Application close date

10/12/2026

Title

Cybersecurity Program and Process Design and Implementation Consultant

1. Project Background

The Asian Infrastructure Investment Bank (AIIB) is a multilateral development bank whose mission is financing Infrastructure for Tomorrow in Asia and beyond – infrastructure with sustainability at its core. AIIB maintains a comprehensive cybersecurity program to manage evolving cyber risks and strengthen the Bank’s security and operational resilience. The program encompasses cybersecurity governance and strategy, security operations and incident response, security engineering, threat detection and monitoring, and the implementation of strategic cybersecurity initiatives.The Bank is currently progressing several important and time-sensitive cybersecurity initiatives, including the Frontier AI cybersecurity initiative, Cloud SOC transformation, the IT Security Strategy and three-year cybersecurity roadmap, and the update of the Instruction on IT Security Management. In parallel, the Bank is implementing remediation actions arising from Internal Audit findings and other security assessments, some of which have defined completion timelines. Effective delivery of these initiatives requires strong cybersecurity subject-matter expertise, program management, coordination across internal and external stakeholders, and effective management of deliverables, dependencies, risks, and timelines.From a security operations perspective, AIIB operates an outsourced Security Operations Center (SOC) through a Managed Security Service (MSS) provider to support continuous security monitoring, alert triage, and initial investigation. Effective cybersecurity incident management nevertheless requires strong Bank-side operational oversight and technical expertise to assure the quality and effectiveness of MSS-delivered services, validate the appropriate investigation and closure of security incidents, and engage directly with Bank personnel and internal technology teams where further investigation or remediation is required.The Bank also continues to strengthen and modernize its cybersecurity monitoring and detection capabilities across on-premises and cloud environments. This requires security engineering expertise to support the Bank’s SIEM/SOC platforms, including detection engineering, development and fine-tuning of detection rules, reduction of false positives, improvement of detection coverage and effectiveness, integration of relevant security data sources, and the transition and optimization of monitoring capabilities across on-premises and cloud platforms.

2. Objectives of the Assignment

The Consultant will provide a combination of cybersecurity program management, incident response, and security engineering expertise. The Consultant will support the timely delivery of priority cybersecurity initiatives and audit-related commitments, while also providing Bank-side oversight of cybersecurity operations, quality assurance over significant or complex incident investigations, and technical support for the continuous improvement of the Bank’s monitoring and detection capabilities. The engagement will also support knowledge transfer and continuity of critical cybersecurity activities during the current resource transition.

3. Scope of Services

The Consultant will provide expert support across cybersecurity incident response, security engineering, and the management and delivery of priority cybersecurity initiatives.• For cybersecurity incident response, the Consultant will provide quality assurance over incident investigation and closure, and work closely with affected Bank personnel, technology teams, and relevant service providers to ensure that significant or complex cybersecurity incidents are appropriately investigated, documented, remediated, and closed. The Consultant will also support incident coordination, root-cause analysis, lessons learned, and continuous improvement of the Bank’s incident response capabilities.• For security engineering and monitoring, the Consultant will support the engineering and continuous improvement of AIIB’s cybersecurity monitoring capabilities, with particular focus on the Bank’s on-premises and cloud SIEM/SOC platforms. This includes performing detection engineering by developing new or fine-tuning existing detection rules, reducing false positives, improving detection coverage and effectiveness, integrating relevant data sources, and supporting the transition and optimization of monitoring capabilities across on-premises and cloud environments.• For cybersecurity program management, the Consultant will provide subject-matter expertise and program management support for priority and time-sensitive cybersecurity initiatives. This includes supporting the planning, coordination, implementation, and tracking of key initiatives such as the Frontier AI cybersecurity initiative, Cloud SOC transformation, IT Security Strategy and three-year cybersecurity roadmap, and the update of the Instruction on IT Security Management, as well as cybersecurity-related Internal Audit remediation activities and other priority initiatives as assigned.• The Consultant will work with relevant stakeholders to define and track deliverables, milestones, dependencies, risks, and actions; coordinate activities across internal teams and external service providers; identify and escalate delivery risks and issues; prepare progress updates and management reporting; and support the timely completion of agreed deliverables and audit commitments. • The Consultant will also facilitate knowledge transfer and documentation to support continuity and the sustainable transition of responsibilities to the IT Security Team.• Perform other cybersecurity operations and incident response duties as assigned and be prepared to provide support outside regular working hours when required for significant or urgent cybersecurity incidents.

3. Scope of Services (Continued)

(No Value)

4. Consultancy Output / Deliverables

• Updated IT Security strategy, roadmap, implementation plan, and Instruction on IT Security Management • Cybersecurity incident reports and forensics reports where applicable • MSS Quality Assurance Reviews• SIEM use cases and detection rules• Up-to-date Cybersecurity incident handling books • Operational Metrics

4. Consultancy Output / Deliverables (Continued)

(No Value)

5. Implementation Arrangement

The assignment is expected to be carried out remotely.

5. Implementation Arrangement (Continued)

(No Value)

6. Support to the Consultant by the Bank

Network/Bank-issued laptop

7. Knowledge Transfer and Training

N/A

Qualification Requirement

• Bachelor’s degree or higher in Computer Science, Information Technology, Software Development, Information Security, etc. Equivalent combination of education and experience is acceptable.• More than 15 years’ direct experience as IT security engineer, incident responder, digital forensic analyst, or Security Operation analyst• Working knowledge with digital forensic concepts, tools and procedures.• Knowledge of security protection for digital workspace, hybrid cloud and business applications such as Microsoft 365, Microsoft Defender suite, Azure Cloud, AWS Cloud, container, etc.• Knowledge of security products such as firewall, EDR, IDS/IPS, Sandbox, Anti-Malware, SIEM, CSPM, DLP, etc.• Familiar with popular operating systems such as Windows, Linux, macOS, etc.• Exposure to one or more programming/scripting languages (e.g., Python, C/C++, JavaScript, PowerShell, Unix Shell) and/or low-code development platforms is beneficial.• Information Security certification such as CISSP, CISA, CISM, CEH is a plus• Must be able to brainstorm with technical and non-technical personnel, thrive in a collaborative team environment, and quickly adapt to change.• Must be able to write thorough, concise, and user-friendly documentation in English.• Strong interpersonal communication skills in English, both verbal and written.• High degrees of diplomacy, integrity, and tact.


At Impactpool we do our best to provide you the most accurate info, but closing dates may be wrong on our site. Please check on the recruiting organization's page for the exact info. Candidates are responsible for complying with deadlines and are encouraged to submit applications well ahead.
Before applying, please make sure that you have read the requirements for the position and that you qualify. Applications from non-qualifying applicants will most likely be discarded by the recruiting manager.