Security Consulting And Risk Officer
2 days ago
to follow
Be #InGoodHands with Metrobank
Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach
Position Title: Security Consulting and Risk Officer
Job Summary: Responsible for securing data, network, and applications in system development or system implementations. Perform threat modeling, business and technical process analysis, application security and architecture reviews to evaluate, identify vulnerabilities and enforce security controls in IT and application systems. Ensures coordination of penetration testing support and vulnerability validation scans of systems project.
Role Exposure:
- Work closely with cross-functional teams - ITG Infrastructure team, ITG DevOps team, Developers, Solutions and Enterprise Architects, Technical Project Managers, Delivery Managers and Project Proponents.
- Helps to improve the security health of the application systems, information processing facilities and connected services of the bank by:
- Providing security consulting services on information security related matters for on premise and cloud-based project implementations and deployments.
- Serves as project security technical point of contact for system development as it relates to automation, continuous integration/continuous deployment activities and products/services being developed and deployed across the full application development life cycle.
- Ensure enforcement of security requirements across all new application systems and API deployments.
- Performs threat modeling and business/technical process analysis to identify vulnerabilities/weaknesses on processes and technology implementations thru a documented analysis and assessment report.
- Standardize the technical, functional and administrative security requirements covering areas of application system, technical design and architecture.
- Ensures that the security requirements align with the business objective of the application systems to be implemented.
- Provides consulting on technical designs and solutions to address infrastructure security and application security related weaknesses.
- Collaborate with relevant stakeholders to implement security improvements.
- Collaborate with the appropriate subject matter expert in Security Architecture and Innovation Department in reviewing security architecture and addressing architecture concerns in a project.
- Ensures that source code reviews are performed and validated across all platforms and frameworks.
- Coordinates application vulnerability scanning and penetration testing remediation activities with ITG developers.
- Assist with vulnerability prioritization and provide guidance on resolution.
- Ensures that standard security requirements are kept updated.
- Maintains an expert knowledge in the field of Information Security and the related issues, systems, processes, products, and services. Stay current with best security practices.
- Collaborates with other ITG Servicing units and application teams to harden its operating systems and application systems to better protect user data when implemented.
- Proactively works with the Department Head in implementing programs for the continuous improvement of the bank's information security posture.
- Perform other information security governance, risk and compliance related duties and responsibilities as directed by the Department Head.
Qualifications:
- Graduate of any college degree in Computer Science or Information Security, or related technical field of expertise.
- General understanding of regulatory compliance and how it relates to application security and privacy.
- Certification training may include is CISA, CISM, SANS GIAC, CISSP, PCI-DSS, etc.)
- Understanding of network and application security risks and how to address them.
- History of designing, developing, or customizing application systems a plus.
- Extensive and deep technical knowledge/understanding of system development, typically ranging from front-end user interfaces all the way to the back-end systems of both on premise and cloud deployment.
- Working knowledge of on premise and cloud architectures.
- Strong familiarity with web protocols and web services, networking concepts and encryption.
- Understanding of Microsoft, Linux/Unix security architecture.
- Strong attention to detail, analytical, and problem-solving skills. Thinking logically and intuitively; strong learning agility with the ability to learn new processes/patterns
- Result-orientated in terms of disposition for corrective action and security remediation.
- Have good teamwork and collaboration skills, a good team player with the ability to lead.
- Good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.
- Possess excellent time management skills, thrive in a fast paced demanding environment
- Be a self-managed, self-starter with good organizational skills to include good follow-up skills
- Knowledge in using MS office tools such as PowerPoint, word, excel and project
Other Details:
Rank: Junior Officer
Unit: Information Security Division
Location: Metrobank Center, BGC
to follow
-
Security Consultant
2 days ago
Philippines Asia Select Full time ₱900,000 - ₱1,200,000 per yearJob title:SECURITY CONSULTANTJob type:Full-TimeEmp type:Full-timeFunctional Expertise:INFORMATION TECHNOLOGY & TELECOMMUNICATIONSSkills:VAPTJob published: Job ID:47822JOB DESCRIPTIONKey Responsibilities:As a Security Consultant, you will play a key role in delivering high-quality technical security assessments for prominent clients worldwide. Your...
