IT Security Risk Assessment Officer
2 months ago
Bachelor’s degree in Computer Science, Information Technology, or a related field.
Must have minimum 3 years of experience in Information Security or related fields.
Must be knowledgeable on various compliance and regulatory requirements (i.e., BSP, DPA, PCI-DSS, etc.)
Must have experience in various information and IT security domains and controls related to third party risks, data security and risk management, data transmission integrity. This includes understanding various processes related to the service, product or solution provided by vendors to the Bank and its links to bank processes.
Must have experience in information security governance, controls assurance, risk assessments and key risk indicators development.
Must have experience in IT general controls and auditing.
Must have the ability to do research on items assigned to them.
Must have strong background on network and application system security risk assessments.
Must have experience in planning, executing, and documenting assessment activities following established processes and procedures with minimal guidance
Must have experience in leading and working well with the team, internal, and external clients. Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.
Analytical and risk identification skills to analyze a variety of information security –related risk situations and develop recommendations on the best course of action.
Must have Project management skills: to lead and manage accomplishments of assigned tasks/risk assessment activities.
Must possess excellent time management skills, thrive in a fast-paced demanding environment.
Be a self-managed self-starter with good organizational skills to include good follow-up skills
Be able to work under pressure on multiple assessments/projects simultaneously
Strong attention to detail, analytical, and problem-solving skills. Strong learning agility with the ability to learn new processes
Must have good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.
Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action
Must be knowledgeable in using MS office tools such as PowerPoint, word, excel and project.
Job Description:
Develop tactical plans and programs for the establishment and maintenance of the Bank’s third-party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset-based risk assessment. Analyze and review of complex bank processes, application system and network security implementation and third-party relationships to identify potential risk including the determination of risk mitigation strategies. Analysis and review of complex application system and network security implementation on the current production environments to identify potential risk including the determination of risk mitigation strategies. Recommend strategies to control risks from inadequate protection of confidentiality, integrity and availability of the information assets, processing facilities and connected services.
Specific Duties & Responsibilities:
Prepares tactical plans and/or programs in the conduct of information, third party and system security risk assessments.
Identify the Bank’s critical assets, threats to these assets, vulnerabilities, and reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information.
Coordinate and assess the security performance of third-party vendors that collect, process, transmit, and store client data
Performs threat modelling-based system security risk assessment for all IT systems and other IT assets, as applicable
Analyze and assess the impact of changes in process, technical changes and systems enhancements and third-party relationships.
Reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information and information processing facilities to mitigate information security risk.
Formulates, recommends information security policies and procedures on physical, environmental and personnel security with respect to results of information security assessment activities.
Responsible for coordinating across all business units and stakeholders in gathering information in preparation to the conduct of information, third party and system security risk assessment.
Articulate security findings and risk remediation strategies through issuance of risk assessment report. Track and follow-up status of risk mitigation activities.
Ensures security risk register is maintained and kept updated including status of remediation activities.
Executes and monitors accomplishment of the risk assessment plans and programs.
Articulate security findings and risk remediation strategies through issuance of risk assessment report; writing comprehensive, concise and understandable to non-technical. Tracking and follow up on status of mitigation activities.
Maintain and track library of records and documentation.
Investigation of applicable reported incidents related to information handling and data privacy.
Keep abreast of and apply information, IT and third-party security trends and regulatory and compliance changes affecting the security of landscape, security best practices, threat landscape (emerging and existing) and apply them in daily work.
Review the work of other Security Quality and Assurance Risk Assessors; guides and mentors them.
Proactively works with the Department Head in implementing programs for the continuous improvement of the bank’s information security plans and strategies.
Perform other information security risk management and compliance related duties and responsibilities as directed by the Department Head.
-
IT Security Risk Assessment Officer
2 months ago
Taguig, Philippines Hunter's Hub, Inc. Full timeMust have: Bachelor’s degree in Computer Science, Information Technology, or a related field. Must have minimum 3 years of experience in Information Security or related fields. Must be knowledgeable on various compliance and regulatory requirements (i.e., BSP, DPA, PCI-DSS, etc.) Must have experience in various information and IT security domains and...
-
IT Security Risk Assessment Officer
4 weeks ago
Taguig, Philippines Hunter's Hub Incorporated Full timeJob Description Job Summary: Develop tactical plans and programs for the establishment and maintenance of the Bank’s third-party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset-based risk assessment. Analyze and review of complex...
-
IT Security Risk Assessment Officer
4 weeks ago
Taguig, Philippines Hunter's Hub Incorporated Full timeJob Description Job Summary: Develop tactical plans and programs for the establishment and maintenance of the Bank’s third-party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset-based risk assessment. Analyze and review of complex...
-
IT Security Risk Assessment Specialist
4 weeks ago
Taguig, National Capital Region, Philippines Hunter's Hub, Inc. Full timeAbout the JobWe are seeking an experienced IT Security Risk Assessment Officer to join our team at Hunter's Hub, Inc. The ideal candidate will have a strong background in information security risk management and a proven track record of conducting thorough risk assessments.Key ResponsibilitiesConduct thorough risk assessments of third-party vendors and IT...
-
IT Security Risk Assessment Specialist
1 month ago
Taguig, National Capital Region, Philippines Hunter's Hub, Inc. Full timeJob Title: IT Security Risk Assessment OfficerAt Hunter's Hub, Inc., we are seeking a highly skilled IT Security Risk Assessment Officer to join our team. This role is responsible for developing tactical plans and programs for the establishment and maintenance of the Bank's third-party information security risk management framework.Key...
