{"id":1431084,"url":"https://alion.io/job/msf-information-security-lead","title":"Information Security Lead","company":{"id":1756985,"name":"MSF","domain":"msf.org","url":"https://alion.io/company/msf-org","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Recruitee","truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Brussels, Belgium"],"countries":["BE"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":93000,"max_usd":247000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":399},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"DLP","optional":false},{"name":"GDPR","optional":false},{"name":"ISO 27001","optional":false},{"name":"PCI DSS","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-09-28T15:35:44Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-10-01T18:07:48Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"Location: Any MSF office\nContract: Fixed term at 100% position - The term of this assignment is intended to be for a period of two (2) years, nevertheless, the duration of the contract may be subject to the employment regulations and labor laws of the country where the selected candidate is based.\nStarting date: 15th of November 2026\nDeadline to apply: 18th of October\nCompensation and Benefits: MSF practice is to offer the compensation and benefits package in line with the MSF entity offering the contract.\nI. MSF INTERNATIONAL\nMédecins Sans Frontières (MSF) is an international, independent, medical humanitarian organisation that delivers emergency aid to people affected by armed conflict, epidemics, healthcare exclusion and natural disasters. MSF offers assistance to people based only on need and irrespective of origins, religion, gender or political affiliation. MSF International provides coordination, information and support to the MSF Movement, as well as implements international projects/programmes and initiatives as requested.\nII. POSITION BACKGROUND\nThe Information Systems Management (ISM), one of the international platforms of MSF gathering all the Heads of IT/IS from key MSF entities, has been mandated by MSF’s executive governance body, the Full Excom, to lead the development of an international information systems management strategy seeking to optimise interoperability across MSF in priority areas. The ISM Platform is responsible for setting standards for IT/IS architecture and technology development and aims to promote targeted innovation in information technology/information systems (IT/IS).\nCritical to this role, and in response to an increasingly complex cyber and global regulatory landscape, the ISM Platform spearheaded the development of a global information security policy framework back in 2020, which has continued to evolve.\nIn its strategic ambitions, the ISM Platform has committed to prioritising information security and incident resilience as a cross-cutting theme across all its initiatives. The role of the Information Security Lead is to develop an effective execution strategy and a programme to improve MSF’s overall information security posture and governance of information security in the movement.\nIII. PLACE IN THE ORGANISATION\nThe Information Security Lead will:\nReport hierarchically to the International Information Systems Coordinator (who chairs the ISM Platform), with functional oversight provided by the ISM Platform\n\nWork closely with the members of the ISM Platform, InfoSec focal points in each section, ISM InfoSec WG, MSF SITS (Shared IT Services) and other MSF stakeholders to ensure the information security initiatives, working group(s) and/or task force(s) created/sponsored/guided by the ISM are all aligned to the evolving needs of the organisation and the ISM’s strategic vision\n\nWork in collaboration with the ISM Coordination team to ensure a consistent approach to programme and project management within the ISM portfolio and Working Group (WG) initiatives\n\nIV. OBJECTIVES OF THE POSITION\nThe Information Security Lead will lead the development of the roadmap for information security governance, risk & compliance in MSF under the guidance of the ISM platform and in close collaboration with the Info Sec WG. The Information Security Lead will provide strategic guidance, operational support, and incident response expertise across headquarters and field missions, balancing security requirements with the realities of medical and humanitarian operations.\nThe Information Security Lead will establish the governance mechanisms necessary to ensure better identification, monitoring and mitigation of information security risks in MSF. This role will recommend planning and allocation of infosec resources, and develop the necessary processes/frameworks to do so.\nSpecific Objectives\nAn effective global information security framework, strategy, and roadmap are in place to guide MSF’s short-, medium-, and long-term security priorities.\n\nPriority information security risks are proactively managed through a shared and structured organisational approach.