IT Security Risk Assessment Officer
7 days ago
Bachelor's degree in Computer Science, Information Technology, or a related field.
Must have minimum 3 years of experience in Information Security or related fields.
Must be knowledgeable on various compliance and regulatory requirements (i.e., BSP, DPA, PCI-DSS, etc.)
Must have experience in various information and IT security domains and controls related to third party risks, data security and risk management, data transmission integrity. This includes understanding various processes related to the service, product or solution provided by vendors to the Bank and its links to bank processes.
Must have experience in information security governance, controls assurance, risk assessments and key risk indicators development.
Must have experience in IT general controls and auditing.
Must have the ability to do research on items assigned to them.
Must have strong background on network and application system security risk assessments.
Must have experience in planning, executing, and documenting assessment activities following established processes and procedures with minimal guidance
Must have experience in leading and working well with the team, internal, and external clients. Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.
Analytical and risk identification skills to analyze a variety of information security –related risk situations and develop recommendations on the best course of action.
Must have Project management skills: to lead and manage accomplishments of assigned tasks/risk assessment activities.
Must possess excellent time management skills, thrive in a fast-paced demanding environment.
Be a self-managed self-starter with good organizational skills to include good follow-up skills
Be able to work under pressure on multiple assessments/projects simultaneously
Strong attention to detail, analytical, and problem-solving skills. Strong learning agility with the ability to learn new processes
Must have good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.
Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action
Must be knowledgeable in using MS office tools such as PowerPoint, word, excel and project.
Job Description:
Develop tactical plans and programs for the establishment and maintenance of the Bank's third-party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset-based risk assessment. Analyze and review of complex bank processes, application system and network security implementation and third-party relationships to identify potential risk including the determination of risk mitigation strategies. Analysis and review of complex application system and network security implementation on the current production environments to identify potential risk including the determination of risk mitigation strategies. Recommend strategies to control risks from inadequate protection of confidentiality, integrity and availability of the information assets, processing facilities and connected services.
Specific Duties & Responsibilities:
Prepares tactical plans and/or programs in the conduct of information, third party and system security risk assessments.
Identify the Bank's critical assets, threats to these assets, vulnerabilities, and reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information.
Coordinate and assess the security performance of third-party vendors that collect, process, transmit, and store client data
Performs threat modelling-based system security risk assessment for all IT systems and other IT assets, as applicable
Analyze and assess the impact of changes in process, technical changes and systems enhancements and third-party relationships.
Reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information and information processing facilities to mitigate information security risk.
Formulates, recommends information security policies and procedures on physical, environmental and personnel security with respect to results of information security assessment activities.
Responsible for coordinating across all business units and stakeholders in gathering information in preparation to the conduct of information, third party and system security risk assessment.
Articulate security findings and risk remediation strategies through issuance of risk assessment report. Track and follow-up status of risk mitigation activities.
Ensures security risk register is maintained and kept updated including status of remediation activities.
Executes and monitors accomplishment of the risk assessment plans and programs.
Articulate security findings and risk remediation strategies through issuance of risk assessment report; writing comprehensive, concise and understandable to non-technical. Tracking and follow up on status of mitigation activities.
Maintain and track library of records and documentation.
Investigation of applicable reported incidents related to information handling and data privacy.
Keep abreast of and apply information, IT and third-party security trends and regulatory and compliance changes affecting the security of landscape, security best practices, threat landscape (emerging and existing) and apply them in daily work.
Review the work of other Security Quality and Assurance Risk Assessors; guides and mentors them.
Proactively works with the Department Head in implementing programs for the continuous improvement of the bank's information security plans and strategies.
Perform other information security risk management and compliance related duties and responsibilities as directed by the Department Head.
-
IT Security Risk Assessment Officer
2 weeks ago
Taguig, National Capital Region, Philippines Hunter's Hub Incorporated Full timeJob DescriptionJob Summary:Develop tactical plans and programs for the establishment and maintenance of the Bank's third-party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset-based risk assessment. Analyze and review of complex bank...
-
IT Security Risk Assessment Officer
1 week ago
Taguig, National Capital Region, Philippines Hunter's Hub Incorporated Full timeJob DescriptionJob Summary:Develop tactical plans and programs for the establishment and maintenance of the Bank's third-party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset-based risk assessment. Analyze and review of complex bank...
-
Information Security Risk Assessment Lead
7 days ago
Taguig, National Capital Region, Philippines Hunter's Hub, Inc. Full timeJob Summary:We are seeking an Information Security Risk Assessment Lead to join our team at Hunter's Hub, Inc. This individual will lead the development and implementation of information security risk management plans to ensure the Bank's risk profile is managed effectively. They will perform comprehensive risk assessments, analyze complex security...
-
IT Security Governance Officer
7 days ago
Taguig, National Capital Region, Philippines Hunter's Hub, Inc. Full timeJob Overview:Hunter's Hub, Inc. is seeking an IT Security Governance Officer to join our team. As a key member of our security team, this individual will be responsible for developing and implementing strategic plans to ensure the Bank's information security governance framework is aligned with industry best practices and regulatory requirements. This...
-
Security Consulting and Risk Officer
1 week ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeSecurity Consulting and Risk OfficerLocation: TaguigSetup: OnsiteSalary: Open Rate Graduate of any Bachelors degree courseGraduate of any college degree in Computer Science or Information Security, or related technical field of expertise.General understanding of regulatory compliance and how it relates to application security and privacy.Certification...
-
Info Security Risk Auditor
2 weeks ago
Taguig, National Capital Region, Philippines Optum Full timeOptum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion,...
