Senior IT Assistant, Security, Risk and Compliance

Tags: English language
  • Added Date: Thursday, 04 September 2025
  • Deadline Date: Friday, 19 September 2025
5 Steps to get a job in the United Nations

Senior IT Assistant, Security, Risk and Compliance Job #: req34241 Organization: World Bank Sector: Information Technology Grade: GD Term Duration:ย 3 years 0 months Recruitment Type: Local Recruitment Location: Chennai,India Required Language(s): English Preferred Language(s): Closing Date: 9/18/2025 (MM/DD/YYYY) at 11:59pm UTC

ย 

ย Description

Do you want to build a career that is truly worthwhile? Working at the World Bank Group provides a unique opportunity for you to help our clients solve their greatest development challenges. The World Bank Group is one of the largest sources of funding and knowledge for developing countries; a unique global partnership of five institutions dedicated to ending extreme poverty, increasing shared prosperity and promoting sustainable development. With 189 member countries and more than 130 offices worldwide, we work with public and private sector partners, investing in groundbreaking projects and using data, research, and technology to develop solutions to the most urgent global challenges. For more information, visit www.worldbank.org
ITS Vice Presidency Context:
The Information and Technology Solutions (ITS) Vice Presidential Unit (VPU) enables the World Bank Group to achieve its mission of ending extreme poverty and boost shared prosperity on a livable planet by delivering transformative information and technologies to its staff working in over 150+ locations. For more information on ITS, see this video:https://www.youtube.com/watch?reload=9&v=VTFGffa1Y7w
Vice Presidency Context
Information and Technology Solutions (ITS) enables the WBG to achieve its mission of ending extreme poverty by 2030 and boosting shared prosperity in a sustainable manner by delivering transformative information and technologies to its staff working in over 130 client countries.
ITS services range from: establishing the infrastructure to reach and connect staff and development stakeholders; providing the devices and agile technology and information applications to facilitate the science of delivery through decentralized services; creating and maintaining tools to integrate information across the World Bank Group, the clients we serve and the countries where we operate; and delivering the computing power staff need to analyze development challenges and identify solutions.
The ITS business model combines dedicated business solutions centers that provide services tailored to specific World Bank Group business needs and shared services that provide infrastructure, applications and platforms for the entire Group. ITS is one of three VPUs that have been brought together as the World Bank Group Integrated Services (WBGIS), to provide enhanced corporate core services and enable the institution to operate as one strategic and coordinated entity.
Unit Context
The ITS Information Security and Risk Management (ITSSR) unit, headed by the Chief Information Security Officer (CISO), is responsible for providing leadership in managing the functions and activities of information security and risk across the World Bank Group, enabling the achievement of WBGโ€™s business objectives.ย  ITSSR enables and facilitates a risk aware culture, ensures that WBG information assets are protected in an effective, efficient, and balanced manner; and IT security and risk management efforts throughout the World Bank Group are coordinated and aligned to the Bank's business and IT strategy.ย  ย ITSSR establishes and maintains the World Bank Group's IT and InfoSec policies and standards; develops and engineers the WBGโ€™s information security plans and solutions; responds to security incidents; and ensures that the information risks are identified, assessed, and managed in consistent with the overall risk management approach and with the established appetite and tolerance.ย  ITSSR consists of three main units:ย  1) ITS Risk Management, Compliance, and Policy, 2) ITS Information Security Engineering and Operations (ITSIS), and 3) Program Management Office (PMO).
Note: If the selected candidate is a current Bank Group staff member with a Regular or Open-Ended appointment, s/he will retain his/her Regular or Open-Ended appointment. All others will be offered a 3 year term appointment.
Duties and Accountabilities:
ITSIS is seeking to fill the position of Senior IT Assistant, Security, Risk and Compliance. The successful candidate will partner with other security professionals to develop AI applications and automation playbooks supporting security operations team.ย 
Note: If the selected candidate is a current Bank Group staff member with a Regular or Open-Ended appointment, s/he will retain his/her Regular or Open-Ended appointment. All others will be offered a 3 year term appointment.
Scope of Work

โ€ข Plan and execute the implementation of threat management solutions using a data driven and Agile approach.โ€ข Continuously identify and implement necessary tools and infrastructure to support and enhance the threat management program. Develop scripts, tools, and methodologies to strengthen security operation.

