
Security Analyst Architecture
2 days ago
Position Summary:The Cyber & Information Security Analyst Architecture & Engineering is responsible for delivering the client's Cyber Security Architecture and Engineering capability, working with line management to set the architectural vision, roadmap, and standards in line with the Company's policies and frameworks, and to deliver effective change activities supporting the UK&I business strategy. The Cyber & Information Security Analyst Architecture and Engineering serves as a key member of the UK&I CISO, wider UK&I Digital & IT and Group community, with delegated responsibilities associated with the design and delivery of applications and systems that are secured by design. Keeping up-to-date with security threats that have the potential to adversely affect the client's Manufacturing & Industrial businesses, ensuring adopted cyber security architectural frameworks are fit for purpose and evolve to counter such threats.
Ensuring appropriate Information, IT and OT capabilities and controls are incorporated into architectural designs to protect the client's Manufacturing & Industrial businesses from internal and external cyber threats. Taking responsibility and ensuring local programmes and projects adhere to Group enhance cyber and information security, mitigating existing and emerging security risks. Job Details:Work from HomeMonday to Friday | 8 AM to 5 PM UK Time*Following UK HolidaysResponsibilities:Contribute to defining and delivering a Cyber & Information Security Strategy that supports the company's Business and Digital Transformation plans.
In addition, support the effective delivery of Group-led Cyber & Information Security Hardening initiatives. In collaboration with the Manager and UK&I CISO organization, help define a target state security architecture and identify incremental and strategic change initiatives (with estimated effort and cost) to migrate to the target state. Conduct continuous assessments of current Digital & IT and Industrial systems and processes, identifying areas for improvement using next-generation solutions for which you will lead the secure design and in collaboration with other departments, implement through effective planning, resource management, and cost control.
Support all UK&I project initiatives ensuring the company's existing security frameworks such as the 'Project Security Assessment Tool' (PSAT), Security Insurance Plan (SIP), and Minimum Security Requirements (23 Infrastructure, 25 Web & Application, and 28 Industrial) are completed and integrated into the Product Delivery Lifecycle. Maintain awareness and knowledge of vendor space, current and emerging technologies, and services of interest and relevance to the maturity and continuous improvements of the UK&I and Group catalog of security services. Engage with various stakeholder groups and committees across Digital & IT, Industrial, and Group to provide subject matter expertise and advice on all matters of cyber and information security architecture, and secure commitment to support strategic and tactical security initiatives.
Provide consultancy for technology implementation – ensuring that legislative (privacy, data protection) and security (policies, minimum security requirements, PSATs, etc.) factors are considered to safeguard the company's information assets. Act as a contact for security architecture & engineering project-related escalations. Support the Cyber & Information Security GRC Lead to undertake technical threat and risk assessments/reviews of IT and the Industrial business environments.
In collaboration with line management and the CISO department, develop actions and plans with Digital & IT and Business leaders to address identified security exposures, through effective planning and execution with the help of supporting functions. Keep up-to-date with the latest threat information, risks, and technologies, and implement adequate detective, preventive, and corrective security controls seeking internal (Group) and external advice where necessary. Work closely with the Development department to ensure the 'Low Code' 'No Code' strategy and associated platforms incorporate effective security by design methodologies assuring that known security weaknesses i.e. OWASP top 10 are addressed and tested in advance of system migration to production.
Ensure that you fully comply with Saint-Gobain's Data Governance Policies as they relate to your area and demonstrate in your day-to-day work that you treat data as an important corporate asset that must be protected and managed. Maintain Saint-Gobain's compliance standards and in collaboration with the CISO and CISO department, ensure timely completion and submission of all local and group-driven reporting requirements. In collaboration with the Group, ensure that all architecture designs established to ensure the safe and secure Acquisitions and Divestments are completed in line with Group directives, whilst minimizing the introduction of any new security risks to the company.
Qualifications:Degree in business administration or a technology-related field. Industry-recognised security certifications, such as TOGAF/SABSA/CISSP/CISM or equivalent are desirable but not essential, though attainment will form part of personal development objectives. Experience in a combination of network and or infrastructure design, information security, and Digital IT jobs.
