> Markdown version of [/jobs/ext/2212521-information-security-officer](https://www.wearedevelopers.com/jobs/ext/2212521-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer - **Company:** OP ACCOUNTING SERVICES AND SOLUTIONS PLC - **Location:** United States - **Experience:** Expert - **Salary:** $104,736.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Cloud Computing Security, Cyber Security, Information Leak Prevention, Data Systems, Digital Forensics, Disaster Recovery, Intrusion Detection and Prevention, Network Security, Public Key Infrastructure, Security Information and Event Management, Software Vulnerability Management, Data Processing, Data Classification, Information Technology, Vulnerability Analysis - **Published:** August 24, 2026 - **Apply:** https://jobs.opcw.org/job/job-information-security-officer-p-3-_583.aspx ## About the Role Essential: * Advanced university degree in information security, cybersecurity, computer science or a related field; * A first level university degree in a relevant subject in combination with qualifying experience (minimum of 7 years) may be accepted in lieu of the advanced university degree. Required Certification: * At least one relevant industry certification (e.g., GCIH, GCIA, SSCP, etc.); Desirable Certification: * Additional relevant industry certifications (e.g., GCFA, GNFA, CCSP, etc.)., Minimum of 5 years of relevant experience in information security, with significant practical experience in information security operations, incident response, investigations, assurance and control implementation, including: * Experience with Public Key Infrastructure (PKI), certificate authority management and lifecycle management and related security controls; * Experience with Microsoft 365 security, cloud security, digital forensics and security monitoring tools; * Advising on the design and implementation of ICT security solutions; * Incident monitoring, incident response and security investigations; * Assisting with and conducting security risk assessments; * Advising on and testing the security of ICT environments; * Network security, firewall monitoring and review of related security controls; * Monitoring and/or supervising operations within secure environments and information processing systems. Desirable: * Experience with automated information classification, data-labelling, data loss prevention, intrusion detection/prevention, vulnerability assessment or vulnerability management solutions; * Experience with chain of custody requirements and technical or procedural measures for maintaining digital evidence integrity; * Experience contributing to information security aspects of business continuity, disaster recovery or resilience planning; * Experience analysing security compliance and control effectiveness in large-scale, complex or international organisations; Skills and Competencies * Knowledge or experience working with the CWC and Member States is desirable; * Work experience in the UN Common System. Skills and Competencies: * Strong knowledge of information security principles, confidentiality protection, access control, incident response and security assurance practices; * Knowledge of relevant information security standards and frameworks (e.g., NIST, ISO 27001/27002/27005, etc.); * Experience in the development, review and drafting of information security-related policies, procedures, standards and guidelines; * Ability to support incident response, security investigations and digital evidence handling with appropriate discretion, documentation and chain-of-custody awareness; * Excellent analytical and conceptualisation skills and an ability to plan and organise complicated processes; * Excellent inter-personal, interview and negotiation skills; * Excellent communication skills, with a demonstrated ability to present information clearly and logically both verbally and in writing; * Demonstrated ability to draft, edit and present documents/papers in the English language; * Ability to act with discretion and tact in sensitive situations; * Ability to work well in a team with people of different national/cultural backgrounds., Fluency in English is essential and a good working knowledge of one of the other official languages (Arabic, Chinese, French, Russian, and Spanish) is desirable. ## Description The Office of Confidentiality and Security (OCS) sets the framework, provides the guidelines, institutes the measures and implements the necessary provisions to guarantee and enforce the fulfilment of the stringent OPCW confidentiality regime; operational security of the Secretariat's assets; the security of all its electronic systems; the confidentiality of all classified material and its safeguarding. Under the direct supervision of the Head, Confidentiality and Information Security (H/CIS), the Information Security Officer contributes to the implementation, monitoring and assurance of the OPCW information security programme by supporting information security governance, policy, risk assessment, compliance monitoring, access control review, incident response, investigations, resilience and security testing. Main Responsibilities: 1. OPCW Information Security Governance and Programme Support * Coordinates all aspects of the OPCW information security programme and implementation of information and ICT security measures to ensure the preservation of the confidentiality, integrity and availability of OPCW's information; * Serves as