
Information Security Lead
- Hybrid
- International Office
Job description
Location: Any MSF office
Contract: Fixed term at 100% position - The term of this assignment is intended to be for a period of two (2) years, nevertheless, the duration of the contract may be subject to the employment regulations and labor laws of the country where the selected candidate is based.
Starting date: 15th of November 2026
Deadline to apply: 18th of October
Compensation and Benefits: MSF practice is to offer the compensation and benefits package in line with the MSF entity offering the contract.
I. MSF INTERNATIONAL
Médecins Sans Frontières (MSF) is an international, independent, medical humanitarian organisation that delivers emergency aid to people affected by armed conflict, epidemics, healthcare exclusion and natural disasters. MSF offers assistance to people based only on need and irrespective of origins, religion, gender or political affiliation. MSF International provides coordination, information and support to the MSF Movement, as well as implements international projects/programmes and initiatives as requested.
II. POSITION BACKGROUND
The Information Systems Management (ISM), one of the international platforms of MSF gathering all the Heads of IT/IS from key MSF entities, has been mandated by MSF’s executive governance body, the Full Excom, to lead the development of an international information systems management strategy seeking to optimise interoperability across MSF in priority areas. The ISM Platform is responsible for setting standards for IT/IS architecture and technology development and aims to promote targeted innovation in information technology/information systems (IT/IS).
Critical to this role, and in response to an increasingly complex cyber and global regulatory landscape, the ISM Platform spearheaded the development of a global information security policy framework back in 2020, which has continued to evolve.
In its strategic ambitions, the ISM Platform has committed to prioritising information security and incident resilience as a cross-cutting theme across all its initiatives. The role of the Information Security Lead is to develop an effective execution strategy and a programme to improve MSF’s overall information security posture and governance of information security in the movement.
III. PLACE IN THE ORGANISATION
The Information Security Lead will:
Report hierarchically to the International Information Systems Coordinator (who chairs the ISM Platform), with functional oversight provided by the ISM Platform
Work closely with the members of the ISM Platform, InfoSec focal points in each section, ISM InfoSec WG, MSF SITS (Shared IT Services) and other MSF stakeholders to ensure the information security initiatives, working group(s) and/or task force(s) created/sponsored/guided by the ISM are all aligned to the evolving needs of the organisation and the ISM’s strategic vision
Work in collaboration with the ISM Coordination team to ensure a consistent approach to programme and project management within the ISM portfolio and Working Group (WG) initiatives
IV. OBJECTIVES OF THE POSITION
The Information Security Lead will lead the development of the roadmap for information security governance, risk & compliance in MSF under the guidance of the ISM platform and in close collaboration with the Info Sec WG. The Information Security Lead will provide strategic guidance, operational support, and incident response expertise across headquarters and field missions, balancing security requirements with the realities of medical and humanitarian operations.
The Information Security Lead will establish the governance mechanisms necessary to ensure better identification, monitoring and mitigation of information security risks in MSF. This role will recommend planning and allocation of infosec resources, and develop the necessary processes/frameworks to do so.
Specific Objectives
An effective global information security framework, strategy, and roadmap are in place to guide MSF’s short-, medium-, and long-term security priorities.
Priority information security risks are proactively managed through a shared and structured organisational approach.
Security incidents requiring intersectional coordination are responded to effectively, limiting impact and supporting resilience.
Technical information security decisions across MSF are informed by reliable expert guidance.
Sensitive information is managed securely and in line with relevant governance requirements.
Organisational information security awareness and capability are strengthened on an ongoing basis.
Emerging threats and external developments relevant to MSF are monitored and reflected in a stronger overall security posture.
V. KEY RESPONSIBILITIES
Information Security Strategy and Governance
Develop, implement, and maintain MSF’s information security strategy and roadmap
Define and maintain information security policies, standards, and procedures
Advise senior management on information security risks and mitigation options, including new resourcing and delivery models
Support definition of mutualised approaches for selected information security capabilities across MSF (e.g. baseline policies/standards, security monitoring / SIEM-SOC options, incident coordination, third-party security assurance, etc.)
Contribute to organisational risk management and governance processes
Risk Management
Identify, assess, and prioritise information security risks in the movement
Conduct and support information security risk assessments for existing and new initiatives
Propose feasible mitigation measures
Support the documentation and acceptance of residual risks
Incident Response and Crisis Management
Lead responses to movement-wide information security incidents
Support field missions and headquarters during high‑pressure or sensitive incidents
Coordinate with relevant functions (IT, legal, communications, HR, security, etc.)
Ensure post‑incident reviews and follow‑up actions are completed
Technical and Operational Security Oversight
Advise on matters such as infrastructure, network, cloud, and endpoint security
Advise on security matters such as identity & access management and remote working
Ensure security requirements are integrated into system design, procurement, and third‑party arrangements
Data Protection, Ethics, and Safeguarding
Advise on data classification, minimisation, retention, and secure sharing
Work closely with data protection, legal, safeguarding, and other stakeholders
Promote digital practices that minimise risks of harm to individuals and communities
Awareness and Capacity Building
Develop and deliver information security awareness and training programs
Build information security capacity among staff
Translate complex security concepts into clear, practical guidance
Coordination and Representation
Collaborate closely with all relevant functions
Chair the ISM Information Security Working Group sessions
Coordinate with external service providers and security experts
Represent MSF in relevant information security and humanitarian forums
Monitor emerging threats relevant to humanitarian and medical organisations
Job requirements
Education:
Minimum Bachelor's degree in a technical discipline (Computer Science, Cybersecurity, Information Technology, etc.) or equivalent
Certification as a security professional, e.g. Certified Information Systems Security Professional (CISSP) or Certified Information Security Auditor (CISA)
Experience and skills:
Minimum 7 years’ experience in information security or security risk management.
Strong expertise in cloud, network, and cybersecurity, including incident response, vulnerability management, DLP, IDS/IPS, and penetration testing.
Good knowledge of security frameworks, risk management, and compliance requirements (e.g. NIST, ISO 27001, CIS, GDPR, PCI DSS).
Experience developing security policies, standards, and enterprise solutions in complex, decentralised, and international environments.
Knowledge of business continuity and disaster recovery.
Strong leadership, communication, analytical, and cross-cultural collaboration skills, with high ethical standards and alignment with MSF values.
Languages:
Fluent spoken and written English
Other:
International travel may be required a few times a year
Occasional availability outside normal working hours during incidents
- Geneva, Genève, Switzerland
or
All done!
Your application has been successfully submitted!
You've already applied for this job
Thank you for your interest - we've already received your application, so this new submission can't be accepted. Your previous application is on file.
If you need assistance or believe this is an error, please email us at apply@msf.recruitee-email.com