\n\nSecurity incidents requiring intersectional coordination are responded to effectively, limiting impact and supporting resilience.\n\nTechnical information security decisions across MSF are informed by reliable expert guidance.\n\nSensitive information is managed securely and in line with relevant governance requirements.\n\nOrganisational information security awareness and capability are strengthened on an ongoing basis.\n\nEmerging threats and external developments relevant to MSF are monitored and reflected in a stronger overall security posture.\n\nV. KEY RESPONSIBILITIES\nInformation Security Strategy and Governance\nDevelop, implement, and maintain MSF’s information security strategy and roadmap\n\nDefine and maintain information security policies, standards, and procedures\n\nAdvise senior management on information security risks and mitigation options, including new resourcing and delivery models\n\nSupport definition of mutualised approaches for selected information security capabilities across MSF (e.g. baseline policies/standards, security monitoring / SIEM-SOC options, incident coordination, third-party security assurance, etc.)\n\nContribute to organisational risk management and governance processes\n\nRisk Management\nIdentify, assess, and prioritise information security risks in the movement\n\nConduct and support information security risk assessments for existing and new initiatives\n\nPropose feasible mitigation measures\n\nSupport the documentation and acceptance of residual risks\n\nIncident Response and Crisis Management\nLead responses to movement-wide information security incidents\n\nSupport field missions and headquarters during high-pressure or sensitive incidents\n\nCoordinate with relevant functions (IT, legal, communications, HR, security, etc.)\n\nEnsure post-incident reviews and follow-up actions are completed\n\nTechnical and Operational Security Oversight\nAdvise on matters such as infrastructure, network, cloud, and endpoint security\n\nAdvise on security matters such as identity & access management and remote working\n\nEnsure security requirements are integrated into system design, procurement, and third-party arrangements\n\nData Protection, Ethics, and Safeguarding\nAdvise on data classification, minimisation, retention, and secure sharing\n\nWork closely with data protection, legal, safeguarding, and other stakeholders\n\nPromote digital practices that minimise risks of harm to individuals and communities\n\nAwareness and Capacity Building\nDevelop and deliver information security awareness and training programs\n\nBuild information security capacity among staff\n\nTranslate complex security concepts into clear, practical guidance\n\nCoordination and Representation\nCollaborate closely with all relevant functions\n\nChair the ISM Information Security Working Group sessions\n\nCoordinate with external service providers and security experts\n\nRepresent MSF in relevant information security and humanitarian forums\n\nMonitor emerging threats relevant to humanitarian and medical organisations\n\nRequirements\nEducation:\nMinimum Bachelor's degree in a technical discipline (Computer Science, Cybersecurity, Information Technology, etc.) or equivalent\n\nCertification as a security professional, e.g. Certified Information Systems Security Professional (CISSP) or Certified Information Security Auditor (CISA)\n\nExperience and skills:\nMinimum 7 years’ experience in information security or security risk management.\n\nStrong expertise in cloud, network, and cybersecurity, including incident response, vulnerability management, DLP, IDS/IPS, and penetration testing.\n\nGood knowledge of security frameworks, risk management, and compliance requirements (e.g. NIST, ISO 27001, CIS, GDPR, PCI DSS).\n\nExperience developing security policies, standards, and enterprise solutions in complex, decentralised, and international environments.\n\nKnowledge of business continuity and disaster recovery.\n\nStrong leadership, communication, analytical, and cross-cultural collaboration skills, with high ethical standards and alignment with MSF values.\n\nLanguages:\nFluent spoken and written English\n\nOther:\nInternational travel may be required a few times a year\n\nOccasional availability outside normal working hours during incidents","description_format":"text","description_chars":8375,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Health Care","Hospitals & Health Systems","Diagnostic Tests & IVD"],"lifecycle":[{"event":"open","at":"2026-09-29T01:24:00Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":2,"expected_fill_days":20,"reasons":["conf:8","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/msf-information-security-lead","json_url":"https://alion.io/job/msf-information-security-lead.json","meta":{"generated_at":"2026-10-01T21:58:41Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4591,"day_limit":5000,"remaining_today":409,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}