focal point for all information security-related programmes and projects, advising the H/CIS, and contributes to information security governance, policy, compliance and management reporting; * Contributes to the development, review, maintenance and enforcement of policies, procedures, standards and guidelines for secure Information and Communications Technology (ICT) and information handling; * Monitors, assesses, and reports on control implementation and effectiveness for the maintenance of compliance with organisational policies, confidentiality requirements and relevant international information security standards; * Conducts and reviews security audits of ICT service providers and the supply chain; * Collaborates with staff across OPCW to provide guidance on confidentiality and information security requirements; * Contributes to data collection informing senior leadership on the organisation's information security posture and programme effectiveness. Assists the H/CIS in drafting the Director-General's Annual Reports requiring OCS/CIS input; * Serves as Acting H/CIS when required. 2. Risk, Vulnerability and Control Assessments * Performs security risk, vulnerability and control assessments to identify risks to ICT and data systems, and information assets. Recommends appropriate mitigation measures; * Identifies, analyses and evaluates risks to a/m systems. Recommends or coordinates mitigation measures in close coordination with stakeholders; * Performs regular assessments of the OPCW infrastructure to identify potential vulnerabilities, prioritise and categorise related risks, and supports the development of implementation plans to remediate or mitigate them; * Reviews and assesses the security management, monitoring and performance of ICT assets, recommends improvements, and reports identified gaps where required, * Monitors emerging information security threats, standards, products, techniques, and technologies. Advises the H/CIS on relevant and applicable controls and measures; * Supports security and confidentiality reviews of new or changed applications, platforms and ICT services prior to procurement, approval or deployment. 3. Security Monitoring, Incident Response and Investigations * Conducts security monitoring, incident response, preliminary enquiries, investigations and digital evidence handling related information to security incidents, confidentiality breaches and potential compromise of classified or sensitive information; * Performs security monitoring of all networks, to identify critical functions, control weaknesses and potential security events; * Monitors user access across all networks, ensuring that access to confidential and sensitive information is in line with authorisations granted; * When tasked, coordinates and leads incident response, digital forensic, and investigation activities relating to potential security breaches, working closely with business units and stakeholders to assess and address risks to the integrity and confidentiality of sensitive or classified information; * Participates in technical security investigations and security event analysis related to ICT and data systems, networks and devices; * Prepares briefings and presentations on the potential impact, response status and remedial measures related to information security incidents to senior management; * Collects, documents, and maintains the integrity, custody, and traceability of information and digital evidence related to potential confidentiality breaches or security incidents, supporting preliminary enquiries, incident response, digital forensics, and investigation activities; * Reports (potential) violations of the Confidentiality Regime to the Head/CIS. Advises on the conduct of related enquiries and investigations; * Advises and assists staff on the proper reporting of (potential) breaches of confidentiality and/or security incidents. Where necessary, ensure such breaches or incidents are highlighted to the H/CIS. 4. Information Security Resilience and Security Testing * Supports information security resilience and provides required input to Business Continuity and Disaster Recovery activities. Plans or performs security testing to assess the effectiveness of security controls across ICT systems, data systems and applications; * Assess the implementation of resilience strategies across ICT and data systems and applications, recommends improvements, report gaps; * Plans and performs vulnerability and security testing activities, including penetration testing, compliance audits and table-top exercises, on ICT and data systems and applications; * Supports the identification, review, tracking and follow-up of information security findings. 5. Perform other duties as required ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [From Messy Queries to Scalable Systems - How Data Engineering actually works](https://www.wearedevelopers.com/videos/100203-from-messy-queries-to-scalable-systems-how-data-engineering-actually-works) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Implementing continuous delivery in a data processing pipeline](https://www.wearedevelopers.com/videos/73-implementing-continuous-delivery-in-a-data-processing-pipeline) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Starter Kit For Job Applications For Developers](https://www.wearedevelopers.com/magazine/7-starter-kit-for-job-applications-for-developers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)