โ€ข Develop and build applications and APIs using Python, Power Platform, SharePoint Online and Data Modeling capabilities using Dataverse following Agile principles.โ€ข Employ Python for backend and use technologies like HTML, CSS, JavaScript for front-end to build scalable web applications. Ensure seamless integration and user experience.

โ€ข Design and manage Azure cloud infrastructure, focusing on deploying scalable applications and services. Optimize cloud resources for security, performance, and cost.โ€ข Utilize OpenAI's GPT models via Azure, including fine-tuning, deploying, and scaling.

โ€ข Integrate AI/ML models using OpenAI and other AI frameworks into applications. Apply machine learning algorithms to enhance application intelligence and functionality.โ€ข Create RESTful APIs with Python and integrate third-party APIs. Ensure the APIs are secure, efficient, and scalable.

โ€ข Design, implement, and manage SQL and NoSQL databases. Focus on data integrity, performance optimization, and security.โ€ข Build and maintain applications using Power platform, automate using power automate, perform data modeling using Dataverse, build dashboards and reports using Power BI.

โ€ข Implement security best practices and protocols to protect data and comply with regulations. Use tools and methodologies to secure applications and data.โ€ข Maintain code quality with reviews, testing, and documentation. Use version control (e.g., Git) and document development processes for maintainability.

โ€ข Keep up to date with the latest in software development, cloud technologies, and AI. Innovate and apply new technologies to improve application performance and user experience.โ€ข Continuously research, explore, and document newly onboarded enterprise technologies and data sources to identify new artifacts and analytical methodologies that can be leveraged to detect cyber threats.

โ€ข Leverage operational results to identify, communicate, and mitigate identified threats as well as implement knowledge sharing across various teams.โ€ข Identify process and resiliency improvement areas; propose changes.

โ€ข Bring an applied understanding of relevant and emerging technologies, begin to identify opportunities to provide input to the team and coach others, and embed learning and innovation in the day-to-dayโ€ข Perform other duties as assigned.

Selection Criteria

โ€ข Bachelor's degree in computer science, information technology, systems engineering, or a related field.

โ€ข Direct experience working with large datasets and log analysis tools including but not limited to: SIEM, EDR, Python, PowerShell, etc.โ€ข Demonstrable knowledge of large enterprise environments, network protocols, network devices, operating systems (Windows, macOS, Linux, etc.), and cloud environments.

โ€ข Experience using Splunkโ€™s Search Processing Language (SPL) and Microsoftโ€™s Kusto Query Language (KQL).โ€ข Familiarity with common enterprise scripting languages (PowerShell, Python, Bash, etc.).

๐Ÿ“š ๐——๐—ถ๐˜€๐—ฐ๐—ผ๐˜ƒ๐—ฒ๐—ฟ ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—š๐—ฒ๐˜ ๐—ฎ ๐—๐—ผ๐—ฏ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—จ๐—ก ๐—ถ๐—ป ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฏ! ๐ŸŒ๐Ÿค ๐—ฅ๐—ฒ๐—ฎ๐—ฑ ๐—ผ๐˜‚๐—ฟ ๐—ก๐—˜๐—ช ๐—ฅ๐—ฒ๐—ฐ๐—ฟ๐˜‚๐—ถ๐˜๐—บ๐—ฒ๐—ป๐˜ ๐—š๐˜‚๐—ถ๐—ฑ๐—ฒ ๐˜๐—ผ ๐˜๐—ต๐—ฒ ๐—จ๐—ก ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฏ ๐˜„๐—ถ๐˜๐—ต ๐˜๐—ฒ๐˜€๐˜ ๐˜€๐—ฎ๐—บ๐—ฝ๐—น๐—ฒ๐˜€ ๐—ณ๐—ผ๐—ฟ ๐—จ๐—ก๐—›๐—–๐—ฅ, ๐—ช๐—™๐—ฃ, ๐—จ๐—ก๐—œ๐—–๐—˜๐—™, ๐—จ๐—ก๐——๐—ฆ๐—ฆ, ๐—จ๐—ก๐—™๐—ฃ๐—”, ๐—œ๐—ข๐—  ๐—ฎ๐—ป๐—ฑ ๐—ผ๐˜๐—ต๐—ฒ๐—ฟ๐˜€! ๐ŸŒ

