PERMANENT WFH: Sr. Information Security Analyst

3 weeks ago


Pasig, National Capital Region, Philippines Nowcom Corporation Full time

Company Description

Nowcom is a leading provider of automotive dealer management solutions (DMS), specifically catering to the independent automobile dealer's needs. DealerCenter is Nowcom's all in one dealer management software solution that gives the dealer total control over their sales, inventory, insurance offerings, and financing through a web-based platform. As an authorized credit reseller, Nowcom provides dealerships access to all three major credit bureaus. DealerCenter.com is utilized by over 19,000 dealerships across the United States.

Additionally, as a part of the Hankey Group of Companies, Nowcom provides infrastructure support, custom software development, and call center services to its seven sister companies. Along with the other companies in the organization, Nowcom has experienced 20% growth YoY over the last decade. The Hankey Group employs over 3000 people and has assets exceeding $25 billion (USD). Nowcom has 4 offices in four countries across the globe, India, Philippines, Korea and United States.

Sr. Information Security Analyst

We are seeking an Sr. Information Security Analyst to become a key member of our international information security group. This job requires the ability to work as part of a team that is responsible for the information security program across multiple affiliated companies, primarily in the United States, with subsidiaries outside USA. The Information Security Analyst oversees all affiliated companies'compliance mandates, Information Security policies, plans and procedures. The analyst will review, modify, and update existing policies, plans and procedure to meet and comply with Federal, State, industry standards and relevant contractual cyber security requirements, implement and assess technical controls, audit the organization based on all applicable frameworks and requirements. The ideal candidate is someone that has a passion for dissecting complex Information Security challenges, analyzing varieties of requirements, and designing pragmatic policies and controls to protect our organization's information systems and data.

Essential Duties and Responsibilities, but not limited to:

  • Conduct monthly, quarterly, semi-annual, and annual audits/assessment to satisfy PCI DSS, GLBA, FCRA and ISO270001.
  • Research and perform gap analysis over existing and new cyber security laws, industry compliance regulations and policies to correlate the result with our security doctrine coverage.
  • Evaluate compliance with regulatory requirements and business requirements including, but not limited to, GLBA, FCRA, PCI-DSS, EI3PA/ISO27k.
  • Perform an impact analysis and enterprise risk assessment over covered requirements from operational and business feasibility.
  • Assist in the design, implementation, and maintenance of security controls for cloud and on-premises environments.
  • Provide technical expertise in network security, endpoint protection, and identity & access management (IAM).
  • Support secure configuration of firewalls, intrusion detection/prevention systems, and other security technologies.
  • Develop, implement, and communicate security policies, procedures, standards, best practices, guidance, and controls.
  • Assist with planning and administration of phishing campaigns and cybersecurity awareness training.
  • Plan and execute business continuity and disaster recovery exercises based on security incident.
  • Manage technical, operational, and administrative projects across the Enterprise.
  • Educate and guide employees on industry compliance requirements.
  • Actively participate in the development of the information security and security awareness training program.
  • Facilitate control testing in form of vulnerability assessment, risk assessments, penetration, and social engineering testing.
  • Work with different IT disciplines on remediation efforts to correct identified weaknesses.
  • Monitor security logs, alerts, and reports from SIEM tools and other security systems.
  • Investigate security incidents, conduct root cause analysis, and implement corrective actions. Understand and implement incident handling procedures/playbooks.

Position Requirements:

  • Bachelor's Degree from a four-year college in Cybersecurity, Computer Science, Information Technology, (or equivalent experience).
  • Minimum 10+ years in Information Security domain.
  • Excellent in written and verbal communication skills.
  • Excellent in writing and reading English.
  • Detail oriented and ability to focus on granular level compliance and security issues.
  • Ability to work well on a collaborative team and influence others without direct authority.

Desired Qualifications:

  • Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISM), Certified Information Systems Manager (CISA), or PCI Internal Security Assessor (ISA) rating is desired.
  • Master's Degree in law, compliance, or equivalent degree.
  • Experience in Financial Institution operations and environment.
  • Two to three years' project management experience is highly desired; PM certification a plus.
#J-18808-Ljbffr

  • Pasig, National Capital Region, Philippines Nowcom Global Services, LLC Full time

    Company DescriptionNowcom is a leading provider of automotive dealer management solutions (DMS), specifically catering to the independent automobile dealer's needs. DealerCenter is Nowcom's all-in-one dealer management software solution that gives the dealer total control over their sales, inventory, insurance offerings, and financing through a web-based...


  • Pasig, National Capital Region, Philippines weSource Management Consultancy Firm Full time

    Cyber Security Analyst - Sr Analyst - Hybrid Ortigas - 57KAbout the JobThe Cyber Security Analyst - Sr Analyst will be responsible for the following key responsibilities:KEY RESPONSIBILITIESConducting cyber detection and response including incident response, threat intelligence, hunting, and security monitoring.Developing cyber intelligence assessments and...

  • IT Security Analyst

    2 weeks ago


    Pasig, National Capital Region, Philippines TASQ Staffing Solutions Full time

    TASQ is looking to fill a hybrid/WFH position for a Security Operations Center Level 1 Analyst ASAP.The pre-screening interview will take place over the phone.About the job Security Operations Center Level 1 AnalystRole summaryThe SOC Analyst Level 1 will report in a hybrid work - either work remotely routing through the Internet or will report to the office...

  • Sr. Analyst, Risk

    6 days ago


    Pasig, National Capital Region, Philippines Transcom Full time

    Sr. Analyst, Risk & Compliance - Manila, PhilippinesJob category: Facilities and SecurityTranscom is looking for talented individuals like you to join our team Become the next Sr. Analyst, Risk & Compliance at our Pasig site.Join our Transcom Family as a Sr. Analyst, Risk & ComplianceAs the Regional Risk and Compliance Sr. Analyst, you will be a key part of...


  • Pasig, National Capital Region, Philippines beBee Careers Full time

    Job Summary:The Information Security Analyst is responsible for reviewing and assessing the organization's information security posture. This includes identifying vulnerabilities, developing mitigation strategies, and implementing security controls to protect against cyber threats.Key Responsibilities:Develop and implement information security policies and...

  • Security Analyst

    3 weeks ago


    Pasig, National Capital Region, Philippines Insight Full time

    Position OverviewOur Information Security Analyst will help plan and carry out the organization's information security strategy. They develop a set of security standards and best practices for the organization and recommend security enhancements to management as needed. They develop strategies to respond to and recover from a security breach. Information...


  • Pasig, National Capital Region, Philippines beBee Careers Full time

    Job RequirementsAs a Senior Data Security Manager, you will be responsible for ensuring the confidentiality, integrity, and availability of sensitive data.You will lead a team of Data Security Analysts and develop and implement data security policies and procedures.Duties and ResponsibilitiesDevelop and enforce data security policies and procedures.Conduct...


  • Pasig, National Capital Region, Philippines beBee Careers Full time

    Are you a skilled security professional looking for a challenging role?About the JobWe are seeking a highly motivated and experienced Information Security Specialist to join our team. As a Senior Security Operations Center Analyst, you will be responsible for detecting and investigating all security events on our global network, endpoints, and cloud...


  • Pasig, National Capital Region, Philippines beBee Careers Full time

    Job DescriptionThis position requires expertise in information assurance.The successful candidate will have extensive experience in conducting security monitoring and incident response.A strong understanding of threat intelligence and analysis is also necessary.The role involves developing and implementing internal tools and procedures to enhance the team's...


  • Pasig, National Capital Region, Philippines beBee Careers Full time

    Job DescriptionWe are seeking an experienced Information Security Risk Analyst to join our team. In this role, you will support information security standards, policies, and procedures to secure and protect data residing on systems. You will work directly with third-party user departments to implement procedures and systems for the protection, conservation,...