Talent.com
Vulnerability Management Officer
Vulnerability Management OfficerOECD • Paris, Île-de-France, France
Vulnerability Management Officer

Vulnerability Management Officer

OECD • Paris, Île-de-France, France
Il y a plus de 30 jours
Type de contrat
  • Temps plein
  • Temporaire
Description de poste

THE EXECUTIVE DIRECTORATE (EXD)

The Executive Directorate (EXD) is the steward of OECD resources on behalf of the Secretary-General. Our focus is on people and their wellbeing; the effective and efficient management of the budget; the safety and security of staff Delegations visitors and of the OECDs data; maintaining and sustaining physical and digital infrastructure; and enabling the convening power of the OECD through conferences meetings and events whether virtual physical or hybrid. As well as providing corporate services functions and management support to our staff and Members we provide integrated strategic and expert advice on corporate policies and management issues to the Secretary-General to Council and to Standing Committees to which we regularly report on corporate matters. We also provide compliance and risk management functions (for management areas under our purview). Ours is a fast-paced environment focused on delivering management excellence across all of our functions.

THE DIGITAL KNOWLEDGE AND INFORMATION SERVICE (EXD/DKI)

Within the Executive Directorate working closely with business partners the Digital Knowledge and Information Service (EXD/DKI) designs and provides secure digital solutions IT and information management services and the technologies to deliver efficient corporate services meet business partners needs and to support and enhance the OECDs global role in building knowledge communicating with the world and interacting with governments to inform and influence policy-making.

The Digital Security Office (EXD/DKI/DSO) leads the OECDs cyber security capability and information management policy: it develops and implements corporate information security policies and technical compliance frameworks conducts security audits and risk assessments supports user awareness campaigns and performs security operations and related compliance monitoring to safeguard the digital assets of the Organisation. It also leads on information management policies practices and culture for the Organisation.

THE POSITION

Reporting to the Head of Digital Security Assurance and Vulnerability Management in the OECD Digital Security Office (EXD/DKI/DSO) as the Vulnerability Management Officer you will be contributing to improving the Organisations Digital Security Posture reducing the attack surface through Vulnerability identification and Management recommending mitigation options and advising on best practice digital Security Controls.

Main Responsibilities

Vulnerability Management:

  • Lead Vulnerability Identification and Remediation: Proactively identify assess and track vulnerabilities across all OECD digital assets and systems. Coordinate and oversee remediation efforts with relevant technical teams to ensure timely resolution and reduction of the organisations attack surface.

  • Specialised Security Assessments: Plan and execute advanced security assessments including annual Red Teaming exercises and penetration tests to evaluate the effectiveness of existing controls and uncover potential weaknesses.

  • Support Digital Solution Risk Assessments (DSRA): Advise on control recommendations during risk reviews for digital solutions (SaaS PaaS on-premise web platforms bespoke projects) to avoid exposure to well-known vulnerabilities and ensure security and compliance. Collaborate with Digital Security and Privacy Risk Managers documenting remediation plans in line with OECD and industry standards (CIS Controls OWASP).

  • Develop and maintain security and privacy controls: Issue mandatory notifications for vulnerability remediation ensuring alignment with OECD policy and requirements. Oversee the implementation of patching and controls and monitor compliance across the organisation.

  • Policy and compliance oversight: Contribute to the development implementation and continuous improvement of digital security policies technical compliance frameworks and vulnerability management protocols. Ensure all digital solutions adhere to the Patch Management Policy and related OECD guidelines.

  • Performance monitoring and reporting: Establish and maintain regular performance monitoring and reporting mechanisms for vulnerability management activities. Provide actionable insights to management and stakeholders.

Stakeholder Engagement & Change Management:

  • Communications and change management: Develop and deliver communications and change management strategies to promote a culture of digital security and privacy by design. Draft guidance documentation and best practices to support staff and reduce the attack surface across the OECD.

  • Workshops and training: Organise facilitate and participate in workshops with stakeholders to raise awareness build capacity and ensure alignment with digital security objectives.

  • Collaboration and support: Assist with stakeholder interaction. Support Directorates in understanding and fulfilling their digital security responsibilities including third-party due diligence and vulnerability assessments.


Qualifications :

Ideal Candidate Profile

Academic Background

  • Post-secondary education in Information Security or a related field or equivalent practical experience. Qualifications or education in Vulnerability Management would be an advantage.

Professional Background

  • Minimum of 3 years of relevant Vulnerability Management experience.

  • Experience in delivering practical Vulnerability Management strategies and practices in organisations in either the public or private sector.

  • Experience in Vulnerability Management Methodologies and Frameworks such as ISO 27001 & 27002 / NIST SP 800-40r4 / SANS/ OWASP/ CVSS.

  • Demonstrated knowledge of the M365 technological environment.

  • Experience in drafting Vulnerability Management and patching documentation and user guidance.

  • Excellent communication skills with the ability to explain complex technical ideas in plain or easy to understand language.

  • Experience with data protection-related matters and strategies would be an advantage.

