Apply Now

Please mention DailyRemote when applying

AI Summary

The consultant will design, implement, and operate identity lifecycle processes for human and non-human identities while managing access control policies across O365 and Azure environments. They are responsible for automating provisioning, enforcing governance, and maintaining security dashboards to ensure compliance and operational efficiency.

DEADLINE FOR APPLICATIONS

10 September 2026-23:59-GMT+01:00 Central European Time (Rome)

WFP celebrates and embraces diversity. It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender, gender identity and/or expression, sexual orientation, religion or belief, HIV status or disability.


ABOUT WFP

The World Food Programme is the world’s largest humanitarian organization saving lives in emergencies and using food assistance to build a pathway to peace, stability and prosperity, for people recovering from conflict, disasters and the impact of climate change.


At WFP, people are at the heart of everything we do and the vision of the future WFP workforce is one of diverse, committed, skilled, and high performing teams, selected on merit, operating in a healthy and inclusive work environment, living WFP's values (Integrity, Collaboration, Commitment, Humanity, and Inclusion) and working with partners to save and change the lives of those WFP serves.

To learn more about WFP, visit our website: https://www.wfp.org and follow us on social media to keep up with our latest news: YouTube, LinkedIn, Instagram, Facebook, Twitter, TikTok.

WHY JOIN WFP? 

  • WFP is a 2020 Nobel Peace Prize Laureate.

  • WFP offers a highly inclusive, diverse, and multicultural working environment.

  • WFP invests in the personal & professional development of its employees through a range of training, accreditation, coaching, mentorship, and other programs as well as through internal mobility opportunities.

  • A career path in WFP provides an exciting opportunity to work across the various country, regional and global offices around the world, and with passionate colleagues who work tirelessly to ensure that effective humanitarian assistance reaches millions of people across the globe.

  • We offer an attractive compensation package (please refer to the Terms and Conditions section of this vacancy announcement).

JOB TITLE: Identity and Access Management Consultant

TYPE OF CONTRACT: Regular Consultant

UNIT/DIVISION: Information Security Branch (TECI) / IT Division (TEC)

DUTY STATION (City, Country): Remote

DURATION: 11-months, EOD: ASAP

BACKGROUND AND PURPOSE OF THE ASSIGNMENT:

Under the general supervision of the CISO and direct supervision of the Workplace Services Lead, the role of the Identity & Access Management Consultant is to support O365 and Azure identity management deployment, design, build, and day-to-day Operations & Sustainment of our enterprise identity management in a 24/7 operation.

ACCOUNTABILITIES/RESPONSIBILITIES:

Design, implement, and operate identity lifecycle processes for human and non-human identities, enforcing governance, ownership, and the prevention of unauthorized provisioning or lifecycle manipulation. Implement and optimize Conditional Access, MFA, and access control policies across O365, Azure, and virtual environments, while defining and enforcing role-based and least-privilege access models for privileged accounts. Design, streamline, and automate access request, approval, and provisioning processes, integrating IAM capabilities across enterprise platforms to improve compliance, traceability, and operational efficiency. Establish governance, lifecycle management, and security controls for service accounts and external (B2B) identities, including inventory, ownership models, and enforcement of enterprise IAM policies. Implement monitoring, alerting, and KPI dashboards for identity activities, while driving access review, revocation, and risk reduction initiatives to strengthen the overall IAM security posture.

DELIVERABLES AT THE END OF THE CONTRACT:

Phase 1 Deliverables (6 months)

Identity Lifecycle Automation Improvement

Implement provisioning quality checks aligned with Conditional Access. Align Conditional Access with VDI and Citrix environment. Strengthen Conditional Access controls for privileged accounts.

Access Request & Approval Simplification

Standard Operating Procedure for Role-Based Privileged Access Baselines Deliver a streamlined approval layer for access requests, improving compliance.

Service Account and Non-Human Identity Management: Stabilization Across All Identity Providers

Inventory of service accounts and other Non-Human Identity defined in Active Directory/ Azure /AWS /GCP, used to remove unused accounts, removing security risk. Implement lifecycle access management to service accounts and Non-Human Identity. Develop SOP and governance.

Development environments

Provide expert support to the design, setup, configuration and operations of secure and compliant development environments aligned with organizational standards and best practices.

