Organisation for the Prohibition of Chemical Weapons vacancy search engine

Information Security Officer (P-3)


About Us

The OPCW’s mission is to implement the provisions of the Chemical Weapons Convention to achieve our vision of a world free of chemical weapons in which chemistry is used for peace, progress, and prosperity, and to contribute to international security and stability, general and complete disarmament, and global economic development.


The OPCW was awarded the Nobel Peace Prize in 2013 for its extensive efforts to eliminate chemical weapons.

 

General Information

  • Contract Type
    Fixed-term Professional
  • Grade
    P3
  • Total Estimated monthly remuneration depending on post adjustment and family status: USD
    8,728
  • Closing Date
    24/09/2026

Responsibilities

Job Summary

The Office of Confidentiality and Security (OCS) sets the framework, provides the guidelines, institutes the measures and implements the necessary provisions to guarantee and enforce the fulfilment of the stringent OPCW confidentiality regime; operational security of the Secretariat's assets; the security of all its electronic systems; the confidentiality of all classified material and its safeguarding.

 

Under the direct supervision of the Head, Confidentiality and Information Security (H/CIS), the Information Security Officer contributes to the implementation, monitoring and assurance of the OPCW information security programme by supporting information security governance, policy, risk assessment, compliance monitoring, access control review, incident response, investigations, resilience and security testing. 

 

Main Responsibilities:

 

1. OPCW Information Security Governance and Programme Support

  • Coordinates all aspects of the OPCW information security programme and implementation of information and ICT security measures to ensure the preservation of the confidentiality, integrity and availability of OPCW’s information;
  • Serves as focal point for all information security-related programmes and projects, advising the H/CIS, and contributes to information security governance, policy, compliance and management reporting;
  • Contributes to the development, review, maintenance and enforcement of policies, procedures, standards and guidelines for secure Information and Communications Technology (ICT) and information handling;
  • Monitors, assesses, and reports on control implementation and effectiveness for the maintenance of compliance with organisational policies, confidentiality requirements and relevant international information security standards;
  • Conducts and reviews security audits of ICT service providers and the supply chain; 
  • Collaborates with staff across OPCW to provide guidance on confidentiality and information security requirements;
  • Contributes to data collection informing senior leadership on the organisation’s information security posture and programme effectiveness. Assists the H/CIS in drafting the Director-General’s Annual Reports requiring OCS/CIS input;
  • Serves as Acting H/CIS when required.

2. Risk, Vulnerability and Control Assessments

  • Performs security risk, vulnerability and control assessments to identify risks to ICT and data systems, and information assets. Recommends appropriate mitigation measures;
  • Identifies, analyses and evaluates risks to a/m systems. Recommends or coordinates mitigation measures in close coordination with stakeholders; 
  • Performs regular assessments of the OPCW infrastructure to identify potential vulnerabilities, prioritise and categorise related risks, and supports the development of implementation plans to remediate or mitigate them; 
  • Reviews and assesses the security management, monitoring and performance of ICT assets, recommends improvements, and reports identified gaps where required; 

Main Responsibilities

  • Monitors emerging information security threats, standards, products, techniques, and technologies. Advises the H/CIS on relevant and applicable controls and measures;
  • Supports security and confidentiality reviews of new or changed applications, platforms and ICT services prior to procurement, approval or deployment.

3. Security Monitoring, Incident Response and Investigations

  • Conducts security monitoring, incident response, preliminary enquiries, investigations and digital evidence handling related information to security incidents, confidentiality breaches and potential compromise of classified or sensitive information;
  • Performs security monitoring of all networks, to identify critical functions, control weaknesses and potential security events;
  • Monitors user access across all networks, ensuring that access to confidential and sensitive information is in line with authorisations granted;
  • When tasked, coordinates and leads incident response, digital forensic, and investigation activities relating to potential security breaches, working closely with business units and stakeholders to assess and address risks to the integrity and confidentiality of sensitive or classified information;
  • Participates in technical security investigations and security event analysis related to ICT and data systems, networks and devices;
  • Prepares briefings and presentations on the potential impact, response status and remedial measures related to information security incidents to senior management; 
  • Collects, documents, and maintains the integrity, custody, and traceability of information and digital evidence related to potential confidentiality breaches or security incidents, supporting preliminary enquiries, incident response, digital forensics, and investigation activities;
  • Reports (potential) violations of the Confidentiality Regime to the Head/CIS. Advises on the conduct of related enquiries and investigations; 
  • Advises and assists staff on the proper reporting of (potential) breaches of confidentiality and/or security incidents. Where necessary, ensure such breaches or incidents are highlighted to the H/CIS.

4. Information Security Resilience and Security Testing 

  • Supports information security resilience and provides required input to Business Continuity and Disaster Recovery activities. Plans or performs security testing to assess the effectiveness of security controls across ICT systems, data systems and applications;
  • Assess the implementation of resilience strategies across ICT and data systems and applications, recommends improvements, report gaps;
  • Plans and performs vulnerability and security testing activities, including penetration testing, compliance audits and table-top exercises, on ICT and data systems and applications;
  • Supports the identification, review, tracking and follow-up of information security findings.