-
Security Consulting and Risk Officer
2 weeks ago
Taguig, National Capital Region, Philippines Nityo Infotech Full timeLocation: BGC TaguigSchedule: DayshiftWork Setup: OnsiteQualifications:*Graduate of any college degree in Computer Science or Information Security, or related technical field of expertise*General understanding of regulatory compliance and how it relates to application security and privacy*Certification training may include is CISA, CISM, SANS GIAC, CISSP,...
-
IT Security Compliance Specialist
6 days ago
Taguig, National Capital Region, Philippines IT Managers, Inc. Full timeJob DescriptionWe are seeking a highly skilled IT Security Compliance Specialist to join our team at IT Managers, Inc.The successful candidate will work closely with our security and compliance teams to develop policies and procedures that govern our products.Key ResponsibilitiesDevelop policies and procedures in accordance with industry standards and...
-
Cybersecurity Risk Management Specialist
7 days ago
Taguig, National Capital Region, Philippines Hunter's Hub, Inc. Full timeJob Description:The Cybersecurity Risk Management Specialist at Hunter's Hub, Inc. plays a pivotal role in developing and implementing tactical plans to ensure the Bank's third-party information security risk management framework is established and maintained. This individual will perform thorough third-party security, system security, and information...
-
Information Security Manager
1 week ago
Taguig, National Capital Region, Philippines Visage Executive Search Full timeShall represent the bank in all cybersecurity matters and will be responsible for establishing and maintaining an Information Security Management Program to ensure that the information assets are adequately protected. The ISM should be able to identify, evaluate and report the information security risks in relation to the bank's compliance and regulatory...
-
Compliance Risk Officer
2 weeks ago
Taguig, National Capital Region, Philippines Visage Executive Search Full timeBrief Description:The Compliance Risk Officer is primarily responsible in assisting the Chief Compliance Officer inoverseeing the risk management framework of the Bank, ensuring compliance with regulatoryrequirements, and implementing strategies to mitigate risks across various functions.Duties & Responsibilities:1. Risk Assessment and Monitoring:• Conduct...
-
IT Security Risk Consultant
2 days ago
Taguig, National Capital Region, Philippines Amadeus Full timeAbout the RoleWe are seeking a highly motivated and detail-oriented individual to join our Security Operations Center (SOC) team as an Associate Information Security Analyst.The role involves monitoring and reviewing security events and alerts from various sources, including network and endpoint sensors, SIEM systems, and commercial sources.The ideal...
-
Information Security Analyst I
6 days ago
Taguig, National Capital Region, Philippines Neksjob Full timeInformation Security Analyst IPractice: Cybersecurity | Areas of Work: Security Monitoring & Incident ResponseLevel: Specialist | Location: Remote (Work from Home) | Shift: Night ShiftSalary: PHP 35,000About the RoleAre you passionate about cybersecurity and safeguarding digital assets? As an Information Security Analyst I, you will play a critical role in...
-
Credit and Risk Assessment Professional
5 days ago
Taguig, National Capital Region, Philippines Ingram Micro Company Full timePosition Description:We are seeking a skilled Credit and Risk Assessment Professional to join our team at Ingram Micro. As a key member of our finance department, you will be responsible for developing and implementing policies for investigating customer credit-worthiness. Your expertise in credit risk analysis and management will play a crucial role in...
-
Cyber Security Risk Analyst
6 days ago
Taguig, National Capital Region, Philippines Cyber Crime Full timeJob OverviewCiti, a leading global bank for institutions with cross-border needs, is seeking a highly skilled professional to join our team as Assistant Vice President, Technology/Cyber Risk Sr Analyst - Hybrid.This role involves assessing technology and cyber risks, evaluating actions to address root causes, and supporting independent assurance activities...
-
Risk Management Officer
2 days ago
Taguig, National Capital Region, Philippines Aboitiz Group Full timeAre you a detail-oriented Risk Management Officer looking for a new challenge? Aboitiz Equity Ventures is seeking a skilled professional to oversee the development and implementation of its Business Continuity Management (BCM) program. As a key member of our team, you will be responsible for ensuring the continuity of critical business functions through...
-
Information Security Manager Bank
2 weeks ago
Taguig, National Capital Region, Philippines MKIT (HONG KONG) HOLDINGS LIMITED Full timeShall represent the bank in all cybersecurity matters and will be responsible for establishing and maintaining Information Security Management Program to ensure that the information assets are adequately protected. The ISM should be able to identify, evaluate and report the information security risks in relation to the bank's compliance and regulatory...
-
Chief Security Officer Candidate
6 days ago
Taguig, National Capital Region, Philippines Michael Page Full timeAbout the RoleWe are seeking a highly experienced Chief Security Officer Candidate to join our team. The successful candidate will be responsible for developing and implementing a comprehensive cybersecurity strategy that aligns with our business objectives.Key Responsibilities:Develop and implement comprehensive cybersecurity policies and procedures that...
-
Compliance Officer
6 days ago
Taguig, National Capital Region, Philippines AtomIT Business Solutions Full time**What We're Looking For**We are looking for a highly skilled Information Security Professional to join our team at AtomIT Business Solutions. As a key member of our security team, you will play a critical role in ensuring the confidentiality, integrity, and availability of sensitive data.In this position, you will be responsible for evaluating, evolving,...
-
Cybersecurity Risk Specialist
6 days ago
Taguig, National Capital Region, Philippines UnitedHealth Group Full timeAt UnitedHealth Group, we're committed to helping people live healthier lives and making the health system work better for everyone. We believe that diversity is a key component in creating a healthier atmosphere.In this role as Cybersecurity Risk Specialist, you'll play a crucial part in ensuring the security and compliance of our third-party suppliers....