-
Information Security Risk Management Specialist
2 weeks ago
Taguig, National Capital Region, Philippines Hunter's Hub, Inc. Full timeJob Summary:We are seeking an experienced Information Security Risk Management Specialist to join our team at Hunter's Hub, Inc. As a key member of our security department, you will be responsible for developing and implementing tactical plans and programs to establish and maintain the bank's third-party information security risk management framework. Your...
-
Information Security Risk Management Specialist
2 weeks ago
Taguig, National Capital Region, Philippines Hunter's Hub Incorporated Full timeJob DescriptionWe are seeking an experienced Information Security Risk Management Specialist to join our team at Hunter's Hub Incorporated. This is a unique opportunity to leverage your expertise in IT security and risk management to drive business growth and ensure the long-term success of our organization.Key Responsibilities:Develop tactical plans and...
-
Information Security Risk Manager
4 weeks ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeJob Summary: We are seeking a highly skilled Information Security Risk Manager to join our team at Nityo Infotech. The ideal candidate will have a strong background in IT security, risk management, and compliance, with a proven track record of success in identifying and mitigating risks in complex IT environments.Key Responsibilities:Develop and implement...
-
Information Security Risk Manager
4 weeks ago
Taguig, National Capital Region, Philippines Hunter's Hub Incorporated Full timeJob Title: Information Security Risk ManagerAbout Us:Hunter's Hub Incorporated is a leading company in the field of information security. We are looking for a highly skilled Information Security Risk Manager to join our team.Job Summary:We are seeking a seasoned Information Security Risk Manager to lead our risk management efforts. The successful candidate...
-
Information Security Manager
2 months ago
Taguig, Philippines Visage Executive Search Full timeShall represent the bank in all cybersecurity matters and will be responsible for establishing and maintaining an Information Security Management Program to ensure that the information assets are adequately protected. The ISM should be able to identify, evaluate and report the information security risks in relation to the bank’s compliance and regulatory...
-
Compliance Risk Officer
2 weeks ago
Taguig, Philippines Visage Executive Search Full timeBrief Description: The Compliance Risk Officer is primarily responsible in assisting the Chief Compliance Officer in overseeing the risk management framework of the Bank, ensuring compliance with regulatory requirements, and implementing strategies to mitigate risks across various functions. Duties & Responsibilities: 1. Risk Assessment and Monitoring: •...
-
Risk Management Specialist
1 day ago
Taguig, National Capital Region, Philippines GSS PH Full timeAt GSS PH, we are seeking a highly skilled Risk Management Specialist to join our team. This role will be responsible for managing and mitigating risks associated with third-party vendors.About the Role:We are offering a competitive salary of $120,000 per annum, depending on experience, in addition to a comprehensive benefits package including health...
-
Information Security Manager
2 months ago
Taguig, Philippines Visage Executive Search Full timeShall represent the bank in all cybersecurity matters and will be responsible for establishing and maintaining an Information Security Management Program to ensure that the information assets are adequately protected. The ISM should be able to identify, evaluate and report the information security risks in relation to the bank’s compliance and regulatory...
-
Compliance Risk Officer
2 weeks ago
Taguig, Philippines Visage Executive Search Full timeBrief Description: The Compliance Risk Officer is primarily responsible in assisting the Chief Compliance Officer in overseeing the risk management framework of the Bank, ensuring compliance with regulatory requirements, and implementing strategies to mitigate risks across various functions. Duties & Responsibilities: 1. Risk Assessment and Monitoring: •...
-
Cybersecurity Risk Management Expert
2 weeks ago
Taguig, National Capital Region, Philippines Visage Executive Search Full timeThe Visage Executive Search is seeking a highly skilled Cybersecurity Risk Management Expert to join our team. With a strong background in information security, this role will play a crucial part in ensuring the bank's sensitive information assets are adequately protected.About the RoleThis executive position requires an individual who can lead and manage...
-
Chief Information Security Strategist
2 weeks ago
Taguig, National Capital Region, Philippines Visage Executive Search Full timeJob DescriptionWe are seeking a highly skilled Chief Information Security Strategist to join our team at Visage Executive Search. This is a senior leadership role that requires a strong background in information security, strategic planning, and stakeholder management.About the RoleThe successful candidate will be responsible for developing and implementing...
-
Chief Risk Officer
1 month ago
Taguig, Philippines Cobden and Carter International Full timeCobden and Carter International – Taguig, Metro Manila Our client is one of the leading, trusted, and innovative Digital Banks in the country. The Role: The Chief Risk Officer is responsible for directing, administering and overseeing risk management activities in accordance with the goals and objectives established by the CEO and Board of Directors ...
-
Information Security Manager
4 weeks ago
BGC, Taguig, Philippines Visage Executive Search Full timeJob DescriptionThe role of Information Security Manager at Visage Executive Search is to oversee and implement effective information security measures to protect the bank's information assets. The candidate will be responsible for developing and maintaining an Information Security Management Program, ensuring compliance with regulatory requirements, and...
-
Taguig, National Capital Region, Philippines Hunter's Hub Incorporated Full timeAbout the RoleHunter's Hub Incorporated is seeking a highly skilled Senior Cybersecurity Risk Management Specialist to join our team. In this role, you will play a critical part in developing and implementing tactical plans for third-party information security risk management frameworks.Job ResponsibilitiesDevelop comprehensive tactical plans for...
-
Security Risk Management Specialist
2 weeks ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeJob DescriptionWe are seeking a highly skilled Security Risk Management Specialist to join our team at Nityo Infotech. In this role, you will be responsible for managing and mitigating security risks across our organization.About the RoleThis is a challenging and rewarding opportunity for an experienced security professional to lead our vulnerability...