Security Assurance and Assessment Officer

2 weeks ago


Taguig, National Capital Region, Philippines Metrobank Full time
Security Assurance and Assessment Officer Metrobank Metrobank gives meaning to your financial journey with these broad range of products and services. Start your journey to meaningful banking now.

View company page

Develop tactical plans and programs for the establishment and maintenance of the Bank's third party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset based risk assessment. Analyze and review of complex bank processes, application system and network security implementation and third party relationships to identify potential risk including the determination of risk mitigation strategies. Analysis and review of complex application system and network security implementation on the current production environments to identify potential risk including the determination of risk mitigation strategies. Recommend strategies to control risks from inadequate protection of confidentiality, integrity and availability of the information assets, processing facilities and connected services.

Specific Duties & Responsibilities:

  • Prepares tactical plans and/or programs in the conduct of information, third party and system security risk assessments.
  • Identify the Bank's critical assets, threats to these assets, vulnerabilities, and reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information.
  • Coordinate and assess the security performance of third-party vendors that collect, process, transmit, and store client data
  • Performs threat modelling-based system security risk assessment for all IT systems and other IT assets, as applicable
  • Analyze and assess the impact of changes in process, technical changes and systems enhancements and third party relationships.
  • Reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information and information processing facilities to mitigate information security risk.
  • Formulates, recommends information security policies and procedures on physical, environmental and personnel security with respect to results of information security assessment activities.
  • Responsible for coordinating across all business units and stakeholders in gathering information in preparation to the conduct of information, third party and system security risk assessment.
  • Articulate security findings and risk remediation strategies through issuance of risk assessment report. Track and follow-up status of risk mitigation activities.
  • Ensures security risk register is maintained and kept updated including status of remediation activities.
  • Executes and monitors accomplishment of the risk assessment plans and programs.
  • Articulate security findings and risk remediation strategies through issuance of risk assessment report; writing comprehensive, concise and understandable to non-technical. Tracking and follow up on status of mitigation activities.
  • Maintain and track library of records and documentation.
  • Investigation of applicable reported incidents related to information handling and data privacy.
  • Keep abreast of and apply information, IT and third party security trends and regulatory and compliance changes affecting the security of landscape, security best practices, threat landscape (emerging and existing) and apply them in daily work.
  • Review the work of other Security Quality and Assurance Risk Assessors; guides and mentors them.
  • Proactively works with the Department Head in implementing programs for the continuous improvement of the bank's information security plans and strategies.
  • Perform other information security risk management and compliance related duties and responsibilities as directed by the Department Head.

Job Summary:

  • Develop tactical plans and programs for the establishment and maintenance of the Bank's third party information security risk management framework and ensure alignment with the enterprise risk framework
  • Performs third party security, system security and information asset based risk assessment. Analyze and review of complex bank processes, application system and network security implementation and third party relationships to identify potential risk including the determination of risk mitigation strategies
  • Analysis and review of complex application system and network security implementation on the current production environments to identify potential risk including the determination of risk mitigation strategies
  • Recommend strategies to control risks from inadequate protection of confidentiality, integrity and availability of the information assets, processing facilities and connected services

Role Exposure:

  • Prepares tactical plans and/or programs in the conduct of information, third party and system security risk assessments
  • Identify the Bank's critical assets, threats to these assets, vulnerabilities, and reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information
  • Coordinate and assess the security performance of third-party vendors that collect, process, transmit, and store client data
  • Performs threat modelling-based system security risk assessment for all IT systems and other IT assets, as applicable
  • Analyze and assess the impact of changes in process, technical changes and systems enhancements and third party relationships.
  • Reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information and information processing facilities to mitigate information security risk
  • Formulates, recommends information security policies and procedures on physical, environmental and personnel security with respect to results of information security assessment activities
  • Responsible for coordinating across all business units and stakeholders in gathering information in preparation to the conduct of information, third party and system security risk assessment
  • Articulate security findings and risk remediation strategies through issuance of risk assessment report. Track and follow-up status of risk mitigation activities
  • Ensures security risk register is maintained and kept updated including status of remediation activities
  • Executes and monitors accomplishment of the risk assessment plans and programs
  • Articulate security findings and risk remediation strategies through issuance of risk assessment report; writing comprehensive, concise and understandable to non-technical
  • Tracking and follow up on status of mitigation activities
  • Maintain and track library of records and documentation
  • Investigation of applicable reported incidents related to information handling and data privacy
  • Keep abreast of and apply information, IT and third party security trends and regulatory and compliance changes affecting the security of landscape, security best practices, threat landscape (emerging and existing) and apply them in daily work
  • Review the work of other Security Quality and Assurance Risk Assessors; guides and mentors them
  • Proactively works with the Department Head in implementing programs for the continuous improvement of the bank's information security plans and strategies
  • Perform other information security risk management and compliance related duties and responsibilities as directed by the Department Head

