Threat and Vulnerability Management Lead

1 week ago


Manila, National Capital Region, Philippines SM Investments Corporation Full time

Position Overview: We are seeking a highly motivated and detail-oriented Cyber Security Threat Technical Manager to join our team. As a Cyber Threat Technical Lead, you will be responsible for conducting various security activities, including feasibility studies, automation initiatives, vulnerability assessments (VA), threat monitoring, risk assessments, policy compliance scanning, and reporting.

Your role will be crucial in identifying and mitigating security risks, ensuring policy compliance, and maintaining a secure environment for our organization.

Key Responsibilities:
  1. Feasibility Studies:
    1. Conduct daily feasibility studies to assess the viability and effectiveness of potential security measures or initiatives.
    2. Collaborate with cross-functional teams to gather information and analyze the feasibility of implementing new security solutions.
    3. Prepare reports summarizing the findings and recommendations from feasibility studies.
  2. Automation Initiatives:
    1. Identify opportunities for process automation within the security operations function.
    2. Develop and implement automated solutions to streamline security operations and enhance efficiency.
    3. Continuously monitor and optimize existing automation initiatives.
  3. Vulnerability Assessments (VA) and Policy Compliance (PC):
    1. Perform daily application onboarding and assessment for vulnerability scanning.
    2. Analyze vulnerability scan results and generate comprehensive reports.
    3. Collaborate with relevant teams to ensure timely remediation of identified vulnerabilities.
    4. Track and document the progress of remediation efforts.
    5. Provide daily support for troubleshooting and coordination activities related to security incidents.
    6. Generate reports and perform clean-up tasks to maintain accurate and up-to-date security records.
    7. Conduct policy compliance scanning and reporting, ensuring adherence to security standards.
    8. Assist in tracking and documenting remediation efforts for identified security risks.
  4. Threat Monitoring:
    1. Monitor daily threat bulletins, threat intelligence feeds, and other relevant sources.
    2. Stay updated on emerging threats, vulnerabilities, and industry trends.
    3. Assist in identifying potential security risks and implementing proactive measures to mitigate them.
  5. Risk Assessments:
    1. Respond to risk assessment requests related to architecture design and new applications.
    2. Evaluate security risks associated with exemption requests for WAF rules, Snyk findings, IP/URL whitelisting, and ad-hoc assessments.
    3. Collaborate with stakeholders to gather necessary information and perform in-depth risk analysis.
    4. Prepare detailed reports outlining risks and recommendations for risk mitigation.
  6. Periodic Tasks:
    1. Conduct periodic activities such as policy configuration and onboarding.
    2. Perform firewall (FW) rule reviews, coordinate remediation efforts, and track progress.
    3. Coordinate and conduct password audits, ensuring compliance with password policies.
    4. Collaborate with teams to address identified vulnerabilities and improve security posture.
Qualifications and Requirements:
  1. Bachelor's degree in Computer Science, Information Security, or a related field.
  2. Solid understanding of information security principles, concepts, and best practices.
  3. Experience in conducting feasibility studies and performing risk assessments.
  4. Knowledge of vulnerability assessment tools and techniques.
  5. Familiarity with threat monitoring tools and practices.
  6. Strong analytical and problem-solving skills.
  7. Excellent written and verbal communication skills.
  8. Ability to work both independently and collaboratively within a team.
  9. Attention to detail and ability to prioritize tasks effectively.
  10. Strong Development skills and experience are a plus.
  11. Relevant certifications (e.g., CISSP, CISM, CEH) are a plus.

Join our team and contribute to the security of our organization by effectively managing security operations, conducting thorough assessments, and implementing proactive security measures. This is an exciting opportunity for someone passionate about information security and dedicated to maintaining a robust security posture. Apply now and help us safeguard our digital assets.

#J-18808-Ljbffr

  • Manila, National Capital Region, Philippines SM Investments Full time

    Threat and Vulnerability Management Lead1 day ago Be among the first 25 applicantsVulnerability Assessments (VA) and Policy Compliance (PC): Infrastructure AND ApplicationsPerform daily application onboarding and assessment for vulnerability scanning.Analyze vulnerability scan results and generate comprehensive reports.Collaborate with relevant teams to...


  • Manila, National Capital Region, Philippines Monroe Consulting Group Full time

    A successful Security Engineer will be responsible for designing, implementing, and managing Threat Exposure and Attack Surface Management (TASM) platforms or similar systems. The ideal candidate will have a strong background in cybersecurity and be proficient in threat exposure and attack surface management.Responsibilities:Analyze attack surfaces and...


  • Manila, National Capital Region, Philippines weSource Management Consultancy Firm Full time

    We are looking for a Cybersecurity Analyst to join our team in a threat detection role. The ideal candidate will have knowledge of web application vulnerabilities, common attack techniques, and mitigation strategies, as well as experience with manual testing techniques, automated vulnerability scanners, and exploit frameworks.About the RoleThis role involves...


  • Manila, National Capital Region, Philippines weSource Management Consultancy Firm Full time

    Job Overview:The information security consultant plays a crucial role in helping organizations identify and mitigate security threats. As an information security consultant, you will conduct threat intelligence analysis to identify potential security risks and provide recommendations for mitigation.You will work closely with other cybersecurity experts,...


  • Manila, National Capital Region, Philippines Monroe Consulting Group Full time

    A highly skilled Security Engineer is required to join our client's dynamic team in Ortigas, Pasig. The ideal candidate will have at least 8 years of experience in Threat Exposure and Attack Surface Management (TASM) platforms or similar systems.Responsibilities:Design, implement, and manage Threat Exposure and Attack Surface Management (TASM) platforms or...


  • Manila, National Capital Region, Philippines MEGA PRIME FOODS INCORPORATED Full time

    **Job Overview:**Mega Prime Foods Incorporated is seeking a dedicated Cyber Security Analyst to support our organization's digital transformation goals. This role plays a crucial part in safeguarding our digital assets and ensuring the security framework is protected from cyber threats.**Key Responsibilities:Threat Analysis:Analyze security logs from various...


  • Manila, National Capital Region, Philippines Infinit-O Global, Limited Full time

    Cyber Threat Analyst Job SummaryWe are seeking an experienced Cyber Threat Analyst to join our team at Infinit-O Global, Limited.Key Responsibilities:Threat Intelligence: Conduct research on adversary tactics, techniques, and procedures (TTPs) to identify threat leads.Reporting: Author detailed reports on identified threat leads, combining information from...


  • Manila, National Capital Region, Philippines Dexcom Inc. Full time

    About Dexcom Inc.Dexcom Inc. is a pioneer in continuous glucose monitoring (CGM) technology. Our mission is to improve human health by developing innovative solutions for diabetes management.We're driven by a team of passionate individuals who are dedicated to making a difference in the lives of people with diabetes. Join us in our quest to revolutionize...


  • Manila, National Capital Region, Philippines Cathay Land, Inc. Full time

    Job DescriptionThreat Analysis and Monitoring: Our ideal candidate will identify and analyze potential security threats by monitoring network traffic, system logs, and security tools.Incident Response: They will respond swiftly to security incidents, investigate breaches, and provide timely resolution.Vulnerability Management: Regular vulnerability...


  • Manila, National Capital Region, Philippines Infinit-O Global, Limited Full time

    Pasay, Philippines | Posted on 02/28/2025State/Province National Capital Region (Manila)Country PhilippinesAbout UsInfinit-O is the trusted customer-centric and sustainable leader in Business Process Optimization for Small and Medium businesses in the Financial Services, Healthcare, and Technology sectors by delivering continuous improvement through...


  • Manila, National Capital Region, Philippines Infinit-O Global, Limited Full time

    About Infinit-O Global, LimitedInfinit-O is a leading provider of Business Process Optimization services for Small and Medium businesses in the Financial Services, Healthcare, and Technology sectors.Job Description: Cyber Threat AnalystConduct research on technical subject matter such as malware developments, offensive security tools, vulnerability exploits,...


  • Manila, National Capital Region, Philippines YONDU INC. Full time

    The Tech Security Engineer – VAPT is responsible for assessing and strengthening the organization's securityposture by conducting vulnerability assessments and penetration testing (VAPT) across infrastructure, networks,and applications (Web, Mobile, Client-Server). This role involves identifying, analyzing, and mitigating securityvulnerabilities, ensuring...


  • Manila, National Capital Region, Philippines N-able Technologies Ltd. Full time

    Why N-ableIT doesn't get better than this N-able isn't just another software company – we're going places, and we'd love for you to be a part of that journey. With N-ablites in more than 15 countries around the world, you're adding your unique voice to a diverse team of people who are supporting our customers, and one another. The Way We Work, our hybrid...


  • Manila, National Capital Region, Philippines Monroe Consulting Group Full time

    A technology and consulting firm seeks a skilled IT professional for the role of VAPT Specialist. This position requires hands-on experience in web and mobile application vulnerability assessment and penetration testing.In this On-site role in Pasig City, you will work with our client to identify potential security threats and provide recommendations for...


  • Manila, National Capital Region, Philippines TGI Full time

    Job DescriptionTrends Group Inc. is seeking a highly skilled Vulnerability Assessment Lead to join our team.About the Role:This is an exciting opportunity for a motivated individual to work in a dynamic environment and contribute to the success of our organization. The successful candidate will be responsible for leading Vulnerability Assessment (VA) and...


  • Manila, National Capital Region, Philippines Willis Towers Watson Full time

    As a seasoned IT Security Vulnerability Analyst, you will play a critical role in identifying and mitigating cybersecurity risks at Willis Towers Watson. In this role, you will be responsible for conducting vulnerability assessments, penetration testing, and security analysis to identify potential entry points for attackers.Your expertise will help us...


  • Manila, National Capital Region, Philippines TREND MICRO INCORPORATED-PHILIPPINE BRANCH Full time

    VicOne is seeking an expert Automotive Threat Researcher to join our cybersecurity team. Ideal candidates will enhance vehicle security through innovative research and analysis. Apply now to be part of our dynamic companyResponsibilities:Conduct vulnerability research on QNX, AGL, Android Automotive, or related automotive operating systems.Perform automotive...

  • Cloud Security Lead

    3 days ago


    Manila, National Capital Region, Philippines Vista Equity Partners Management, LLC Full time

    In this critical role, you will be responsible for protecting our digital assets from cyber threats and vulnerabilities. You will work closely with cross-functional teams to ensure the confidentiality, integrity, and availability of data. If you are a seasoned cyber security professional with a deep understanding of threats, vulnerability assessments,...


  • Manila, National Capital Region, Philippines Emapta Full time

    Threat Detection AnalystEmapta is a leading innovator in cybersecurity solutions, empowering businesses worldwide to stay secure in an ever-evolving digital landscape. As a Threat Detection Analyst, you will be responsible for analyzing security threats, vulnerabilities, and trends, providing recommendations for risk mitigation.Hands-on experience in...


  • Manila, National Capital Region, Philippines Total Information Management Corp. Full time

    Job DescriptionThe SOC Analyst is responsible for a broad range of responsibilities with a primary emphasis on 24/7 log analysis, threat and event monitoring, and data loss prevention to contribute to effective remediation of security incidents.This includes being part of the primary service relationship interface between customers and TIM SOC Operations,...