¡Celebramos 30 años de Idealist! Descubre nuestra trayectoria y nuestra visión para el futuro.
Organización sin fin de lucro
Nuevo
Publicado hace 6 horas

IT/Cybersecurity RFP

A distancia, El trabajo puede realizarse desde cualquier lugar del mundo
Aplicar



  • Descripción

    Tipo de contrato:
    Bajo contrato / Freelance
    Fecha de inicio:
    Octubre 1, 2026
    Fecha de finalización:
    Septiembre 30, 2027
    Fecha límite de postulación:
    Septiembre 11, 2026
    Educación:
    Otros requisitos educativos
    Salario:
    USD $20.000 - $25.000 / año
    This is a range for the RFP
    Área de impacto:
    Arte y música, Desarrollo económico, Pobreza, Transparencia y rendición de cuentas, Mujeres

    Descripción

    The purpose of this RFP is to solicit proposals from experienced IT and cybersecurity firms to:

    • Establish foundational IT and cybersecurity practices (we can share results from an initial

    exposure scan)

    • Reduce operational and financial risk
    • Improve nonprofit audit readiness and governance
    • Provide ongoing, right-sized IT and security support as we continue to grow
    • Ensure compliance with data protection regulations

    Given our size and priorities, Nest is seeking a pragmatic, phased approach that prioritizes material risk

    reduction over enterprise-scale solutions.

    Scope of Work

    Comprehensive IT Audit & Risk Assessment

    The selected vendor will conduct an initial assessment to establish Nest’s IT and cybersecurity baseline.

    Expected activities include:

    Scope:

    • Creating an organized framework demonstrating how our organization currently operates

    (processes, technology, data)

    • Identification of key IT and cybersecurity pain points and risks

    Deliverables:

    • Written risk assessment summary
    • Prioritized remediation roadmap (0–3 months, 3–6 months, 6–12 months, 12+ months)

    Core IT & Security Needs

    The selected vendor will propose implementation and/or management solutions across the following:

    Identity & Access Management

    Scope:

    • Review current identity and access management practices
    • Provide role-based access control recommendations
    • Implement or optimize multi-factor authentication (MFA) and related access controls

    Deliverables:

    • Recommend a restructure of account hierarchy, shared drives, groups, and security settings

    designed to reduce risk exposure to scams

    • Centralize identity and access management framework documentation

    Backup & Recovery

    Scope:

    • Assess backup coverage and storage architecture across systems and data repositories (Note:

    Nest currently has no formal backup practices beyond Google Drive's native retention features,

    and no separate backup or retention method for data held in other platforms such as Sage

    Intacct or Salesforce.)

    • Recommend testing cadence and recovery procedures

    Deliverables:

    • Documented backup recovery strategy
    • Backup testing plan and testing schedule
    • Documentation of recovery procedures and timelines

    Secure Remote Access

    Scope:

    • Evaluate current remote access methods and tools
    • Recommend secure remote access solutions appropriate for Nest’s environment
    • Review third-party applications and access pathways
    • Recommend a standardized antivirus / endpoint protection solution

    Deliverables:

    • Security control documentation for remote access
    • Develop timeline and plan for deploying antivirus / endpoint protection solution
    • Staff training on security awareness
    • Documentation of required staff behavior changes to ensure compliance with recommendations

    Data Protection and Privacy Requirements

    The selected vendor will support the organization in maintaining strong compliance with applicable

    global data protection regulation including:

    Scope:

    • Support compliance with relevant international standards and laws, including:
    • Compliance with EU General Data Protection Regulation (GDPR)
    • Compliance with applicable U.S. federal and state privacy laws (e.g., CCPA), in addition

    to GDPR and other international requirements, given Nest's U.S.-based donor base

    • Guidance for organizations like Nest handling EU resident data
    • Alignment of privacy policies with appropriate, recognized security frameworks
    • Develop an incident response plan for security breaches, aligned to regulation requirements

    Deliverables:

    • Data compliance assessment or gap analysis
    • Compliance roadmap with prioritized remediation actions

    Policies, Governance & Audit Readiness

    The selected vendor will support the development of right-sized, nonprofit-appropriate governance

    documentation and processes to strengthen Nest’s IT security posture and support audit readiness.

    Scope:

    • Conduct a review of Nest’s current IT security practices an documentations in relation to

    existing audit requirements and industry best practices

    • Draft practical and enforceable IT governance policies appropriate for a globally operating

    nonprofit environment

    • Ensure policies address key areas such as cybersecurity risk management, data processing and

    protection, backup and recovery, and data retention and deletion

    Deliverables:

    • A set of practical, enforceable IT governance policies aligned with Nest’s audit requirements and

    operational needs

    • Recommendations for a lightweight change management system to reduce risks associated with

    emergency or undocumented systems changes

    • Staff training on incident reporting and data protection requirements

    Ongoing Support & Advisory Services

    The selected vendor may support ongoing support services. Proposals should describe a support model,

    including:

    • Help desk or user support approach for Nest staff
    • Ongoing security monitoring including periodic (quarterly or semi-annual) security reviews
    • Named point of contact and escalation procedures (Note: board member accounts were

    previously targeted in phishing attempts. Vendor support will cover @buildanest.org accounts,

    including board members using Nest email addresses; assistance with accounts outside the

    buildanest.org domain will likely be limited.)

