Risk and Security Assessment Consultant

3 weeks ago


Makati, Philippines HRTX Full time

Responsibilities

  • Conducts security and/or risk assessments in a fast-paced environment and provides timely, practical recommendations to mitigate identified risks
  • Performs security and/or risk assessments in alignment with industry standards (ISO 27001/2, NIST, CIS, PCI DSS, SWIFT CSP, CSA CCM), regulatory requirements (BSP circulars and others), and best practices
  • Carries out maturity assessments in cybersecurity and information technology
  • Engages in discovery workshops with consultants and key stakeholders across IT and other business units
  • Participates in project presentations for client project teams and other key stakeholders
  • Facilitates security training and awareness programs
Qualifications
  • Possesses over 3 years of experience in Information Technology
  • Holds 23 years of specific experience in security assessments, including Cloud Security Assessment, Third Party Security Risk Assessments, ISMS/NIST Assessment, SOC 2 Type 2 Assessment, RCSA, Configuration Review, Architecture Review, and Controls Review (must have)
  • Has facilitated at least one (1) IT Risk Assessment project
  • Experienced in Data Privacy frameworks such as PDPA, GDPR, and the Data Privacy Act of 2012
  • Experienced in conducting Security Awareness and Training initiatives
  • Has at least 1 year of consulting or advisory engagement experience (preferred)
  • Strong knowledge in IT Audit/Assessments and Maturity Assessments
  • Strong knowledge of information security standards and guidelines, including ISO 27001/2, NIST, CIS, PCI DSS, and SWIFT CSP
  • Understands local regulations such as BSP circulars
  • Knowledgeable in cloud computing, storage, security, and virtualization best practices
  • Effective communicator with the ability to interact across all organizational levels
  • Skilled in technical writing and infographic reporting
  • Strong time management skills, capable of multi-tasking and handling shifting priorities
  • Demonstrated ability to deliver exemplary customer service to both internal and external stakeholders
  • Preferably holds at least one of the following certifications: ISC2 CISSP, ISMS LA/LI, ISACA CISA or CRISC, or certifications relevant to PCI DSS, SWIFT, HITRUST, and other industry security standards/guidelines
#J-18808-Ljbffr
  • IT Risk

    3 weeks ago


    Makati, Philippines HRTX Full time

    Overview Job Description: Conduct security and risk assessments, providing practical recommendations for risk mitigation. Ensure assessments align with industry standards (ISO, NIST, CIS, PCIDSS, SWIFT CSP, CSA CCM) and regulatory requirements (e.g., BSP circulars). Perform cybersecurity and IT maturity assessments. Lead and participate in discovery...


  • Makati, Philippines HRTX Full time

    Responsibilities Performs security and/or risk assessments and provide timely and practical recommendations to mitigate the identified risks Performs security and/or risk assessments aligned with industry standards (ISO 27001/2, NIST, CIS, PCI DSS, SWIFT CSP, CSA CCM), regulatory requirements (BSP circulars and others), and best practices Performs maturity...


  • Makati City, National Capital Region, Philippines AvantePH Staffing and Consultancy Inc. Full time

    Responsible for securing data, network, and applications in system development or system implementations. Perform threat modeling, business and technical process analysis, application security and architecture reviews to evaluate, identify vulnerabilities and enforce security controls in IT and application systems. Ensures coordination of penetration testing...


  • Makati, Philippines Smart Communications, Inc. Full time

    Information Security Lead (Risk Assessment) Determine the risk position of PLDT group as a result of changes in the technology architecture, products and services. Execute or review a general security review based on company-accepted standards and good industry practices. Execute or review a compliance assessment of PLDT’s technology architecture, products...


  • Makati City, National Capital Region, Philippines Security Bank Corporation Full time ₱1,500,000 - ₱2,500,000 per year

    About the RoleAs an Operational Risk Manager, you are responsible for carrying out operational risk governance, oversight, consulting, and risk management activities as part of the Bank's Second Line of Defense. Supports the identification, assessment, mitigation, monitoring, and reporting of operational risks by the various businesses and functions within...

  • Risk Consulting

    2 weeks ago


    Makati City, National Capital Region, Philippines SGV & Co. Full time $80,000 - $120,000 per year

    SGV Risk ConsultingIn Risk Consulting, we assist organizations in identifying, assessing, and managing risks to protect their assets and achieve their strategic objectives. Our services include third party risk assessments and management, risk assessment, internal audit, compliance, and cybersecurity. We provide tailored solutions to mitigate potential...


  • Makati, Philippines OpenText Full time

    Location: Makati, National Capital Region, Philippines Overview OpenText is a global leader in information management, where innovation, creativity, and collaboration are the key components of our corporate culture. As a member of our team, you will have the opportunity to partner with the most highly regarded companies in the world, tackle complex...


  • Makati, Philippines SGV & Co. Full time

    Cybersecurity Strategy, Risk, and Compliance Senior Consultant SGV & Co. is the largest professional services firm in the Philippines. In everything we do, we nurture leaders and enable businesses for a better Philippines. Our multidisciplinary teams work across a full spectrum of services in assurance, tax, strategy and transactions, and consulting. Enabled...


  • Makati, Philippines Relief International Full time

    Overview Position: Baseline Assessment Consultant Location: Hybrid Reports to: Project Manager Engagement period: 2 months Background Tanggol Kababaihan: Operationalising the Philippine National Action Plan on Women, Peace and Security (NAPWPS) is a three-year initiative funded by the European Union, with the main aim of contributing to the...


  • Makati, Philippines Rockwell Land Corporation Full time

    Cyber Security Risk Officer role description Overview The Cyber Security Risk Officer is responsible for identifying, assessing, mitigating, and monitoring cyber risks across the organization. This role ensures the company’s digital assets, infrastructure, and data are protected from internal and external cyber threats. The officer collaborates with IT,...