Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us
The International Livestock Research Institute (ILRI) works to improve food security and reduce poverty in developing countries through research for better and more sustainable use of livestock. ILRI is a CGIAR research centre - part of a global research partnership for a food-secure future.
About the position
- The position combines a 60% allocation to the CGIAR System-wide Cybersecurity Assurance Lead function, hosted by ILRI, and a 40% allocation to ILRI Cybersecurity Governance and Assurance responsibilities.
- At the CGIAR level, the position will support the implementation and ongoing coordination of the Integrated Cybersecurity Governance Framework (ICGF), maintain cybersecurity standards, coordinate cybersecurity reporting and dashboards, facilitate collaboration among CGIAR cybersecurity focal points, and provide cybersecurity assurance reporting to CGIAR leadership.
- At the ILRI level, the position will support cybersecurity governance, risk management, compliance, security assurance, cybersecurity strategy implementation, security awareness and cyber resilience initiatives to strengthen ILRI's cybersecurity posture and support digital transformation objectives.
- The role serves as ILRI's focal point for cybersecurity governance and assurance and provides system-wide cybersecurity coordination, reporting and assurance support across the CGIAR System.
Key Responsibilities
CGIAR CYBERSECURITY ASSURANCE LEAD RESPONSIBILITIES (60%)
Standards & Catalogue
- Collate, document, co-develop, and maintain a minimum CGIAR Cybersecurity Standards Catalogue (feasible monitorable controls only).
- Define and publish incident severity levels and SLA expectations as system-wide standards.
- Coordinate with Centre focal points to ensure standards are understood, adopted, and evidenced.
Scorecards & Dashboards
- Design, build, and maintain a central CGIAR Cybersecurity Scorecard and dashboards (Power BI or equivalent) using centrally accessible telemetry and metrics data.
- Aggregate data from Centre security platforms (e.g., SentinelOne, Volexity MDR, Microsoft Defender, KnowB4) into unified reporting views.
Reporting & Governance
- Produce and present quarterly cyber-risk reports to GLT, the Audit and Risk Committee (AFRC/IPB), and ICT leaders — ensuring cybersecurity visibility extends beyond the IT function.
- Prepare ad-hoc briefings for senior leadership and Boards as required.
- Maintain a one-page Decision Rights Charter (RACI & escalation) for system-wide cybersecurity.
Coordination and Network Leadership
- Convene and lead the distributed cybersecurity focal-point network (one focal point per Centre, each ~20% FTE).
- Establish a regular meeting cadence (monthly or as agreed) for focal points to share threat intelligence, coordinate remediation, and align on standards.
- Liaise with the Managed Security Service Provider (MSSP) and the 1CGSec working group.
- Coordinate with Internal Audit, the Digital Transformation Accelerator (DTA), and other relevant governance bodies to avoid duplication.
Monitoring Integration (Year 1 Setup)
- Oversee the one-time integration project to connect Centre security-platform outputs into the central reporting infrastructure.
- Specify minimum telemetry and metrics-reporting requirements for all Centres.
Roadmap & Continuous Improvement
- Track and document lessons learned, gaps, and readiness indicators for selective adoption of Model 2 elements (shared playbooks, harmonised incident classification, SLAs).
- Prepare a recommendation paper for the 12–18-month review gateway on whether and how to advance to Model 2.
Procurement and Vendor Relations Coordination
- Support cybersecurity procurement activities, cost distribution and payment follow-up.
- Maintain an inventory of cybersecurity solutions, vendors, contracts and Centre adoption of these solutions.
ILRI CYBERSECURITY GOVERNANCE AND ASSURANCE RESPONSIBILITIES (40%)
Cybersecurity Strategy and Governance
- Support the development and implementation of ILRI's cybersecurity strategy, roadmap and annual work plans.
- Coordinate implementation of the institutional Cybersecurity Roadmap, monitor delivery against agreed milestones, track benefits realised and report progress to management.
- Coordinate the development, review and maintenance of cybersecurity policies, standards, procedures and guidelines.
- Provide trusted cybersecurity advice to Executive Management, project sponsors and business leaders to support informed, risk-based decision-making.
- Support the implementation of cybersecurity governance practices across the institution.