    Optional

    Proposals may include optional services with separate pricing, such as:

    • Device management (inventory tracking and lifecycle management)
    • Support for our annual audit

    Compensación

    NA - IT/Cybersecurity RFP

    Nivel de Idiomas

    English proficiency

    Ubicación

    A distancia
    El trabajo puede realizarse desde cualquier lugar en el mundo
    Ubicación asociada
    501 5th Avenue, New York, NY 10017, United States

    Cómo aplicar

    Please contact cleopatra@buildanest.org with questions. The Full RFP is below:

    Proposal Submission Requirements

    Interested vendors should submit proposals according to the following requirements:

    • Submission deadline: proposals will be reviewed on a rolling basis, with priority given to

    proposals received by September 11, 2026 at 5 pm, EST.

    • Submission format: proposals should be submitted as a PDF via email to Cleopatra Frazier at

    cleopatra@buildanest.org.

    • Point of contact: all questions regarding this RFP should be directed to Cleopatra Frazier at

    cleopatra@buildanest.org. Vendors should not contact other Nest staff directly regarding this

    RFP.

    • Proposal contents should include: a scope of work response addressing each section above, an

    itemized pricing breakdown, a proposed timeline, vendor qualifications (see below), and at least

    two references from comparable engagements.

    Vendor Qualifications

    To be considered, vendors should demonstrate:

    • Prior experience working with nonprofit organizations, ideally of comparable size and

    remote-first structure to Nest.

    • Experience supporting organizations with a distributed, fully remote workforce.
    • At least two references from past clients, ideally including at least one nonprofit client.
    • Direct experience remediating or preventing incidents similar to those Nest has previously

    encountered, including financial fraud and phishing-based social engineering.

    • Proof of the vendor's own cyber liability insurance, including coverage amount, submitted with

    the proposal.

    Nest Request for Proposal

    IT & Cybersecurity Services

    Organizational Overview

    Nest is a fully remote nonprofit organization dedicated to preserving craft traditions and expanding

    economic opportunity for artisans and makers worldwide. Nest works with a distributed staff and relies

    on cloud-based systems to support its programs and operations.

    Nest currently has no internal IT staff and is seeking a qualified external partner to provide IT and

    cybersecurity services appropriate to its size, risk profile, and nonprofit context.

    Nest currently operates with:

    • Fully remote workforce using personally assigned computers (both MacOS and Windows)
    • Phones/computers are intermingled between work and personal use
    • Staff primarily located in the U.S. and Europe
    • No servers, firewalls, or on-premises infrastructure
    • Core systems include Google Suite, Justworks (PEO), Zoom, Canva, Salesforce/Virtuous, Sage

    Intacct, and SAP Concur as well as secondary systems such as Dropbox, Docusign, Microsoft

    365, Asana, MediaGraph, Meta, Flodesk and Squarespace

    • No standardized account ownership, single sign on (SSO), or password policies for above

    systems

    • Legacy shared-login accounts (e.g., info@) accessed by multiple staff simultaneously, which

    currently block org-wide multi-factor authentication (MFA) enforcement ahead of Google's

    October 20, 2026, 2-Step Verification requirement for Cloud Console access

    • No formal IT, cybersecurity, or incident response policies or staff (basic day-to-day support

    provided by Operations staff)

    • History of attempted cybersecurity attacks (bank fraud which has since been contained and

    addressed, phishing schemes, targeting of board member emails, etc.);

    • Works with a wide range of donors, grantee partners, vendors, and third parties based across the

    globe (e.g., individuals, small businesses, cooperatives, multi-national corporations)

    Purpose of This RFP

    The purpose of this RFP is to solicit proposals from experienced IT and cybersecurity firms to:

    • Establish foundational IT and cybersecurity practices (we can share results from an initial

    exposure scan)

    • Reduce operational and financial risk
    • Improve nonprofit audit readiness and governance
    • Provide ongoing, right-sized IT and security support as we continue to grow
    • Ensure compliance with data protection regulations

    Given our size and priorities, Nest is seeking a pragmatic, phased approach that prioritizes material risk

    reduction over enterprise-scale solutions.

    Scope of Work

    Comprehensive IT Audit & Risk Assessment

    The selected vendor will conduct an initial assessment to establish Nest’s IT and cybersecurity baseline.