Qualifications:

  • Bachelor's Degree
  • Experienced in IT general controls and auditing, preferably strong background on system security risk assessments
  • Can perform information security risk-based prioritization decisions, analyze business risk, and can articulate complex business/risk trade-off recommendations and decisions
  • Experienced on project security technical review and risk assessment
  • Analytical and risk identification skills to analyze a variety of information security –related risk situations and develop recommendations on the best course of action
  • Should also be abreast with security best practices and knowledge of common and emerging security threats
  • Professional Certification may include CISA, CISM, CRISK, PCI-DSS, ISO-27001 LA or equivalent is an advantage
Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Taguig, National Capital Region, Philippines JT International S.A. Full time

    We are JTI, Japan Tobacco International, and we are present in 130 countries. We have spent years innovating, creating new and better products for the consumers to choose from. This is our business. But not only. Our business is our people. Their talent. Their potential. We believe that when they are free to be themselves, and they are given the opportunity...


  • Taguig, National Capital Region, Philippines Satellite Office Full time

    Key Responsibilities:Communication Monitoring: Systematically review and assess the quality of inbound and outbound calls, SMS, emails, and other customer interactions to ensure consistency and adherence to Q Report's quality standards and compliance requirements.Compliance Assurance: Verify that all communications comply with relevant laws, regulations, and...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    Metrobank Metrobank gives meaning to your financial journey with these broad range of products and services. Start your journey to meaningful banking now. View company page Formulate and recommend information security policies and procedures to meet the bank's information security objectives and ensure effective implementation. Monitor the accomplishments...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    Metrobank Metrobank gives meaning to your financial journey with these broad range of products and services. Start your journey to meaningful banking now. View company page Plan, document test methodologies and perform penetration testing or ethical hacking of network infrastructure, application systems including mobile applications all in a stealthy...


  • Taguig, National Capital Region, Philippines Gratitude Philippines Full time

    Responsibilities:Carry out quality assurance oversight activities defined in the Client Managed Care National Best Practices and Quality Assurance StandardsConduct regular and systematic review of Managed Care internal and external claim files with focus towards validation of consistent evaluation of evidence-based medicine, comprehensive assessments,...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    Metrobank Metrobank gives meaning to your financial journey with these broad range of products and services. Start your journey to meaningful banking now. View company page Responsible for configuring and maintaining security controls of endpoint security infrastructure; ensures that the security systems documentation is up to date. Identifies and defines...


  • Taguig, National Capital Region, Philippines Neksjob Philippines Full time

    ManagerMinimum 8 years of large-scale consulting experience and/or working with hi-tech companies.Bachelor's degreeMBA Degree from Tier-1 College (Preferable)Professional certifications like TOGAF, SABSA, Cloud Architect Professionals certificationShould have practical industry expertise in one of these areas - Financial Services, Retail, consumer goods,...


  • Taguig, National Capital Region, Philippines Eteam Workforce Full time

    Job Qualification:Bachelor's/College degree graduate.Background on quality Assurance or Administrative experience Technical Skills RequiredBasic proficiency with office software like Microsoft Office, Google Docs, and any relevant industry specific programs.Process excellence trainingCoaching experienceLaptop ProvidedHYBRID (1 Day office and 4 days WFH)Job...