โš ๏ธ ๐‚๐ก๐š๐ง๐ ๐ž ๐˜๐จ๐ฎ๐ซ ๐‹๐ข๐Ÿ๐ž ๐๐จ๐ฐ: ๐๐จ๐ฐ๐ž๐ซ๐Ÿ๐ฎ๐ฅ ๐“๐ž๐œ๐ก๐ง๐ข๐ช๐ฎ๐ž๐ฌ ๐ก๐จ๐ฐ ๐ญ๐จ ๐ ๐ž๐ญ ๐š ๐ฃ๐จ๐› ๐ข๐ง ๐ญ๐ก๐ž ๐”๐ง๐ข๐ญ๐ž๐ ๐๐š๐ญ๐ข๐จ๐ง๐ฌ ๐๐Ž๐–!

โ€ข Demonstrated knowledge of cloud platforms, with a specific focus on Microsoft Azure, including Azure WebApp, Azure functions, Azure OpenAI, APIM, Azure SQL Database, and Azure Blob Storage.โ€ข Deep understanding in using any of the DevOps tool such as Azure DevOps.

โ€ข Experience with Azure's OpenAI technologies and familiarity with machine learning frameworks, indicating the ability to integrate AI capabilities into applications.โ€ข Proficient in front-end technologies, including HTML, CSS, JavaScript, and frameworks like React or Angular, showcasing the ability to work on full-stack projects.

โ€ข Database Management: Experience in designing, implementing, and managing both SQL and NoSQL databases, ensuring data integrity, security, and performance optimization.ย โ€ข Proven ability to develop and manage RESTful APIs, along with integrating third-party APIs, demonstrating expertise in creating scalable and maintainable service interfaces.

โ€ข Experience in understanding and analyzing various log formats from various sources.โ€ข Familiarity with industry-standard processes defined for systems design, database design, development, testing, and integration phases of a project, including Agile-based implementations.

โ€ข Experience working in Agile environments, participating in Agile ceremonies, and utilizing Agile methodologies for security operations and threat hunting.ย โ€ข Ability to work well under pressure and meet tight deadlines. Demonstrate a high level of motivation, confidence, integrity and responsibility.

โ€ข Ability to be organized, responsive and to be able to effectively multi-task with a focus on driving results.โ€ข Demonstrate excellent interpersonal skills, including the ability to work in dependently, effectively in a team/task force as a team member.ย 

โ€ข Leverage diverse ideas, experiences, thoughts, and perspectives to the benefit of the organization.โ€ข Ability to learn new skills and knowledge on an on-going basis through self-initiative and tackling challenges.

โ€ข Excellent problem solving, communication and collaboration skills.
Preferred Skillsets / Requirements

โ€ข GIAC Certified Intrusion Analyst (GCIA)ย  or GIAC Certified Incident Handler (GCIH)Competenciesย 

โ€ข Client Understanding and Advising - Looks at issues from the clientโ€™s perspective and takes action beyond normal expectations to ensure client satisfaction.โ€ข Learning Orientation - Stays abreast of new trends and developments in own specialty area, the broader industry, and exposes self to increasingly more challenging projects and opportunities to learn.

โ€ข Broad Business Thinking - Maintains an in-depth understanding of the long term implications of decisions both for department and the clientโ€™s business. Ensures that decisions are supported by relevant stakeholders as well as sound performance data.โ€ข Compliance with Standards - Monitors and maintains records on requests for information and assistance.

โ€ข Knowledge of Emerging Technology - Tests new technology to evaluate capability compared to specifications.

World Bank Group Core Competencies

The World Bank Group offers comprehensive benefits, including a retirement plan; medical, life and disability insurance; and paid leave, including parental leave, as well as reasonable accommodations for individuals with disabilities.

We are proud to be an equal opportunity and inclusive employer with a dedicated and committed workforce, and do not discriminate based on gender, gender identity, religion, race, ethnicity, sexual orientation, or disability.

Learn more about working at theย World Bankย andย IFC, including our values and inspiring stories.

Recommended for you