Tools

  • Knowledge of the following tools would be an asset:

  • Rapid7 Insight Vulnerability Management/ Nexpose

  • Microsoft Defender for Endpoint

  • Microsoft Office

  • M365 suite of applications

  • Microsoft Azure

  • ServiceNow

Languages

  • Fluency in one of the two OECD official languages (English and French) and a knowledge of or a willingness to learn the other.

  • Knowledge of other languages would be an asset.

Core Competencies

  • OECD staff are expected to demonstrate behaviours aligned to six core competencies which will be assessed as part of this hiring processes: Vision and Strategy (Level 1); Enable People (Level 1); Ethics and Integrity (Level 2); Collaboration and Horizontality (Level 2); Achieve Results (Level 2); Innovate and Embrace Change (Level 2).

  • There are three possible levels for each competency. The level for each competency is determined according to the specific needs of each job role and its associated grade.

  • To learn more about the definitions for each competency for levels 1-3 please refer to OECD Core Competencies.


Additional Information :

Closing Date

  • Applications should reach us no later than 4 January 2026 23h59 (Paris time).

Contract Duration

  • Fixed-term contract of 3 years.

What the OECD offers

  • Depending on level of experience monthly salary starts at 7 644.78 EUR plus allowances based on eligibility exempt of French income tax.

  • Click here to learn more about what we offer and why the OECD is a great place to work.

  • Click here to browse our People Management Guidebook and learn more about all aspects relating to people at the OECD our workplace environment and many other policies supporting staff in their daily life.

  • Please note that the appointment may be made at one grade lower in the specified job family based on the qualifications and professional experience of the selected applicant.

The OECD is an equal opportunity employer and welcomes the applications of all qualified candidates who are nationals of OECD member countries irrespective of their racial or ethnic origin opinions or beliefs gender sexual orientation health or disabilities.

The OECD promotes an optimal use of resources in order to improve its efficiency and effectiveness. Staff members are encouraged to actively contribute to this goal.


Remote Work :

No


Employment Type :

Full-time


Key Skills
Databases,Inventory Control,Law Enforcement,Warehouse Experience,Computer Literacy,Business requirements,Sharepoint,Training & Development,Property Management,Public Speaking,Supervising Experience,Stocking
Experience: years
Vacancy: 1
Créer une alerte emploi pour cette recherche

Vulnerability Management Officer • Paris, Île-de-France, France

Offres similaires
Project Management Officer F/H

Project Management Officer F/H

WAAT • Malakoff, France, FR
Temps plein +1
Chez WAAT, on ne fait rien comme les autres… mais toujours avec le sourire ! Ici, c’est un univers où dépassement de soi, passion et bonne humeur partagée règnent en maîtres.Chez nous, la RSE n’est...Voir plus
Dernière mise à jour : il y a 3 jours • Offre sponsorisée
Chef de projet informatique IT – Asset Management / Green IT / Delivery Officer (IT) / Freelance

Chef de projet informatique IT – Asset Management / Green IT / Delivery Officer (IT) / Freelance

Groupe Aptenia • Paris, Île-de-France, FR
Temps plein
Projet Asset Management (VESI).Projet stratégique en cours depuis 18 mois visant à transformer l’outil Asset en solution globale d’Asset Management.Coordination des équipes (Développement, Platefor...Voir plus
Dernière mise à jour : il y a 2 jours • Offre sponsorisée
Remote Senior Solutions Architect - Growth

Remote Senior Solutions Architect - Growth

KBR • Chantilly, Hauts-de-France, France
Temps plein
A leading technology firm in Hauts-de-France is seeking a Senior Solution Architect to lead complex technical solutions in various mission areas including Defense and Intelligence.The ideal candida...Voir plus
Dernière mise à jour : il y a 2 jours • Offre sponsorisée
Ingénieur Cybersécurité - Gestion Des Vulnérabilités H/F -

Ingénieur Cybersécurité - Gestion Des Vulnérabilités H/F -

SERMA Safety and Security • Paris, France, FR
Temps plein
SERMA Group est un acteur indépendant français dans le conseil et l’expertise spécialisée dans les systèmes électroniques embarqués et industriels, ainsi que la sécurité des systèmes d’information ...Voir plus
Dernière mise à jour : il y a 1 jour • Offre sponsorisée
Climate Mitigation And Adaptation Consultants

Climate Mitigation And Adaptation Consultants

NTU International A/S • Paris, France, FR
Temps plein
Climate Mitigation and Adaptation ConsultantsLocation: FranceContract Type: Project-Based/ConsultancyApplication Deadline: Rolling ApplicationsAbout the Opportunity:We are creating a pool of Consul...Voir plus
Dernière mise à jour : il y a 3 jours • Offre sponsorisée
Vulnerability Manager

Vulnerability Manager

BEHIVE • Paris, France, FR
Temps plein
Gestionnaire de vulnérabilités expérimenté pour une entreprise internationale, responsable de la détection, de l'évaluation et du suivi des failles de sécurité sur tous les systèmes.Voir plus
Dernière mise à jour : il y a 1 jour • Offre sponsorisée
Remédiation des Vulnérabilités Applicatives - Équipe AppSec