  • Taguig, National Capital Region, Philippines Stotsenberg Leisure Park and Hotel Corporation Full time

    OVERVIEWQA Lead duties include performing visual inspections, recording quality issues and planningprocesses to decrease the instance of defects in products.JOB SCOPE:● Reviewing quality specifications and technical design documents to providetimely and meaningful feedback● Creating detailed, comprehensive and well-structured test plans and testcases●...


  • Taguig, National Capital Region, Philippines Neksjob Philippines Full time

    Cloud Security ConsultantLocation: Taguig City Responsibilities:Identifying, assessing, and solving complex business problems for area of responsibility, where analysis of situations or data requires an in-depth evaluation of variable factorsManaging portfolio of Security consulting engagements across clientsOverseeing the development of Security solutions,...


  • Taguig, National Capital Region, Philippines Apple Inc. Full time

    Software is often referred to as the "soul" of Apple's products. In this position you will play a critical role in ensuring the security of the systems and infrastructure used to manage, build, and distribute, Apple's software.We are looking for a proficient Embedded Security Engineer to join our team and contribute to the protection of our critical assets....


  • Taguig, National Capital Region, Philippines Radix Systems Services Corporation Full time

    The Sr. Security Consultant is primarily responsible for all security related to Systems, Datacenter, and Cloud Infrastructure. As a Sr. Security Consultant, you are expected to ensure all projects and initiatives under SDC team are being done on a secure way. You will be joining a Global Systems and Datacenter team under Technical Solutions.Responsibilities...


  • Taguig, National Capital Region, Philippines Citigroup Inc. Full time

    Info Sec Analyst - Cyber SecurityAs a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients' best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals...


  • Taguig, National Capital Region, Philippines Neksjob Philippines Full time

    Senior Manager Minimum 12 years of large-scale consulting experience and/or working with hi-tech companies. Bachelor's degree MBA Degree from Tier-1 College (Preferable) Professional certifications like TOGAF, SABSA, Cloud Architect Professionals certification Should have practical industry expertise in one of these areas - Financial Services, Retail,...


  • Taguig, National Capital Region, Philippines Neksjob Philippines Full time

    Senior Manager Minimum 12 years of large-scale consulting experience and/or working with hi-tech companies.Bachelor's degreeMBA Degree from Tier-1 College (Preferable)Professional certifications like TOGAF, SABSA, Cloud Architect Professionals certificationShould have practical industry expertise in one of these areas - Financial Services, Retail, consumer...


  • Taguig, National Capital Region, Philippines Nezda Technologies Full time

    Quality Assurance & Control (Manufacturing, Transport & Logistics) Position: Quality Assurance Specialist (Medical Field)Location: BGC, TaguigWork setup: On-siteWork Schedule: Shifting.Job Descriptions:The Quality Assurance (QA) Specialist is responsible in ensuring accuracy of information and quality of delivery by monitoring, auditing, reviewing,...


  • Taguig, National Capital Region, Philippines Citigroup Inc. Full time

    Whether you're at the start of your career or looking to discover your next adventure, your story begins here. At Citi, you'll have the opportunity to expand your skills and make a difference at one of the world's most global banks. We're fully committed to supporting your growth and development from the start with extensive on-the-job training and exposure...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    Metrobank Metrobank gives meaning to your financial journey with these broad range of products and services. Start your journey to meaningful banking now. View company page Entry level position in the SOC team. Triage specialist whose responsibility is to review real-time event data, monitor alert queue on a rotating 24 x 7 x 365 basis, and to determine...


  • Taguig, National Capital Region, Philippines Sysgen Full time

    Cyber Defense Assurance Senior (Hybrid / Mid Shift) Security (Information & Communication Technology) We are looking for a candidate for the Cyber Defence Assurance Senior who has the following:Have a people focused approach that displays trustworthy, professional attributes to deliver innovative approaches to your work.Experience and knowledge of cyber...


  • Taguig, National Capital Region, Philippines UnitedHealth Group Full time

    Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion,...