We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Cybersecurity Technical Advisor

CRDF Global
United States, Virginia, Arlington
1776 Wilson Boulevard (Show on map)
Jun 26, 2025
Job Title
Cybersecurity Technical Advisor
Location
Arlington - Arlington, VA 22209 US (Primary)
Job Type
Full-Time
Category
Program/Project Management
Career Level
Experienced (Non-Manager)
Travel Required
0 - 25%
Job Description

Around the world, digital security is increasingly seen as a foundational component of national security, as nearly all facets of global financial, political, and social systems are rooted in deeply interconnected information & communications technology (ICT). A recent World Economic Forum policy note has identified data fraud/theft and large-scale cyberattacks as two of the top five most concerning international security threats, as governments, international organizations, corporations, and individuals race to strengthen their infrastructure, reduce network vulnerabilities, and safeguard broader operational systems from malicious actors.

CRDF Global is seeking a Cybersecurity Technical Program Advisor to serve as a thought leader and solution architect who can deliver effective, adaptive, and innovative Cybersecurity capabilities and host country technical assistance programs in Europe and around the world. The ability to communicate effectively and to interact with subject matter experts in the government, academic, non-profit, and private sectors is essential. Note: Within the NICE Framework, this position aligns with Systems Requirement Planning, Work Role ID DD-WRL-006.

This position will require travel throughout the Western Balkans.

Major Responsibilities:



  • Risk Assessment and Threat Modeling


  • Conduct landscape and risk assessments: Identify, evaluate, and prioritize potential security risks to beneficiary organizations, both from external and internal threats.
  • Develop threat models: Understand potential attack vectors, vulnerabilities, and adversary tactics to design defensive measures that may be unique to individual beneficiaries.
  • Mitigate vulnerabilities: Recommend solutions and develop time-phased road maps to address security gaps and vulnerabilities identified during assessments.
  • Consult and advice: Provide guidance to beneficiaries on security best practices, security frameworks (e.g., NIS2, ISO, NIST), and regulatory compliance (e.g., GDPR, DSA).


  • Designing Security Architectures


  • Develop security frameworks: Create secure architectures and frameworks that align with the beneficiaries' goals while ensuring the integrity, confidentiality, and availability of information systems.
  • Assess system requirements: Identify the specific security needs of various applications, platforms, and networks, and design tailored solutions to meet these needs.


  • Security Solution Integration


  • Select and implement security tools: Identify the right mix of security technologies (e.g., firewalls, intrusion detection/prevention systems, encryption solutions, identity management systems) to protect the beneficiaries' assets.
  • Integrate security solutions: Recommend solutions to ensure that various security systems work seamlessly together and are integrated into the beneficiaries' overall IT infrastructure, with a focus on affordability and sustainability.


  • Security Strategy and Policy Development


  • Create security policies: Support beneficiaries as they develop comprehensive cybersecurity policies and guidelines that establish standards for secure system design, data handling, and incident response in their organizations.
  • Strategic planning: Work with stakeholders to align cybersecurity strategy with business objectives, ensuring both short-term and long-term goals are met.


  • Compliance and Regulatory Management


  • Ensure compliance: Recommend security practices to the beneficiary that comply with industry standards, regulatory requirements, and laws (e.g., PCI DSS, DSA, GDPR).
  • Audit preparation: Help prepare beneficiaries for security audits by reviewing their documentation and confirming their systems are compliant with internal and external standards.


  • Incident Response Planning


  • Developing incident response plans: Help beneficiaries create (or improve) and implement plans for responding to security incidents and breaches.


  • Capacity Building and Change Management:


  • Contribute to wider capacity and change diagnostics and program design
  • Integrate and embed technical change requirements into wider change plans to form holistic capacity building solutions.


REQUIREMENTS:



  • Candidate must live in either Montenegro or North Macedonia
  • Bachelor's degree in computer science or related field
  • 12+ years of progressively responsible work experience in information security/cybersecurity or a related field in support of government clients
  • Fluency in spoken and written English
  • Deep knowledge of security technologies, protocols, and encryption methods.
  • Familiarity with industry standards and frameworks (NIST, ISO 27001, etc.).
  • Strong analytical skills and the ability to think like an attacker (offensive security mindset).
  • Expertise in risk management and threat modeling techniques.
  • Knowledge of compliance and regulatory frameworks (e.g., GDPR, DSA, PCI DSS).
  • Demonstrated knowledge of, and interest in, current cybersecurity policies, trends, issues and challenges in a global context, including threat actors, recent vulnerabilities and breaches of note, mitigation strategies, and security policy frameworks
  • Established international knowledge and relationship network, with emphasis on Central and Southern Europe
  • Strong conceptual skills combined with the ability to take ambitious ideas and to break them into manageable, specific sets of objectives to plan and successfully implement creative, ambitious organizational change strategies relevant to and effective in a complex, multinational organizational setting
  • Demonstrated ability and track record in strategic, holistic and systemic thinking, managing resistance to change and understanding of organizational culture, learning and change experience in solution design/proposal development and budgeting
  • Advanced conversation and presentation skills that can influence senior decision makers,
  • Excellent written and oral communication skills, including the ability to engage and influence a wide range of individuals from varied backgrounds at all levels within their organization's Management
  • Be willing and able to travel internationally


PREFERRED:



  • Master's degree in computer science or related field
  • Experience in implementation in a developing country context strongly preferred
  • Industry certification(s), such as Certified Ethical Hacker (CEH), CompTIA Security+, or Certified Information System Security Professional (CISSP)
  • Experience of international development programming, particularly in. the European Union

Applied = 0

(web-8588dfb-vpc2p)