Remédiation des Vulnérabilités Applicatives - Équipe AppSec

PSSWRD • Issy-les-Moulineaux, Île-de-France, FR
Temps plein
Les équipes AppSec disposent aujourd’hui de multiples sources de remontée de vulnérabilités : pentests, bug bounty, outils SAST (ex.Checkmarx) et Cyber Threat Intelligence (CTI).En revanche, il exi...Voir plus
Dernière mise à jour : il y a 15 heures • Offre sponsorisée • Nouvelle offre
OT analyste informatique NOZOMI (IT) / Freelance

OT analyste informatique NOZOMI (IT) / Freelance

Groupe Aptenia • Paris, Île-de-France, FR
Temps plein
Soutenir l'intégration des sondes OT dans l'équipe IR.Créer des schémas de détection pour les alertes reçues.Création de règles pour les faux positifs.Ajustement des règles de détection de la conso...Voir plus
Dernière mise à jour : il y a 2 jours • Offre sponsorisée
Deputy Head of Compliance (H/F) - Tikehau Investment Management - Annonces

Deputy Head of Compliance (H/F) - Tikehau Investment Management - Annonces

Tikehau Investment Management - Annonces • Paris, France
CDI
Vous rejoindrez une équipe jeune et dynamique, composée de 9 compliance officers et placée sous la responsabilité du Head of Compliance de Tikehau Investment Management.Le département Conformité et...Voir plus
Dernière mise à jour : il y a 28 jours • Offre sponsorisée
Ingénieur sécurité Opérationnelle – VULNERABILITES - N2

Ingénieur sécurité Opérationnelle – VULNERABILITES - N2

KEONI CONSULTING • Paris, Île-de-France, FR
Temporaire
Accompagner l'équipe de gestion des vulnérabilités.Contrainte forte du projet .Périmètre étendu et sensible, Environnement international.Check du matin sur l'état des traitements de la nuit, les no...Voir plus
Dernière mise à jour : il y a 6 jours • Offre sponsorisée
Cyber Defence Specialist - Vulnerability

Cyber Defence Specialist - Vulnerability

Airbus • Paris, France, FR
Temps plein
Job Description:**Version française*Airbus Protect* est une entreprise européenne spécialisée qui fournit des services dans la Cybersécurité, la Safety et la Sustainability.Notre mission est de pro...Voir plus
Dernière mise à jour : il y a 2 heures • Offre sponsorisée • Nouvelle offre
Consultant Gestion des Vulnérabilités

Consultant Gestion des Vulnérabilités

Ewolve • Paris, Île-de-France, FR
CDI
Dans le cadre du renforcement de son dispositif de cybersécurité, notre client,.Consultant en gestion des vulnérabilités.Vous intégrerez l’équipe en charge de la gestion des vulnérabilités et assur...Voir plus
Dernière mise à jour : il y a 6 jours • Offre sponsorisée
Chief Information & Security Officer

Chief Information & Security Officer

Blue Search Conseil • Paris, Île-de-France, France
Temps plein
En forte croissance, une prestigieuse maison du secteur du luxe renforce significativement sa gouvernance et ses capacités de cybersécurité.Dans le cadre d’une réorganisation stratégique de sa DSI,...Voir plus
Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
Chapter Lead (Expert Alerting) H/F (IT) / Freelance

Chapter Lead (Expert Alerting) H/F (IT) / Freelance

ALLEGIS GROUP • Paris, Île-de-France, FR
Temps plein
Définir les bonnes pratiques en.Améliorer la fiabilité et le temps de réponse aux incidents.Standardiser les dashboards, seuils, KPIs (SLO/SLA).Accompagner les squads dans la mise en place d’outils...Voir plus
Dernière mise à jour : il y a 7 jours • Offre sponsorisée
Release Management Consultant - Murex

Release Management Consultant - Murex

Murex • Paris, France
Temps plein
Murex is a global fintech leader in trading, risk management and processing solutions for capital markets.Operating from our 19 offices, 3 400 Murexians from over 65 different nationalities ensure ...Voir plus
Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
Head of Global Training Operations

Head of Global Training Operations

Exclusive Networks • Paris, Île-de-France, France
Temps plein
Global Talent Acquisition Director & Diversity and Inclusion Manager at Exclusive Networks with expertise in HR.Exclusive Networks is the global cybersecurity go-to-market specialist that provides ...Voir plus
Dernière mise à jour : il y a 19 jours • Offre sponsorisée
Senior Solution Architect - Growth

Senior Solution Architect - Growth

KBR • Chantilly, Hauts-de-France, France
Temps plein
Senior Solution Architect - Growth.Join KBR's Mission Technology Solutions team and help shape the future of critical missions across government and commercial sectors.We are seeking experienced Se...Voir plus
Dernière mise à jour : il y a 2 jours • Offre sponsorisée
Head of Risk - Commodities H/F - Goodman Masson

Head of Risk - Commodities H/F - Goodman Masson

Goodman Masson • Vanves, France
Temps plein
Je recrute pour mon client, acteur spécialisé dans le trading de commodités, un Head of Risk H/F dans le cadre d’une création de poste.Ce poste en CDI est basé à Paris.Accountable to the Board and ...Voir plus
Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée