Bachelor's degree in information or computing sciences.
Experience leading end-to-end security audits and gap analyses against CIS Controls (CIS CSC), NIST CSF, and ISO 27001.
Experience administering vulnerability scanning tools (e.g., Tenable Nessus, Qualys, Rapid7) and translating vulnerabilities into business risk.
Excellent written and verbal communication skills in English and ability to work independently with strong interpersonal skills.
Requirements:
Plan, manage, and conduct organizational security assessments; propose recommendations and provide guidance, training, and mentoring to improve beneficiaries' security posture.
Draft Organization Security Risk Assessments (OSRA) and, with leadership, develop Organizational Action Plans (APs) to enhance beneficiaries' security.
Lead the design and delivery of tailored Security Awareness Programs (SAP) and trainings for beneficiaries; collaborate with SOC team as needed.
Develop, update, and maintain security documentation (policies, procedures, baselines) in collaboration with beneficiary organizations; draft technical and programmatic reports and support monitoring and evaluation.
Job description
ABOUT IREX
IREX is an independent nonprofit organization dedicated to building a more just, prosperous, and inclusive world by empowering youth, cultivating leaders, strengthening institutions, and extending access to quality education and information.
POSITION SUMMARY
The Cybersecurity Specialist, under the supervision of the Project Senior Technical Advisor, will be hired as a consultant to perform some or all activities including (1) conducting and writing organizational cybersecurity risk assessments, following Center for Internet Security Controls Framework (CIS Controls v8.1), (2) Open Source Intelligence Analysis (OSINT) (3) vulnerability assessments, (4) penetration testing (black box), (5) and developing and delivering Security Awareness Programs (SAP) and ad-hoc trainings in coordination with beneficiary organizations’ needs.
IREX will prioritize candidates whose native language(s) are either Spanish, Arabic, Chinese, Urdu, Korean, Russian, or French with experience working on information security, in particular, organizational cybersecurity. However, all candidates who can perform the above-mentioned tasks are encouraged to apply regardless of language abilities. Consultant(s) will be hired on a rolling basis based on project needs.
Please note this position is based on the needs of the project, with an expected approximate engagement between 20 and 100 days per year, pending the consultant’s technical skills, relevant language capabilities, and qualifications to fulfill the required tasks.
DUTIES AND RESPONSIBILITIES
Plan, manage, and conduct organizational assessments; propose recommendations for improvement; provide guidance, training, mentoring, and support to improve organizational security posture; and provide guidance, training, mentoring, and support to improve organizational security posture for project beneficiaries.
Draft Organization Security Risk Assessment (OSRA) reports geared towards both non-technical and technical audiences.
In collaboration with the Project Director and/or Deputy Project Director, develop organizational Action Plans (APs) based on OSRA findings and in consultation with beneficiary organization executive leadership to help improve beneficiary security postures rooted in organizational assessment findings.
Lead design efforts with assigned beneficiaries on tailored Security Awareness Program (SAP), ensuring that beneficiaries learn, internalize, use, and spread appropriate cybersecurity awareness practices.
Lead the design of specialized training as needed.
Collaborate with SOC team members on services specifically designed for beneficiaries.
Develop, draft, and update documentation, including policies, procedures, baselines, guidelines, etc., in collaboration with beneficiary organizations.
Write technical and programmatic reports on activities and program implementation.
With supervision, provide input to internal/external reports, presentations, and other products.
Contribute to monitoring and evaluation activities, including data management and analysis, as assigned.
Draft correspondence with stakeholders. Guidance and/or approval before engaging stakeholders may be required.
Perform additional duties as assigned.
SKILLS AND EXPERIENCE
Organizational Assessments
Assessments Execution: Experience leading end-to-end security audits, comparing current technical controls against organizational policies and industry benchmarks.
Framework Guided Assessments: Deep understanding of organizational assessment standards, conducting comprehensive gap analyses and risk assessments against industry standards such as CIS CSC, NIST CSF, and ISO 27001.
Vulnerability Scanning: Experience administering scanning tools (e.g., Tenable Nessus, Qualys, Rapid7) to continuously discover web application and endpoint vulnerabilities.
Risk Analysis and Reporting: Experience quantifying technical vulnerabilities into business risk for non-technical stakeholders and C-suite executives.
Remediation Processes
Cross-Functional Remediation: Proven track record of coaching/mentoring beneficiary technical staff to address assessment-identified gaps (recommendations), patches, and configuration changes without disrupting business continuity.
Policy & Control Evaluation: Experience acting as the primary technical liaison during external assessments to review the effectiveness of current security controls and policies.
Security Awareness Programs
Phishing Simulations: Experience designing, executing, and analyzing regular social engineering campaigns to test and improve employee resilience against malicious emails.
Curriculum Development: Experience creating engaging, role-specific security training modules and company-wide communications using platforms like KnowBe4 or Infosec IQ.
Culture & Metrics Tracking: Experience monitoring key performance indicators (KPIs) such as simulation click rates, reporting rates, and training completion percentages to report program developments to executive leadership.
Other
Very strong verbal, written, and listening communication skills (in English).
Ability to work independently on assigned efforts.
Strong interpersonal skills and experience developing solid professional relationship
Ability to work under pressure and manage multiple activities.
Preferred:
Existing, trust-based relationships with a wide array of stakeholders working for civil society organizations, human rights organizations, and independent media, or any relevant experience.
Bachelor’s degree in information or computing sciences.
Fluency in Spanish, Arabic, Russian, and/or French
**this position is a remote position**
To apply please submit a full CV alongside a separate document summarizing of relevant experience, along with a proposed daily rate (in $ USD). IREX is seeking individual consultants but would also welcome applications from consulting/security firms that are interested in providing these services.
IREX may at its discretion ask for additional information, including references. Issuing this call does not commit IREX to select any applicant/expert. IREX may hire more than one applicant/expert from this call. IREX may accept multiple bidders and partial bids for the services requested. IREX reserves the right, based on the availability of funding and consultant performance, to increase the duration and/or enter into subsequent contractual agreements with the selected candidates for up to 5 years without re-publicizing the opportunity.
Prior to any engagement, you will be asked to provide references. IREX will not extend an offer until the reference check is completed.
IREX conducts anti-terrorism database clearances on candidates who accept employment offers.
IREX is committed to a diverse and inclusive workplace and inclusive hiring practice. IREX is an equal-opportunity employer.