-
SAP Security Consultant
4 weeks ago
, , Philippines Socium - Teams Done Differently Full timeResponsibilities Design, implement, and manage SAP security roles and authorizations. Conduct risk analysis and mitigation using SAP GRC (Access Control). Collaborate with business and audit teams to ensure compliance and segregation of duties (SoD). Support SAP system upgrades and transport management from a security perspective. Troubleshoot authorization...
-
SAP GRC Security Lead Consultant
5 days ago
, , Philippines Avensys Consulting Full timeSAP GRC Security Lead Consultant - Australia (Onsite) Location: Newcastle, Australia (on-site) Type: Permanent Experience: 15+ years Candidates should be open to relocate to Australia. Requirements Minimum 15+ years of experience in implementation support and upgrade projects. Experience with SAP GRC AC – ARM, ARA, EAM . BTP Experience. S/4 HANA Fiori...
-
Security Consultant
2 days ago
Remote, Philippines Theos Cyber Solutions Ltd. Full time ₱1,200,000 - ₱2,400,000 per yearAbout TheosOur mission is to empower businesses to thrive in the new digital security age by helping define and execute strategies to achieve cyber resilience. Practical steps instead of silver bullets. We are a team of experts in key security domains, including Penetration Testing, Red Teaming, Managed Detection & Response, and Digital Forensics and...
-
Security Trader
3 weeks ago
, Davao del Sur, Philippines PUBLIC SAFETY SECURITY Full timeTrade Execution Buy and sell securities in financial markets according to client instructions or market strategies. Execute trades efficiently and accurately, ensuring compliance with trading policies and regulations. Monitor and manage positions to minimize risk and optimize profitability. Market Analysis Stay up-to-date on market trends, economic news, and...
-
Security Officer/ Security Guard
1 week ago
, Benguet, Philippines Skyhawk Security Services, Inc. Full timeTasks for Security Officer/ Security Guard - Tuba, Benguet Maintain security and safety of property and personnel Monitor surveillance equipment Inspect buildings, equipment, and access points Enforce regulations to prevent theft, violence, and infractions of rules Investigate and prepare reports on incidents and suspicious activities Apprehend criminal...
-
Fraud & Security Risk Assessment Manager
3 weeks ago
, Metro Manila, Philippines GCash Full timeOverview Join to apply for the Fraud & Security Risk Assessment Manager role at GCash . Responsibilities Develops a complete understanding of a company’s technology and information systems. Identify and communicate current and emerging cybersecurity and fraud threats and risks that are relevant to GCASH. Design cybersecurity and fraud management...
-
Security Manager
3 weeks ago
, Davao del Sur, Philippines Security Devices Trading Full timeResponsibilities Develop, implement, and oversee security policies and procedures to safeguard company assets, employees, and visitors. Monitor security operations, manage incident response, and conduct regular risk assessments to identify vulnerabilities. Recruit, train, and supervise security personnel, ensuring adherence to safety standards and protocols....
-
, Bulacan, Philippines Skyhawk Security Services, Inc. Full timeOverview Tasks for Security Officer/ Security Guard – Bulacan, Central Luzon Secure premises and personnel by patrolling property; monitoring surveillance equipment; inspecting buildings, equipment, and access points; permitting entry Obtain help by sounding alarms Prevent losses and damage by reporting irregularities, informing violators of policy and...
-
Sr. Security
2 weeks ago
, , Philippines Asurion Full timeSr. Security & Safety Officer page is loaded## Sr. Security & Safety Officerremote type: Onsitelocations: Cebutime type: Full timeposted on: Posted Todayjob requisition id: ASU * ## Maintain a safe and secured environment for employees, clients and visitors by enforcing security policies and procedures.* ## Provides risk assessments on security and safety to...