Team and Job Purpose
The Information Security Specialist role is critical to increasing and then maintaining security maturity across Save The Children Association (SCA) Members, allowing them to meet their obligations under the Mutual Accountability Framework minimum standard for information security.
The Information Security Specialist will act as the primary contact for information security matters between SCA Member organisations and SCI within the region to which they are assigned and offer independent objective advice, guidance and support for the senior leadership teams and functional teams.
They will also be required to lead or assist with incident management processes both in SCI and SCA Members.
Ultimately, the Information Security Specialist will help achieve and maintain SCA and SCI compliance through the implementation of transparent IT Security policies, systems and procedures.
Principal Accountabilities
Information Security Assessment
- Carrying out regular assessments of current information security practices across SCA Member organizations.
- Supporting the delivery of vulnerability assessments and penetration tests (and other Shared Services) with the SCI Information Security & Assurance team.
- Establish key performance indicators (KPIs) to measure the effectiveness of security initiatives.
- Regularly report on security metrics and progress toward maturity goals to the Head of SCA Information Security Services.
Policy Development and Implementation
- Support and advise the Member’s Point of Contacts (PoC) during the implementation, and maintenance of IT security policies, standards, and procedures. This could include the writing and reviewing of new policies and procedures.
- Ensure Member policies align with the Mutual Accountability Framework and other regulatory requirements and are implemented effectively within the Member.
Training and Awareness
- Support the delivery of Member information security training programs for staff at all levels, including training content and phishing simulations.
- Foster a culture of security awareness within the organization.
Incident Management Support
- Assist in information security incident management processes, including identification, containment, eradication, recovery and testing.
- Coordinate communication and reporting of security incidents to relevant stakeholders.
Stakeholder Engagement
- Serve as the primary point of contact for information security matters within assigned regions.
- Develop strong working relationships with Member PoCs and other key stakeholders. Provide expert advice and support to senior leadership and functional teams on all issues relating to information security.
- Prepare and present reports on security compliance and maturity to senior management.
Risk Management
- Support risk assessment activities to identify and prioritize potential security threats. Support the development of appropriate risk management processes where not in place.
- Recommend risk mitigation strategies and monitor their effectiveness.
Collaboration and Communication
- Collaborate with IT teams and other departments to integrate information security into all business processes.
- Help facilitate clear and regular communications regarding security initiatives and concerns.
Continuous Improvement
- Stay informed about the latest trends and best practices in information security.
- Recommend improvements to security strategies based on industry developments and organizational needs.
Experience and Skills
Essential
- Good knowledge of ISO/IEC 27001 and NIST Cybersecurity Framework (CSF)
- At least two years of experience working in an information security programme or project environment
- Good understanding of IT infrastructure including cloud, networks and information management systems
- Capability to convey technical information effectively to non-technical stakeholders in a clear and comprehensive manner
- Ability to work with a range of business stakeholders to understand and articulate their activities in line with defined standards
- Good verbal and written communication skills (in English)
- Self-motivated, with a proactive and collaborative approach, and a strong results orientation
- Commitment to Save the Children mission and values
Education and Qualifications
Essential
- Degree or diploma in Computer Science / Business Technology / Information Security, or relevant experience
Desirable
- Security related certification/s
Education: Degree, Diploma
Employment Type: Full Time