Cybersecurity Risk Management
- Coordinate the maintenance of the institutional cybersecurity risk register.
- Conduct cybersecurity risk assessments and coordinate risk mitigation activities.
- Monitor emerging cyber threats and vulnerabilities affecting ILRI.
- Prepare regular cybersecurity risk reports for management and governance committees.
Security Assurance and Compliance
- Coordinate vulnerability assessments, penetration testing and cybersecurity control reviews.
- Track remediation of identified vulnerabilities and audit findings.
- Support compliance with regulatory, donor, CGIAR and institutional cybersecurity requirements.
- Coordinate cybersecurity-related internal and external audits.
- Coordinate periodic cybersecurity maturity assessments and benchmarking exercises.
- Support compliance with data protection, privacy and information security requirements across the institution.
- Coordinate cybersecurity risk assessments of third-party service providers, cloud platforms, technology vendors and strategic partners, and monitor remediation of identified risks.
Cybersecurity Operations Coordination
- Coordinate governance activities relating to cybersecurity operations and security monitoring.
- Coordinate cybersecurity incident reporting, investigations and post-incident reviews.
- Review security monitoring outputs from internal teams and managed security service providers.
- Recommend improvements to security controls and monitoring capabilities.
- Coordinate implementation of cybersecurity improvement initiatives arising from incidents, audits, assessments and risk reviews.
Security Architecture and Digital Transformation
- Support security reviews for new systems, projects and technology initiatives.
- Provide technical input on cybersecurity considerations for cloud, data, AI and digital transformation initiatives.
- Support the development and implementation of governance, assurance and risk management practices for AI-enabled solutions and emerging technologies, ensuring their secure, responsible and compliant adoption across the institution.
- Support the adoption of secure-by-design principles across institutional projects.
Cybersecurity Awareness and Culture
- Develop and coordinate cybersecurity awareness and training programmes.
- Coordinate phishing simulations and security awareness campaigns.
- Promote cybersecurity awareness and responsible technology use across the institution.
Business Continuity and Cyber Resilience
- Support cyber resilience, business continuity and disaster recovery planning and initiatives.
- Coordinate cyber incident simulation and tabletop exercises.
- Participate in assessments of organisational preparedness for cyber incidents and recommend improvements.
Other Duties
- Perform any other related duties as may be assigned by the supervisor.
Requirements
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, Information Technology, Risk Management, or a related field.
- Professional certification in one or more of the following areas is required: CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CCSP, or equivalent cybersecurity certification.
- Microsoft Security and GIAC Certifications will be an added advantage.
- At least seven (7) years of progressively responsible experience in cybersecurity, information security, IT risk management, security governance, compliance or IT audit, including at least three (3) years in cybersecurity governance, risk management and/or assurance.
- Demonstrated experience implementing or assessing cybersecurity frameworks including ISO 27001, NIST Cybersecurity Framework and CIS Controls.
- Experience coordinating cybersecurity governance, assurance, compliance or risk management activities within multi-stakeholder environments.
- Experience developing cybersecurity dashboards, scorecards or management reports.
- Experience preparing reports and presenting technical information to management or governance committees.
- Experience working with Managed Security Service Providers (MSSPs) and third-party security vendors will be an added advantage.
- Experience supporting Microsoft security technologies, cloud security or endpoint security solutions will be an added advantage.
- Experience working within international, research, development, NGO, CGIAR, or similarly federated organisations will be an added advantage.
Skills and Competencies
- Knowledge of cybersecurity governance, risk management and assurance practices.
- Knowledge of cybersecurity frameworks and standards, including ISO 27001, NIST Cybersecurity Framework and CIS Controls.
- Knowledge of cybersecurity compliance, audit coordination and risk assessment.
- Knowledge of cloud, network, endpoint and identity security principles.
- Ability to coordinate cybersecurity governance and assurance activities across multiple stakeholders.
- Ability to prepare cybersecurity dashboards, reports and presentations for management.
- Strong communication, facilitation and stakeholder management skills.
- Strong analytical and problem-solving skills.
- Ability to influence and collaborate without direct authority.
- Excellent written, presentation and interpersonal communication skills.
- Ability to operate effectively within multicultural, geographically dispersed and matrix-managed environments.