Phase 2 Deliverables (5 months):

Access Revocation Activities

Revoke legacy access to AD Organizational Units, eliminating risk of non-authorized provisioning, aligning with current accountability and responsibility. Prevent unauthorized lifecycle manipulation (e.g. account end-date changes) Reinforce centralized identity lifecycle governance. Define and implement a procedure for periodic access reviews and access certification processes.

External Identity (B2B) Standardization

Define onboarding, lifecycle, and ownership model for external users, deliver SOP. Identify and reduce privileged accounts, through an SOP and its implementation. Enforce MFA and segmentation, through an SOP and its implementation. Strengthen Conditional Access controls for privileged accounts accessed through B2B.

IAM Monitoring Automation

Implement alerting for abnormal login activity and privilege changes, allowing for proactive security intervention to be taken.

IAM KPI Dashboard

Implement automated KPIs via a dashboard (provisioning rate, orphan accounts, access volume, SLA compliance) Automate reporting for privileged users, orphan accounts, and inactive accounts

Server Governance and Management

Deliver assessment of identified risks related to servers.

QUALIFICATIONS & EXPERIENCE REQUIRED:

Education:

University degree or studies in Computer Science, Engineering or another related field.

Experience:

Minimum 4 years of experience in Identity and Access Management and cloud technologies, with hands-on experience in Microsoft identity platforms (Entra ID / Active Directory) and enterprise environments.

                                                                                                                                  

Knowledge & Skills:

  • Experience with identity systems for O365, Entra ID, and/or Forefront Identity Manager (FIM) or similar platforms
  • Experience supporting and configuring Active Directory, Entra ID, AAD Connect, and federation services (ADFS)
  • Understanding of identity lifecycle management and access provisioning processes
  • Experience with authentication and access control mechanisms, including Multi-Factor Authentication (MFA) and Conditional Access
  • Knowledge of role-based access control (RBAC) and privileged access management concepts
  • Familiarity with service accounts and non-human identity management
  • PowerShell scripting skills to support automation of identity processes (desirable)
  • Strong troubleshooting, analytical, and stakeholder collaboration skills

Languages:

Fluency in oral and written English. Other official UN languages desirable

WFP LEADERSHIP FRAMEWORK

 

WFP Leadership Framework guides to the common standards of behavior that guide HOW we work together to accomplish our mission.

Click here to access WFP Leadership Framework

 

REASONABLE ACCOMMODATION

 

WFP is committed to supporting individuals with disabilities by providing reasonable accommodations throughout the recruitment process. If you require a reasonable accommodation, please contact:  global.inclusion@wfp.org

NO FEE DISCLAIMER

 

The United Nations does not charge any application, processing, training, interviewing, testing or other fee in connection with the application or recruitment process. Should you receive a solicitation for the payment of a fee, please disregard it. Furthermore, please note that emblems, logos, names and addresses are easily copied and reproduced. Therefore, you are advised to apply particular care when submitting personal information on the web.

 

REMINDERS BEFORE YOU SUBMIT YOUR APPLICATION

  • All applications must be submitted exclusively through our online recruiting system. We do not consider CVs or applications sent by email, LinkedIn, or any other channel.

  • We strongly recommend that your Workday profile is accurate and complete, and that all sections are filled in, including your employment history, academic qualifications, language skills, and UN grade (if applicable). Once your profile is completed, please apply, and submit your application.

  • If you experience technical issues while submitting your application, you may contact us at global.hrerecruitment@wfp.org. Please note that this email is only for technical issues with an application - unsolicited applications or documents sent to this inbox will not receive a reply.

  • At the application stage, the only required documents are your CV and Cover Letter. Additional documents (passport, certificates, recommendation letters, etc.) may be requested later in the process.

  • Only shortlisted candidates will be contacted and invited to proceed to the next stage of the recruitment process.

All employment decisions are made on the basis of organizational needs, job requirements, merit, and individual qualifications. WFP is committed to providing an inclusive work environment free of sexual exploitation and abuse, all forms of discrimination, any kind of harassment, sexual harassment, and abuse of authority. Therefore, all selected candidates will undergo rigorous reference and background checks.


No appointment under any kind of contract will be offered to members of the UN Advisory Committee on Administrative and Budgetary Questions (ACABQ), International Civil Service Commission (ICSC), FAO Finance Committee, WFP External Auditor, WFP Audit Committee, Joint Inspection Unit (JIU) and other similar bodies within the United Nations system with oversight responsibilities over WFP, both during their service and within three years of ceasing that service.

Similar Jobs

See all Remote Others jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Management Consultant

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified