> Markdown version of [/jobs/ext/2232562-information-security-officer-mtit-p3](https://www.wearedevelopers.com/jobs/ext/2232562-information-security-officer-mtit-p3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer (MTIT)(P3) - **Company:** International Atomic Energy Agency - **Location:** Wien, Austria - **Experience:** Expert - **Salary:** €71,335.0 - **Contract:** Permanent contract - **Skills:** Computing Platforms, Cyber Security, Information Systems, Identity and Access Management, Information Management, PRINCE2, Phishing, Systems Integration, Information Security Management System, Information Technology - **Published:** August 26, 2026 - **Apply:** https://careerjet.at/jobad/atfe078c89db35e08feadbb04223d61ae0 ## About the Role Information Technology IT Security Experience in the design and architecture of IT security systems, with a strong understanding of secure infrastructure and system integration. Information Technology Information Security Experience in design, implementation and operation of Identity and Access Management solutions; Information Technology Information Security and Risk Management Experience in assessing information security risks and delivering effective technical solutions to mitigate identified vulnerabilities. Proven expertise in the design, implementation, and operation of Information and IT Security Risk Management solutions. Information Technology Information Security and Risk Management Experience in design, implementation and operation of Information and IT Security Risk Management solutions; Asset Expertise Function Name Expertise Description Information Technology Project Management Experience in IT project management using the established project management methodology; eExperience in managing IT projects using best practice project management methodologies such as PMP and/or Prince2. Qualifications, Experience and Language skills Bachelor's Degree - University degree in computer science, information management, IT Security or a related field. Other - Accredited information or IT security relevant certification, such as CISSP, CISM, CISA or GIAC. Other - Accredited certification in Project Management such as PMP, Prince2 as an asset. Minimum of five years of professional experience managing information security programs in enterprise IT environments, applying standardized frameworks, such as ISO/IEC 27000. Demonstrated expertise in IT risk management, policy development, writing and implementation, compliance monitoring, and stakeholder engagement, with a strong background in IT Project Management. Excellent oral and written command of English. Knowledge of other official IAEA languages (Arabic, Chinese, French, Russian and Spanish) is an asset. ## Description This selection exercise may be used to generate a roster of pre-approved candidates to address future staffing needs for similar functions in any of the Departments and Offices of the Organization. IMPORTANT NOTICE REGARDING APPLICATION DEADLINE: Please note that the closing date for submission of applications is indicated in local time as per the time zone of the applicant's location. Organizational Setting The Division of Information Technology provides support to the IAEA in the field of information and communication technology (ICT), including information systems for technical programmes and management. It is responsible for planning, developing and implementing an ICT strategy, for setting and enforcing common ICT standards throughout the Secretariat and for managing central ICT services. The IAEA's ICT infrastructure comprises hardware and software platforms, and cloud and externally-hosted services. The Division has implemented an IT service management model based on ITIL (IT Infrastructure Library) and Prince2 (Projects in a Controlled Environment) best practices. Main Purpose The purpose of the post is to help MTIT define and create repeatable and consistent processes to strengthen IAEA information security. The Information Security Officer participates in the development and delivery of a comprehensive information security program for the IAEA. He/she also manages/participates in implementation of information security projects, and the administration and verification of security controls., The Information Security Officer is (a) an operator for the Agency Information Security Management System (ISMS); (b) the Departmental information Security Officer (DISO) for the department of Management; (c) a risk manager managing security risks identified though set processes; (d) a project manager/coordinator, soliciting inputs from other specialists and assisting in defining, planning and executing information security projects; and (e) a CISG and MTIT team member. Functions / Key Results Expected Contribute as a key player to ensuring the confidentiality, integrity and availability of information systems and data through developing and implementation of mature information security policies, procedures and guidance. Operate the Agency ISMS in order to obtain and maintain the Agency's ISO 27001 certification Develop, implement and maintain a state-of-the-art risk management system, focusing on latest threat landscape, appropriate mitigating controls on technical and organisational level. Participate in the information security risk assessment program, identify and analyse risks, make recommendations for corrective actions and monitor implementation and remediation. Participate in the comprehensive awareness program, including provision of face-to-face or online training, phishing exercise, ad-hoc newsletter, regular intranet information and other relevant information. Participate in IT projects on behalf of the CISO to ensure that security is embedded. Produce high-quality oral and written reports, presenting complex technical matters clearly and concisely. Maintain proficiency in industry standard tools and practices and in IAEA policies and procedures. Competencies and Expertise Core Competencies Name Definition Planning and Organizing Plans and organizes his/her own work in support of achieving the team or Section's priorities. Takes into account potential changes and proposes contingency plans. Communication Communicates orally and in writing in a clear, concise and impartial manner. Takes time to listen to and understand the perspectives of others and proposes solutions. Achieving Results Takes initiative in defining realistic outputs and clarifying roles, responsibilities and expected results in the context of the Department/Division's programme. Evaluates his/her results realistically, drawing conclusions from lessons learned. Teamwork Actively contributes to achieving team results. Supports team decisions. Functional Competencies Name Definition Client orientation Helps clients to analyse their needs. Seeks to understand service needs from the client's perspective and ensure that the client's standards are met. Commitment to continuous process improvement Plans and executes activities in the context of quality and risk management and identifies opportunities for process, system and structural improvement, as well as improving current practices. Analyses processes and procedures, and proposes improvements. Technical/scientific credibility Ensures that work is in compliance with internationally accepted professional standards and scientific methods. Provides scientifically/technically accepted information that is credible and reliable. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [IT Salaries in Austria](https://www.wearedevelopers.com/magazine/286-it-salaries-in-austria) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [10 Highest Paying Jobs in Austria](https://www.wearedevelopers.com/magazine/268-10-highest-paying-jobs-in-austria)