Information Security Engineer Consultant

1 week ago


Taguig, National Capital Region, Philippines UnitedHealth Group Full time

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together.

This role would help to assess and prioritize information security and cybersecurity risk for our clients, risks associated with a vendor's operations and products and its potential impact on client. Facilitates compliance with regulatory requirements and information security policies and develops and reports on information security metrics.

Primary Responsibilities:
  • Ensure compliance to the business agreement, policies, procedures, and regulations along with ability to map controls and compliance requirements
  • Monitors information security risks and drives remediation of policy exceptions
  • Establishes compliance with data privacy regulation
  • Identify process and security gaps, recommend improvements, and assist to implement corrective action
  • Identify required process improvements to proactively address risks or vulnerabilities or threats
  • Perform and manage Control or Risk Assessment and remediation of identified findings as per process documents
  • Establish a baseline of vendor risk, identify areas of potential exposure, develop and align vendor risk management strategies with Client's goals and objectives, and execute program ensuring consistency
  • Support the design and implementation of a common and consistent vendor risk management (VRM) program to effectively manage vendor risk in accordance with internal policy and Federal or State Regulatory requirements
  • Maintain current knowledge on quality management and information security topics and their applicability program requirements
  • Serves as POC (Point of Contact) in lead's absence
  • Create executive summaries with recommendations and direction regarding remediation efforts and disposition of the third party
  • Communicate professionally with stakeholders or end users through multiple communication
  • Define risk thresholds, develop, and implement a risk framework, remediate identified gaps, governing the process
  • Manage the process of granting and expiring exceptions to policies and control standards through the GRC platform
  • Establish real-time actionable dashboards for Policies and Standard and Risk Management
  • Monthly review of High and Critical risks with risk owners and executive leadership
  • Establish an Executive dashboard to provide visibility into the goals and KPI's
  • Perform control testing to evaluate the maturity and effectiveness of implemented security controls based on HITRUST or NIST 800-53 revision 2 Framework
  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives.
Required Qualifications:
  • 5+ years of technical experience in Information Security
  • 5+ years of GRC platform implementation experience (such as Service Now, Logic Gate, Rsam)
  • 5+ years of IT Auditing skills and the ability to manage risk assessments or projects independently
  • Experience with federal cyber security standards (such as NIST 800-53)
  • Good understanding of Risk Register, risk acceptance and risk exceptions
  • Good understanding of ISO27001 and Security Core Concepts
  • Proven excellent communication skills both verbal and written
  • Proven good presentation skills particularly ability to present technology elements in manner personnel can follow and act
Preferred Qualifications:
  • Professional accreditation in IT audit, security, privacy or other related technology disciplines (CISA, CISSP, CompTIA Security+: etc.)
  • Experience with ISO31000 (risk management), ISO 22301 (BCMS), ISO20K (ITSM), Cloud computing and understanding of how to assess Cloud related risks

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission.

Diversity creates a healthier atmosphere: Optum is an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.

Optum is a drug-free workplace. 2025 Optum Global Solutions (Philippines) Inc. All rights reserved.

#J-18808-Ljbffr

  • Taguig, National Capital Region, Philippines Cobden & Carter International Full time

    Information Security Risk ConsultantResponsibilities:Ensure third-party supplier's compliance with business requirements, business agreements, policies, procedures, and regulations.Lead third-party supplier security risk assessment and remediation activities.Research, understand, and analyze information security risks applicable to a supplier.Conduct...


  • Taguig, National Capital Region, Philippines GCash Full time

    Job SummaryWe are seeking an experienced Head of Security Intelligence and Engineering to lead our security architecture and engineering team. The successful candidate will have a deep understanding of security frameworks, such as NIST CSF, ISO 27001, and CSA Cloud Controls Matrix.Key ResponsibilitiesDevelop and execute the organization's security...


  • Taguig, National Capital Region, Philippines Fujitsu Full time

    Fujitsu Taguig, National Capital Region, PhilippinesInformation Security AnalystGet AI-powered advice on this job and more exclusive features.Work Logistics: Hybrid (BGC for onsite work), DayshiftRole Purpose:The Information Security Analyst plays a critical role in safeguarding the organization's information assets by enforcing security policies,...


  • Taguig, National Capital Region, Philippines Visage Executive Search Full time

    Shall represent the bank in all cybersecurity matters and will be responsible for establishing and maintaining an Information Security Management Program to ensure that the information assets are adequately protected. The ISM should be able to identify, evaluate and report the information security risks in relation to the bank's compliance and regulatory...


  • Taguig, National Capital Region, Philippines Visage Executive Search Full time

    The candidate needs to fulfill the 3 key functions,- manaage bank micro/digital loan portfolio,- familiar with banking credit regulation and PIC for designing and demonstrating the flow walkthrough,- being able to coordinate with product/IT team on any flow changes since we are a digital bank shall represent the bank in all cybersecurity matters and will be...


