
International Telecommunication Union (ITU)
Sector
SGDepartment: ISDCountry of contract: SwitzerlandDuty station: Geneva
Department
ISDCountry of contract: SwitzerlandDuty station: Geneva
Grade
P4 Type of contract: Fixed-termDuration of contract: 2 years with possibility of renewalRecruitment open to: ExternalApplication deadline (Midnight Geneva Time): 02 December 2026
ITU is the leading United Nations agency for information and communication technologies, with the mission to connect the world. To achieve this, ITU manages the radio-frequency spectrum and satellite orbits at the international level, works to improve communication infrastructure in the developing world, and establishes global standards that foster seamless interconnection of a vast range of communication systems.
Cybersecurity Operations Manager
Vacancy notice no: 2416
Position number: IS12/P4/328
The General Secretariat directs administrative, human and financial resources and activities of the Union, including the implementation of the provisions of the administrative regulations on operational questions, the dissemination of information on telecommunication/ICT matters for operational and other purposes, and the provision of legal advice to the whole of the Union. The General Secretariat coordinates the implementation of the Strategic Plan, monitors the telecommunication/ICT environment and recommends as needed action relating to the Union’s future policies and strategy. The General Secretariat ensures inter-sectoral coordination and cooperation to advance a whole of ITU approach (One-ITU) in headquarters and the field. The General Secretariat provides logistical and information technology support to the Union’s activities including conferences and global forums; the coordination of the work of the Union with the United Nations system, and other international organizations; and the engagement of the Member States, Sector Members, and Academia. The General Secretariat manages corporate governance, and strategic communications and relations with the media, different stakeholder groups as well as the general public.
Within the General Secretariat, the Information Services Department (IS) is the focal point for the ITU information technology services, managing ERP, CRM, documents, information systems and infrastructure, service-desk, library, archives and information management services, safety and security (both physical and logical), to support staff both at Headquarters and in the Field, as well as delegates attending conferences, meetings and events world-wide. It also promotes ICT collaboration, partnerships and information-sharing and represents ITU in inter-organization meetings and committees related to information technology and security management.ORGANIZATIONAL CONTEXT
Under the supervision and delegated authority of the Head of the ICT Security Unit, Information Services Department, the Cybersecurity Operations Manager leads the hands-on operational management of ITU’s cybersecurity infrastructure, security services, and security projects. The incumbent is a technically competent manager who combines deep practical expertise in cybersecurity technologies with the ability to manage contractors, vendors, and external security service providers.The role is accountable for the day-to-day operation of security infrastructure and the 24/7 Security Operations Center (SOC), managed through an external MSSP. The Cybersecurity Operations Manager also serves as Program/Project Manager for major security initiatives including acquisition and implementation of new security products and services, SOC modernization, and security architecture improvements. The incumbent provides operational oversight of emerging technology security risks, including AI/ML, Large Language Models (LLMs), and agentic AI systems—and ensures alignment of security operations with ITU’s digital transformation strategy and applicable international cybersecurity frameworks.DUTIES AND RESPONSIBILITIES
.CORE COMPETENCIES
Applying Expertise; Effective Communication; Learning and Knowledge Sharing; Organizational Commitment; Results-Focused, and; Teamwork and Collaboration.FUNCTIONAL COMPETENCIES
Analysis, Judgement and Decision MakingClient and Service OrientationInnovation and Facilitating ChangeLeadershipNetworking and Building PartnershipsPlanning and OrganisingSuccessful ManagementTECHNICAL COMPETENCIES
Strong knowledge of NGFW, IPS/IDS, segmentation, zero-trust, and SIEM correlation rules (Splunk/Sentinel/QRadar). Familiarity with EDR across endpoints, IAM, MFA, PAM, Zero Trust, and email security (DMARC/DKIM/SPF).
Capacity to lead incident response, forensics, and vulnerability management. Familiarity with threat intelligence operationalization, SOC/MSSP SLAs, NIST CSF, and ISO 27001.
Strong knowledge of multi-cloud security (AWS/Azure/GCP), AI/ML security (training data, model inference, adversarial defense), and LLM risks (prompt injection, data leakage). Familiarity with agentic AI security, encryption, and DLP.
Ability to deliver cybersecurity projects (procurement, bids). Strong knowledge of vendor/SLA/contract performance management.
Education:
Advanced university degree in Computer Science, Information Security, Cybersecurity, Information Systems or a related field OR education from a reputed college of advanced education with a diploma of equivalent standard to that of an advanced university degree in one of the fields above.For internal candidates, a first university degree in one of the fields above in combination with ten years of qualifying experience may be accepted in lieu of an advanced university degree for promotion or rotation purposes.
Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager (CISM) are strongly preferred.GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), Certified Ethical Hacker (CEH), GIAC Security Essentials (GSEC), and Certified Information Systems Auditor (CISA), are desired.
Certified Cloud Security Professional (CCSP), Amazon Web Services (AWS) Certified Security – Specialty, Microsoft
Certified: Azure Security Engineer Associate, and Google Professional Cloud Security Engineer, are desired.
Experience:
At least seven years of progressively responsible experience in cybersecurity operations and security management, including at least three at the international level. A Doctorate in a related field can be considered as a substitute for three years of working experience.
Experience in SIEM, IPS/IDS, NGFW, EPP/EDR, network security; SOC/MSSP oversight with SLA management.
Experience in incident response, digital forensics, large-scale ICT security (DR, business continuity).
Experience with multi-cloud security (SaaS/IaaS/PaaS) and security assessments of AI/ML and LLM systems.
Experience in vulnerability management, threat intelligence, and cybersecurity project delivery (procurement, implementation, vendor management).
Languages:
Knowledge of one of the six official languages of the Union (Arabic, Chinese, English, French, Russian, Spanish) at advanced level and knowledge of a second official language at intermediate level. Knowledge of a third official language would be an advantage. (Under the provisions of Resolution No. 626 of the Council, a relaxation of the language requirements may be authorized in the case of candidates from developing countries: when candidates from such countries possess a thorough knowledge of one of the official languages of the Union, their applications may be taken into consideration.)BENEFITS AND ENTITLEMENTS
Salary:
Total annual salary consists of a net annual salary (net of taxes and before medical insurance and pension funddeductions) in US dollars and a post adjustment (PA) (cost of living allowance). The PA is variable and subject to change without notice in accordance with the rates set within the UN Common System for salaries and allowances.
Annual salary from $ 86,027 + post adjustment $ 72,004
Other allowances and benefits subject to specific terms of appointment, please refer to: What We Offer
Please note that all candidates must complete an on-line application and provide complete and accurate information. To apply, please visit the ITU Careers website. The evaluation of candidates is based on the criteria in the vacancy notice, and may include tests and/or assessments, as well as a competency-based interview. ITU uses communication technologies such as video or teleconference, e-mail correspondence, etc. for the assessment and evaluation of candidates. Please note that only selected candidates will be further contacted and candidates in the final selection step will be subject to reference checks based on the information provided. Messages originating from a non ITU e-mail account - @itu.int - should be disregarded. ITU does not charge a fee at any stage of the recruitment process.
This position is with International Telecommunication Union (ITU). Applications are processed through their official careers portal.
Apply on International Telecommunication Union (ITU) Careers →