Vulnerability Management Officer
- Lead Vulnerability Identification and Remediation : Proactively identify, assess, and track vulnerabilities across all OECD digital assets and systems. Coordinate and oversee remediation efforts with relevant technical teams to ensure timely resolution and reduction of the organisation's attack surface.
- Specialised Security Assessments : Plan and execute advanced security assessments, including annual Red Teaming exercises and penetration tests, to evaluate the effectiveness of existing controls and uncover potential weaknesses.
- Support Digital Solution Risk Assessments (DSRA) : Advise on control recommendations during risk reviews for digital solutions (SaaS, PaaS, on-premise, web platforms, bespoke projects) to avoid exposure to well-known vulnerabilities and ensure security and compliance. Collaborate with Digital Security and Privacy Risk Managers documenting remediation plans in line with OECD and industry standards (CIS Controls, OWASP).
- Develop and maintain security and privacy controls : Issue mandatory notifications for vulnerability remediation, ensuring alignment with OECD policy and requirements. Oversee the implementation of patching and controls and monitor compliance across the organisation.
- Policy and compliance oversight : Contribute to the development, implementation, and continuous improvement of digital security policies, technical compliance frameworks, and vulnerability management protocols. Ensure all digital solutions adhere to the Patch Management Policy and related OECD guidelines.
- Performance monitoring and reporting : Establish and maintain regular performance monitoring and reporting mechanisms for vulnerability management activities. Provide actionable insights to management and stakeholders.
- Communications and change management : Develop and deliver communications and change management strategies to promote a culture of digital security and privacy by design. Draft guidance documentation and best practices to support staff and reduce the attack surface across the OECD.
- Workshops and training : Organise, facilitate, and participate in workshops with stakeholders to raise awareness, build capacity, and ensure alignment with digital security objectives.
- Collaboration and support : Assist with stakeholder interaction. Support Directorates in understanding and fulfilling their digital security responsibilities, including third-party due diligence and vulnerability assessments.
- Post-secondary education in Information Security, or a related field, or equivalent practical experience. Qualifications or education in Vulnerability Management would be an advantage.
- Minimum of 3 years of relevant Vulnerability Management experience.
- Experience in delivering practical Vulnerability Management strategies and practices in organisations in either the public or private sector.
- Experience in Vulnerability Management Methodologies and Frameworks, such as ISO 27001 & 27002 / NIST SP 800-40r4 / SANS/ OWASP/ CVSS.
- Demonstrated knowledge of the M365 technological environment.
- Experience in drafting Vulnerability Management and patching documentation and user guidance.
- Excellent communication skills with the ability to explain complex technical ideas in plain or easy to understand language.
- Experience with data protection-related matters and strategies would be an advantage.
- Knowledge of the following tools would be an asset:
- Rapid7 Insight Vulnerability Management/ Nexpose
- Microsoft Defender for Endpoint
- Microsoft Office
- M365 suite of applications
- Microsoft Azure
- ServiceNow
- Fluency in one of the two OECD official languages (English and French) and a knowledge of, or a willingness to learn, the other.
- Knowledge of other languages would be an asset.
- OECD staff are expected to demonstrate behaviours aligned to six core competencies which will be assessed as part of this hiring processes: Vision and Strategy (Level 1); Enable People (Level 1); Ethics and Integrity (Level 2); Collaboration and Horizontality (Level 2); Achieve Results (Level 2); Innovate and Embrace Change (Level 2).
- There are three possible levels for each competency. The level for each competency is determined according to the specific needs of each job role and its associated grade.
- To learn more about the definitions for each competency for levels 1-3, please refer to OECD Core Competencies.
- Applications should reach us no later than 4 January 2026 23h59 (Paris time) .
- Fixed-term contract of 3 years.
- Depending on level of experience, monthly salary starts at 7 644.78 EUR, plus allowances based on eligibility, exempt of French income tax.
- Click here to learn more about what we offer and why the OECD is a great place to work.
- Click here to browse our People Management Guidebook and learn more about all aspects relating to people at the OECD, our workplace environment and many other policies supporting staff in their daily life.
- Please note that the appointment may be made at one grade lower in the specified job family, based on the qualifications and professional experience of the selected applicant.
Emplois Recommandés
Collaborateur Comptable TPE/PME & Conseil H/F - Paris 17 (75)
Le poste : Description du poste Vous gérez un portefeuille qualitatif avec un haut niveau d'autonomie et de conseil. Missions principales - Révision et établissement des comptes annuels …
Chargé de gestion administrative des contrats...
Rejoignez l’une des écoles du groupe Eureka Education, un Groupe engagé pour l'avenir ! Le groupe Eureka Education regroupe plus de 20 écoles en France et en Suisse réparties sur plus de 130 campus…
Accountant
Tiffany & Co. seeks an Accountant in Paris to manage vendor invoices, compliance, and support the SDA program. The role requires a Bachelor's degree in Accounting and a minimum of 3 years of experienc…
Collaborateur expérimenté en Tax Transparency Conformité (Services Financiers) - Paris - F/H
Au sein de l'équipe FSO (Financial Services Office), vous travaillerez pour des entreprises relevant du secteur des services financiers (banque, gestion d'actifs et assurance) et vous interviendrez pr…
Analyste junior en Modélisation Financière F/H
Créé en 2008, le groupe Technique Solaire est un producteur d’énergies renouvelables (solaire et biogaz). Nous maîtrisons le développement, le financement, la construction et l’exploitation des centr…
Studio Denim Assistant Intern
Saint Laurent is seeking a Studio Denim Assistant Intern in Paris. This 6-month internship, starting in March 2026, offers a unique opportunity to gain hands-on experience in the luxury fashion indust…
Responsable Commercial - Implants - Chirurgie Esthétique H/F
Le poste de Responsable Commercial - Implants - Chirurgie Esthétique H/F Rattaché(e) à la Direction Commerciale Europe, vous êtes responsable du développement du marché français sur une gamme st…
Chirurgien-dentiste H/F
Chirurgien-dentiste H/F Emploi Chirurgien-dentiste H/F - Paris 20ème 75 Nous recrutons un chirurgien-dentiste H/F pour intégrer une structure médicale et dentaire située à Paris 20ème en Île-de-Fra…
Femme de Chambre/ Valet de Chambre EXTRA (H/F)
Description de l'offre Description de l'entreprise Situé à quelques pas des Champs-Elysées, le Sofitel Paris Arc de Triomphe allie la majesté de sa façade haussmannienne au raffinement de son d…
CHEF DE CUISINE ADJOINT
Présentation de l'entreprise\n H&R est un cabinet de recrutement spécialisé en Hôtellerie-Restauration, nous intervenons principalement sur des missions de recrutement de top et middle management. …