  • Taguig, National Capital Region, Philippines GCash Full time

    As a Risk Management Specialist for Financial Security at GCash, you will play a critical role in identifying and mitigating potential security risks and vulnerabilities in our technology and information systems. You will be responsible for designing and implementing effective cybersecurity and fraud prevention strategies to protect our customers' sensitive...


  • Taguig, National Capital Region, Philippines Movate Full time

    Movate Taguig, National Capital Region, PhilippinesInformation Security ManagerAs an Information Security Manager at MOVATE PHILIPPINES INC., you will be responsible for ensuring the confidentiality, integrity, and availability of the company's information assets. This is a full-time, on-site position located in Bonifacio Global City, Taguig City, Metro...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    About UsMetrobank is a leading financial institution that prioritizes innovation, excellence, and customer satisfaction. We strive to provide a secure and stable environment for our customers, employees, and stakeholders.We are seeking experienced professionals to join our Information Security Division, where you will play a key role in safeguarding our...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    Be #InGoodHands with MetrobankHere at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future...


  • Taguig, National Capital Region, Philippines Pru Life UK Full time

    Pru Life UK Taguig, National Capital Region, PhilippinesInformation Security ManagerInformation Security Lead is a senior cybersecurity leadership position intended to bridge the gap between security and business interests. Information Security Lead is responsible for developing and maintaining the organization's security posture, managing risk, ensuring...


  • Taguig, National Capital Region, Philippines Coca-Cola Europacific Aboitiz Philippines Full time

    NegotiableOn-site - Taguig 3-5 Yrs Exp Bachelor Full-timeJob DescriptionJob Title: Information Security ManagerReports to: Head of Cybersecurity, Governance, Risk & ComplianceLocation: BGC Support CenterAt Coca-Cola Europacific Aboitiz Philippines, we are driven by our purpose to Refresh the Philippines and Make a Difference – continuously leading the...


  • Taguig, National Capital Region, Philippines Michael Page Full time

    Job SummaryWe are seeking an experienced Cybersecurity Consultant to join our team. The ideal candidate will have a strong background in cybersecurity and excellent communication skills.Key Responsibilities:Develop and implement comprehensive cybersecurity policies and procedures that align with organizational goals and regulatory requirements.Collaborate...


  • Taguig, National Capital Region, Philippines MKIT (HONG KONG) HOLDINGS LIMITED Full time

    Shall represent the bank in all cybersecurity matters and will be responsible for establishing and maintaining Information Security Management Program to ensure that the information assets are adequately protected. The ISM should be able to identify, evaluate and report the information security risks in relation to the bank's compliance and regulatory...


  • Taguig, National Capital Region, Philippines UnitedHealth Group Full time

    Security Consulting RoleThe Security Consulting Role involves leading the execution of IT risk assessments and security consulting activities to assess the design, effectiveness and efficiency of IT controls and compliance applicable laws and regulations for the business.Primary Objectives:Leads projects with minimal supervision and demonstrates technical...


  • Taguig, National Capital Region, Philippines Willis Towers Watson Full time

    ResponsibilitiesThe End User Computing Security Operations Engineer is responsible for:Providing Operational Engineering and support against global End User Computing platforms with a specific slant towards security solutions.Maintaining and administering endpoint security controls and policies, focusing on day-to-day operations, troubleshooting, and...


  • Taguig, National Capital Region, Philippines Nityo Infotech Full time

    Job Overview:Nityo Infotech is looking for an experienced Information Security Analyst to join our team. As an Information Security Analyst, you will be responsible for ensuring the security and integrity of our web applications and systems.About the Role:This is an excellent opportunity for individuals with a strong background in information security to...


  • Taguig, National Capital Region, Philippines Cyber Crime Full time

    Cyber Crime is seeking a highly skilled Information Security Specialist to join our team. In this role, you will be responsible for designing and implementing use cases for Security Information and Event Management (SIEM) systems.About the Role:This position requires a strong understanding of network security controls, including routers, firewalls, proxies,...


  • Taguig, National Capital Region, Philippines Aboitiz Power Corp. Full time

    IT Security OfficerWe are seeking an experienced IT Security Officer to lead our Identity and Access Management program. This role involves planning, developing, and implementing policies and procedures for user access to systems, applications, and data.The ideal candidate will have a strong background in information security, particularly in Identity and...


  • Taguig, National Capital Region, Philippines DXC Technology Inc. Full time

    About the JobDXC Technology Inc. is hiring an experienced IT Security Professional to fill the position of Information Security Analyst.This role involves monitoring security events and incidents, escalating issues as required, and contributing to containment efforts.The successful candidate will be a continuous learner who stays abreast with industry...


  • Taguig, National Capital Region, Philippines Fujitsu Full time

    The Information Security Analyst plays a vital role in protecting our organization's digital assets from cyber threats.Responsibilities:Assess and mitigate security risks to ensure the confidentiality, integrity, and availability of information.Develop and implement procedures for technology improvement measurement, standards compliance, and control...