    Expected activities include:

    Scope:

    • Creating an organized framework demonstrating how our organization currently operates

    (processes, technology, data)

    • Identification of key IT and cybersecurity pain points and risks

    Deliverables:

    • Written risk assessment summary
    • Prioritized remediation roadmap (0–3 months, 3–6 months, 6–12 months, 12+ months)

    Core IT & Security Needs

    The selected vendor will propose implementation and/or management solutions across the following:

    Identity & Access Management

    Scope:

    • Review current identity and access management practices
    • Provide role-based access control recommendations
    • Implement or optimize multi-factor authentication (MFA) and related access controls

    Deliverables:

    • Recommend a restructure of account hierarchy, shared drives, groups, and security settings

    designed to reduce risk exposure to scams

    • Centralize identity and access management framework documentation

    Backup & Recovery

    Scope:

    • Assess backup coverage and storage architecture across systems and data repositories (Note:

    Nest currently has no formal backup practices beyond Google Drive's native retention features,

    and no separate backup or retention method for data held in other platforms such as Sage

    Intacct or Salesforce.)

    • Recommend testing cadence and recovery procedures

    Deliverables:

    • Documented backup recovery strategy
    • Backup testing plan and testing schedule
    • Documentation of recovery procedures and timelines

    Secure Remote Access

    Scope:

    • Evaluate current remote access methods and tools
    • Recommend secure remote access solutions appropriate for Nest’s environment
    • Review third-party applications and access pathways
    • Recommend a standardized antivirus / endpoint protection solution

    Deliverables:

    • Security control documentation for remote access
    • Develop timeline and plan for deploying antivirus / endpoint protection solution
    • Staff training on security awareness
    • Documentation of required staff behavior changes to ensure compliance with recommendations

    Data Protection and Privacy Requirements

    The selected vendor will support the organization in maintaining strong compliance with applicable

    global data protection regulation including:

    Scope:

    • Support compliance with relevant international standards and laws, including:
    • Compliance with EU General Data Protection Regulation (GDPR)
    • Compliance with applicable U.S. federal and state privacy laws (e.g., CCPA), in addition

    to GDPR and other international requirements, given Nest's U.S.-based donor base

    • Guidance for organizations like Nest handling EU resident data
    • Alignment of privacy policies with appropriate, recognized security frameworks
    • Develop an incident response plan for security breaches, aligned to regulation requirements

    Deliverables:

    • Data compliance assessment or gap analysis
    • Compliance roadmap with prioritized remediation actions

    Policies, Governance & Audit Readiness

    The selected vendor will support the development of right-sized, nonprofit-appropriate governance

    documentation and processes to strengthen Nest’s IT security posture and support audit readiness.

    Scope:

    • Conduct a review of Nest’s current IT security practices an documentations in relation to

    existing audit requirements and industry best practices

    • Draft practical and enforceable IT governance policies appropriate for a globally operating

    nonprofit environment

    • Ensure policies address key areas such as cybersecurity risk management, data processing and

    protection, backup and recovery, and data retention and deletion

    Deliverables:

    • A set of practical, enforceable IT governance policies aligned with Nest’s audit requirements and

    operational needs

    • Recommendations for a lightweight change management system to reduce risks associated with

    emergency or undocumented systems changes

    • Staff training on incident reporting and data protection requirements

    Ongoing Support & Advisory Services

    The selected vendor may support ongoing support services. Proposals should describe a support model,

    including:

    • Help desk or user support approach for Nest staff
    • Ongoing security monitoring including periodic (quarterly or semi-annual) security reviews
    • Named point of contact and escalation procedures (Note: board member accounts were

    previously targeted in phishing attempts. Vendor support will cover @buildanest.org accounts,

    including board members using Nest email addresses; assistance with accounts outside the

    buildanest.org domain will likely be limited.)

    Optional

    Proposals may include optional services with separate pricing, such as:

    • Device management (inventory tracking and lifecycle management)
    • Support for our annual audit

    Pricing & Budget

    Nest anticipates a budget of $20,000 – $25,000 for an initial four-month implementation engagement.

    Nest anticipates completing the core scope of work outlined above by December 2026, with ongoing

    support and advisory services considered as a separate, subsequent engagement, which should be

    clearly noted as such in the proposal. Proposals should include:

    • Total cost and cost breakdown by service area
    • Implementation timeline
    • Assumptions and clear exclusions
    • Contract term and termination provisions (Nest's preference: an initial term with a renewal

    option.)

    • Payment terms, including any applicable deposits or retainer fees
    Illustration

    Da el siguiente paso en tu carrera

    Contacta con responsables de contratar talento para el impacto social, explora las últimas vacantes laborales y recibe notificaciones cuando nuevas oportunidades cumplan con tus criterios de búsqueda.