are either Spanish, Arabic, Chinese, Urdu, Korean, Russian, or French with experience working on information security, in particular, organizational cybersecurity. However, all candidates who can perform the above-mentioned tasks are encouraged to apply regardless of language abilities. Consultant(s) will be hired on a rolling basis based on project needs. Please note this position is based on the needs of the project, with an expected approximate engagement between 20 and 100 days per year, pending the consultant’s technical skills, relevant language capabilities, and qualifications to fulfill the required tasks.

Requirements

  • Assessments Execution: Experience leading end-to-end security audits, comparing current technical controls against organizational policies and industry benchmarks.
  • Framework Guided Assessments: Deep understanding of organizational assessment standards, conducting comprehensive gap analyses and risk assessments against industry standards such as CIS CSC, NIST CSF, and ISO 27001.
  • Vulnerability Scanning: Experience administering scanning tools (e.g., Tenable Nessus, Qualys, Rapid7) to continuously discover web application and endpoint vulnerabilities.
  • Risk Analysis and Reporting: Experience quantifying technical vulnerabilities into business risk for non-technical stakeholders and C-suite executives.
  • Cross-Functional Remediation: Proven track record of coaching/mentoring beneficiary technical staff to address assessment-identified gaps (recommendations), patches, and configuration changes without disrupting business continuity.
  • Policy & Control Evaluation: Experience acting as the primary technical liaison during external assessments to review the effectiveness of current security controls and policies.
  • Phishing Simulations: Experience designing, executing, and analyzing regular social engineering campaigns to test and improve employee resilience against malicious emails.
  • Curriculum Development: Experience creating engaging, role-specific security training modules and company-wide communications using platforms like KnowBe4 or Infosec IQ.
  • Culture & Metrics Tracking: Experience monitoring key performance indicators (KPIs) such as simulation click rates, reporting rates, and training completion percentages to report program developments to executive leadership.
  • Very strong verbal, written, and listening communication skills (in English).
  • Ability to work independently on assigned efforts.
  • Strong interpersonal skills and experience developing solid professional relationship
  • Ability to work under pressure and manage multiple activities.

Nice To Haves

  • Existing, trust-based relationships with a wide array of stakeholders working for civil society organizations, human rights organizations, and independent media, or any relevant experience.
  • Bachelor’s degree in information or computing sciences.
  • Fluency in Spanish, Arabic, Russian, and/or French

Responsibilities

  • Plan, manage, and conduct organizational assessments; propose recommendations for improvement; provide guidance, training, mentoring, and support to improve organizational security posture; and provide guidance, training, mentoring, and support to improve organizational security posture for project beneficiaries.
  • Draft Organization Security Risk Assessment (OSRA) reports geared towards both non-technical and technical audiences.
  • In collaboration with the Project Director and/or Deputy Project Director, develop organizational Action Plans (APs) based on OSRA findings and in consultation with beneficiary organization executive leadership to help improve beneficiary security postures rooted in organizational assessment findings.
  • Lead design efforts with assigned beneficiaries on tailored Security Awareness Program (SAP), ensuring that beneficiaries learn, internalize, use, and spread appropriate cybersecurity awareness practices.
  • Lead the design of specialized training as needed.
  • Collaborate with SOC team members on services specifically designed for beneficiaries.
  • Develop, draft, and update documentation, including policies, procedures, baselines, guidelines, etc., in collaboration with beneficiary organizations.
  • Write technical and programmatic reports on activities and program implementation.
  • With supervision, provide input to internal/external reports, presentations, and other products.
  • Contribute to monitoring and evaluation activities, including data management and analysis, as assigned.
  • Draft correspondence with stakeholders. Guidance and/or approval before engaging stakeholders may be required.
  • Perform additional duties as assigned.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service