IT Analyst

World Bank Group

Chennai, India

Experience: 0 to 3 Years

Skill Required: IT and ICT

Do you want to build a career that is truly worthwhile? Working at the World Bank provides a unique opportunity for you to help our clients solve their greatest development challenges. The World Bank consists of two entities – the International Bank for Reconstruction and Development (IBRD) and the International Development Association (IDA). It is a global development cooperative owned by 189 member countries. As the largest development bank in the world, the World Bank provides loans, guarantees, risk management products, and advisory services to middle-income and creditworthy low-income countries, and coordinates responses to regional and global challenges.

ITS Vice Presidency Context:

Information and Technology Solutions (ITS) enables the WBG to achieve its mission of ending extreme poverty and promote shared prosperity in a sustainable way by delivering transformative information and technologies to its staff working in over 150 locations.

Our vision is to transform how the Bank Group accomplishes its mission through information and technology. In this fast-paced, ever-changing world, the formulation and implementation of the ITS strategy is an ongoing, iterative process of learning and adaptation developed through extensive consultations with business partners throughout the World Bank Group.

ITS shapes its strategy in response to changing business priorities and leverages new technologies to achieve three high-level business outcomes: business enablement, by providing Bank Group units with innovative digital tools and technologies to transform how they deliver value for their clients; empowerment & effectiveness, by ensuring that all Bank Group staff are connected, able to find information, and productive to accelerate the delivery of development solutions globally; and resilience, by equipping the Bank Group to provide risk-based cybersecurity and robust data protection for a global network and a growing cloud platform.

Implementation of the strategy is guided by three core principles. The first is to deliver solutions for business partners that are customer-centric, innovative, and transformative. The second is to provide the Bank Group with value for money with selective and standard technologies. The third principle is to excel at the basics by providing a high performing, robust, and resilient IT environment for the organization.

The ITS Information Security and Risk Management (ITSSR) unit, headed by the Chief Information Security Officer (CISO), is responsible for providing leadership in managing the information security and risk functions and activities across the World Bank Group, enabling the achievement of WBG's business objectives. ITSSR supports and facilitates a risk aware culture, ensuring that WBG information assets are protected in an effective, efficient, and balanced manner and IT security and risk management efforts throughout the World Bank Group are coordinated and aligned to the Bank's business and IT strategy. ITSSR comprises of the following functions: Security Operations, Risk Management and Advisory, IT Policy, IT Compliance, PMO, Business Continuity, and Sourcing and Vendor Management.

The ITS Risk and Compliance (ITSRC) unit within ITSSR has been tasked with providing technical and architectural information security solutions for The World Bank Group and needs an Information Security professional who is results oriented, multi-disciplined and experienced in evaluating information security controls in web and mobile applications and complex business applications.

The Information Security Analyst – Application Security Testing, would be expected to work primarily in the following areas:

Interface with ITSRC Security Architecture team members to understand security requirements for WBG information systems (websites, enterprise systems, mobile applications, cloud-based solutions, etc.) seeking security accreditation;

Prepare risk-based test plans and perform the security testing (tool-based testing, manual penetration testing, source code review, etc.) on the different layers of those information systems in support of the Certification & Accreditation.

The selected candidate will report to the Team Lead of the Certification and Accreditation function.

Duties and Accountabilities

The Information Security Analyst will have responsibilities for specific individual tasks and for working as an integral part of the team in executing ITSRC's work program. The primary responsibilities will include, but are not limited to, a combination of the following:

  • Review the security architecture evaluation of WBG new systems and create security test plans based on existing and planned controls and recommendations.
  • Perform security analysis of the different layers of the systems (application, operating systems and database layers) by performing source code review, manual testing and automated system vulnerability assessment scans using various web, application, operating systems, source code and database vulnerability scanners.
  • Perform security testing for cloud-based solutions.
  • Perform Gray-Box/White-Box security testing of applications as post-production checks for critical applications.
  • Perform application security testing on both native and web based mobile applications on different mobile platforms.
  • Review testing result reports and work with the application development community to remediate issues following a risk-based approach.
  • Maintain detailed documentation of test procedures and findings in ITSRC ticketing system.
  • Help develop and maintain ITSRC application security testing processes and procedures to incorporate new technologies and testing methodologies.
  • Track relevant security metrics and key performance indicators, analyze test results and vulnerability trends, and prepare status reports.
  • Stay abreast of newer trends in tools and technologies used for application security.

Selection Criteria

  • Master's degree with 2 years relevant experience or Bachelor’s degree with a minimum of 4 years relevant experience. Preferred 2+ years of experience working in information security or working in software development or operations in cloud technology, with demonstrated hands-on experience in application security.
  • Proven level of understanding of the security architecture and security requirements of enterprise applications and platforms, and hands-on experience in preparing risk-based test plans and performing the security testing on the different layers of those information systems.
  • Proven level of understanding of security in various phases of a software, system, and data life cycle.
  • In-depth knowledge of common security vulnerabilities of OWASP Top 10 (e.g., SQL injection, cross-site scripting) and common exploit techniques (e.g., character encoding, privilege escalation, directory traversal).
  • Demonstrated hands-on experience with web application security manual testing, source code review, and running web application testing tools (e.g., TrustWave Hailstorm, HP Web Inspect), identifying vulnerabilities as per SANS 25 or OWASP Top 10 specifications and validating test results, analyzing vulnerabilities, and helping develop platform specific remediation plans.
  • Understanding of cloud technology (e.g., AWS, MS Azure, MS Office 365, MS Power Apps) is an added plus.
  • Understanding of web application technologies (e.g., Java, .NET, Drupal) and the operation/configuration of common web servers (e.g., IIS, Apache) is an added plus.
  • Experience with security vulnerability evaluation of ERP solutions (e.g., SAP and PeopleSoft), COTS solutions and application middleware (Documentum, SharePoint, etc.) is an added plus.
  • Experience with mobile application security testing on different mobile platforms (iOS and Android) is an added plus.
  • Industry certifications highly preferred including, but not limited to, Certified Ethical Hacker (CEH), AWS Solutions Architect Associate, Azure Solutions Architect Associate, CSA Certificate of Cloud Security Knowledge (CCSK), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Global Information Assurance Certification (GIAC), and Information Systems Security Management Professional (ISSMP).
  • Ability to work well under pressure and meet tight deadlines. Demonstrate a high level of motivation, confidence, integrity, and responsibility.
  • Ability to be organized, responsive and to be able to effectively multi-task with a focus on driving results.
  • Demonstrate excellent interpersonal skills; including the ability to work independently, effectively in a team/task force as a team member or leader, and with senior staff and managers in the unit and elsewhere in the WBG.