Knowledge of information security management frameworks, such as ISO/IEC 27001, and NIST are beneficial but not essential. An understanding of the evolving threat landscape and the ability to translate an emerging threat's likelihood of exploiting inherent weaknesses, and business impact and therefore articulating calculating overall risk and developing risk mitigations - is beneficial. Methodical approach to architecture design inclusive of threat assessment and treatment.
Ability to work under pressure and manage multiple priorities simultaneously. Excellent written and verbal communication skills and a high level of personal integrity. Self-motivated and ability to work on own initiative toward business improvement.
Analytical skills and ability to assimilate information. Relationship builder and good networking skills. General understanding of Risk Management and Risk-based decision-making.
Experience with third-party assurance and contract negotiations. Experience with Project Management and Development methodologies, such as Agile. Broad technical Digital IT and Industrial experience including Cloud computing, websites, ERP, big data, ICS, and SCADA systems.
Good standards in quality and integrity towards the delivery of information.
-
Security Engineer
2 days ago
Manila, National Capital Region, Philippines TAC Security Full time $80,000 - $100,000 per yearAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This...
-
Security Engineer
2 days ago
Manila, National Capital Region, Philippines TAC Security Full time $80,000 - $100,000 per yearAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This...
-
Security Analyst
7 days ago
Manila, National Capital Region, Philippines Verifone Full timeJob SummaryThe Security Analyst will be responsible for monitoring our security infrastructure, identifying and responding to security threats, managing vulnerabilities, and contributing to the continuous improvement of our overall security posture. This role is crucial in safeguarding our organization's systems, data, and reputation against an ever-evolving...
-
Senior Security Analyst
2 days ago
Manila, National Capital Region, Philippines QBE Insurance Full time $60,000 - $80,000 per yearPrimary DetailsTime Type: Full time Worker Type: EmployeeWe are seeking a highly skilled and motivated Senior Security Analyst to join our Global Security Operations Centre based in the Philippines. Reporting to the Global Security Operations Centre Lead, the Senior Security Analyst will be a key member of our rapidly growing Global team. This role is...
-
Senior Security Analyst
2 days ago
Manila, National Capital Region, Philippines QBE Insurance Full time $90,000 - $120,000 per yearPrimary DetailsTime Type: Full timeWorker Type: EmployeeWe are seeking a highly skilled and motivated Senior Security Analyst to join our Global Security Operations Centre based in the Philippines. Reporting to the Global Security Operations Centre Lead, the Senior Security Analyst will be a key member of our rapidly growing Global team.This role is looking...
-
Network Security Specialist
4 days ago
Manila, National Capital Region, Philippines beBeeSecurity Full time $40,000 - $60,000Cloud security monitoring is a vital function of any organization, helping to prevent cyber threats and protect sensitive data. As a SOC analyst, you will play a critical role in identifying and responding to potential security incidents.Key ResponsibilitiesMonitor and analyze network traffic for signs of suspicious activity Investigate and respond to...
-
IT Security Analyst
2 days ago
Manila, National Capital Region, Philippines First Focus Full time $60,000 - $80,000 per yearAbout First FocusFirst Focus is Australia's leading Managed Service Provider, with a team of over 300 technical professionals across Australia, New Zealand, and the Philippines. For over 15 years, we've delivered exceptional IT services and solutions, growing consistently and profitably. Our commitment to innovation and excellence has led to the expansion of...
-
IT Security Analyst
2 days ago
Manila, National Capital Region, Philippines Scan Global Logistics Full time $40,000 - $60,000 per yearThe IT Security Analyst primarily function is for strengthening & enhancement Security Infrastructure and Cloud. The successful candidate will be responsible for delivering effective and efficient global wide Security Project and support for security related appliance and he/she will also be a primary contact security hardening and security support. Roles...
-
L1 Cyber Security Analyst
2 days ago
Manila, National Capital Region, Philippines SecureOps Full time ₱600,000 - ₱1,200,000 per yearSOC - Cyber Security Analyst L1The primary responsibilities of the Level 1 Cyber Security Analyst are to sort, filter, analyze, qualify and escalate various cyber-security alerts inside log aggregation tools (SIEM) such as ArcSight, Splunk, and QRadar. The Analyst is also responsible for incident follow-up, process suggestions, and basic automation. This...
-
Security Analyst, Technology
2 days ago
Manila, National Capital Region, Philippines Kroll Full time $80,000 - $120,000 per yearOur professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you'll discover a supportive...