5. Perform other duties as required

Qualifications and Experience

Education

 

Essential:

  • Advanced university degree in information security, cybersecurity, computer science or a related field;
  • A first level university degree in a relevant subject in combination with qualifying experience (minimum of 7 years) may be accepted in lieu of the advanced university degree.

Required Certification:

  • At least one relevant industry certification (e.g., GCIH, GCIA, SSCP, etc.);

Desirable Certification:

  • Additional relevant industry certifications (e.g., GCFA, GNFA, CCSP, etc.). 

Knowledge and Experience

Essential:

Minimum of 5 years of relevant experience in information security, with significant practical experience in information security operations, incident response, investigations, assurance and control implementation, including:

  • Experience with Public Key Infrastructure (PKI), certificate authority management and lifecycle management and related security controls;
  • Experience with Microsoft 365 security, cloud security, digital forensics and security monitoring tools;
  • Advising on the design and implementation of ICT security solutions;
  • Incident monitoring, incident response and security investigations;
  • Assisting with and conducting security risk assessments;
  • Advising on and testing the security of ICT environments;
  • Network security, firewall monitoring and review of related security controls;
  • Monitoring and/or supervising operations within secure environments and information processing systems.

Desirable:

  • Experience with automated information classification, data-labelling, data loss prevention, intrusion detection/prevention, vulnerability assessment or vulnerability management solutions;
  • Experience with chain of custody requirements and technical or procedural measures for maintaining digital evidence integrity;
  • Experience contributing to information security aspects of business continuity, disaster recovery or resilience planning;
  • Experience analysing security compliance and control effectiveness in large-scale, complex or international organisations;

Skills and Competencies

  • Knowledge or experience working with the CWC and Member States is desirable;
  • Work experience in the UN Common System.

 

Skills and Competencies:

  • Strong knowledge of information security principles, confidentiality protection, access control, incident response and security assurance practices;
  • Knowledge of relevant information security standards and frameworks (e.g., NIST, ISO 27001/27002/27005, etc.);
  • Experience in the development, review and drafting of information security-related policies, procedures, standards and guidelines;
  • Ability to support incident response, security investigations and digital evidence handling with appropriate discretion, documentation and chain-of-custody awareness;
  • Excellent analytical and conceptualisation skills and an ability to plan and organise complicated processes;
  • Excellent inter-personal, interview and negotiation skills;
  • Excellent communication skills, with a demonstrated ability to present information clearly and logically both verbally and in writing;
  • Demonstrated ability to draft, edit and present documents/papers in the English language;
  • Ability to act with discretion and tact in sensitive situations;
  • Ability to work well in a team with people of different national/cultural backgrounds.

Languages

Fluency in English is essential and a good working knowledge of one of the other official languages (Arabic, Chinese, French, Russian, and Spanish) is desirable.

Additional Information

Please note that all vacancies will close at 22:00 The Netherlands local time on their respective closing day. Thereafter, the vacancy announcements will no longer appear in the Candidate Portal and you will no longer be able to submit your application. We recommend that you apply well in advance of the deadline.


This fixed-term appointment is for the duration of two years with a six-month probationary period, and is subject to the OPCW Staff Regulations and Interim Staff Rules.


The OPCW is a non-career organisation with limited staff tenure. The total length of service for Professional staff shall not exceed 7 years.


The mandatory age of separation at the OPCW is 65 years.


The Director-General retains the discretion to not make any appointment to this vacancy, to make an appointment at a lower grade, or to make an appointment with a modified job description. Several vacancies may be filled.


Only fully completed applications submitted before the closing date and through OPCW CandidateSpace will be considered. Only applicants under serious consideration for a post will be contacted.


According to article 8 paragraph 44 of the Chemical Weapons Convention the paramount consideration in the employment of the staff is the necessity of securing the highest standards of efficiency, competence, and integrity. Due regard will be paid to the importance of recruiting the staff on as wide a geographical basis as possible.


OPCW is committed to maintaining a diverse and inclusive environment of mutual respect. OPCW recruits and employs staff regardless of disability status, sex, gender identity, sexual orientation, language, race, marital status, religious, ethnic, cultural and socio-economic backgrounds, or any other personal characteristics.


OPCW General Terms and Conditions

 

Important notice for applicants who are currently insured under the Dutch Social Security system

Although headquartered in the Netherlands, the OPCW is not a regular Dutch employer but a public international organisation with its own special status. Please be advised that if you are currently insured under the Dutch Social Security system, you will be excluded from this system as a staff member of the OPCW. You will consequently be insured under the organisation’s system. The above also applies to your dependents unless they are employed by a regular Dutch employer, they are self-employed in the Netherlands, or are receiving Dutch social security payments.

Please refer to the website of the Ministry of Social Affairs and Employment for more information about the possible consequences for you and your dependents, such as exclusion from ‘AWBZ’ and ‘Zorgverzekeringswet’ coverage: ‘Werken bij een internationale organisatie’.