Security Consulting and Risk Officer

6 days ago


Taguig, National Capital Region, Philippines Umpisa Inc Full time

Job Summary

Responsible for securing data, network, and applications in system development or system

implementations. Perform threat modeling, business and technical process analysis, application

security and architecture reviews to evaluate, identify vulnerabilities and enforce security

controls in IT and application systems. Ensures coordination of penetration testing support and

vulnerability validation scans of systems project.

Specific Duties & Responsibilities


• Work closely with cross-functional teams - ITG Infrastructure team, ITG DevOps team,

Developers, Solutions and Enterprise Architects, Technical Project Managers, Delivery

Managers and Project Proponents.


• Helps to improve the security health of the application systems, information processing

facilities and connected services of the bank by:

Providing security consulting services on information security related matters for on

premise and cloud-based project implementations and deployments.

Serves as project security technical point of contact for system development as it relates

to automation, continuous integration/continuous deployment activities and

products/services being developed and deployed across the full application development

life cycle.

Ensure enforcement of security requirements across all new application systems and API

deployments.

Performs threat modeling and business/technical process analysis to identify

vulnerabilities/weaknesses on processes and technology implementations thru a

documented analysis and assessment report.

Standardize the technical, functional and administrative security requirements covering

areas of application system, technical design and architecture.

Ensures that the security requirements align with the business objective of the application

systems to be implemented.

Provides consulting on technical designs and solutions to address infrastructure security

and application security related weaknesses.

Collaborate with relevant stakeholders to implement security improvements.


• Collaborate with the appropriate subject matter expert in Security Architecture and

Innovation Department in reviewing security architecture and addressing architecture

concerns in a project.


• Ensures that source code reviews are performed and validated across all platforms and

frameworks.


• Coordinates application vulnerability scanning and penetration testing remediation activities

with ITG developers.


• Assist with vulnerability prioritization and provide guidance on resolution.


• Ensures that standard security requirements are kept updated.


• Maintains an expert knowledge in the field of Information Security and the related issues,

systems, processes, products, and services. Stay current with best security practices.


• Collaborates with other ITG Servicing units and application teams to harden its operating

systems and application systems to better protect user data when implemented.


• Proactively works with the Department Head in implementing programs for the continuous

improvement of the bank's information security posture.


• Perform other information security governance, risk and compliance related duties and

responsibilities as directed by the Department Head.

Job Specifications


• Graduate of any college degree in Computer Science or Information Security, or related

technical field of expertise.


• General understanding of regulatory compliance and how it relates to application security

and privacy.


• Certification training may include is CISA, CISM, SANS GIAC, CISSP, PCI-DSS, etc.)


• Understanding of network and application security risks and how to address them.


• History of designing, developing, or customizing application systems a plus.


• Extensive and deep technical knowledge/understanding of system development, typically

ranging from front-end user interfaces all the way to the back-end systems of both on

premise and cloud deployment.


• Working knowledge of on premise and cloud architectures.


• Strong familiarity with web protocols and web services, networking concepts and

encryption.


• Understanding of Microsoft, Linux/Unix security architecture.


• Strong attention to detail, analytical, and problem-solving skills. Thinking logically and

intuitively; strong learning agility with the ability to learn new processes/patterns


• Result-orientated in terms of disposition for corrective action and security remediation.


• Have good teamwork and collaboration skills, a good team player with the ability to lead.


• Good written and verbal communication skills: to effectively articulate and explain complex

security topics in simple language and easy to understand concepts.


• Possess excellent time management skills, thrive in a fast paced demanding environment


• Be a self-managed, self-starter with good organizational skills to include good follow-up

skills


• Knowledge in using MS office tools such as PowerPoint, word, excel and project



  • Taguig, National Capital Region, Philippines Asia Select Full time

    Job title:SENIOR SECURITY CONSULTANTJob type:Full-TimeEmp type:Full-timeFunctional Expertise:CONSULTINGINFORMATION TECHNOLOGY & TELECOMMUNICATIONSSkills:CONSULTINGSUPPLY CHAINRISK ASSESSMENTLocation:BGC, Taguig CityJob published: Job ID:48688JOB DESCRIPTIONKey Responsibilities:Assess supply chain security risk: Conduct third-party and supply chain security...


  • Taguig, National Capital Region, Philippines Asia Select, Inc. (ASI) Full time

    KEY RESPONSIBILITIESYou will:Assess supply chain security risk: Conduct third-party and supply chain security assessments, identifying systemic risks across vendors, service providers, and technology dependencies.Design supply chain security frameworks: Develop and implement supply chain security strategies aligned to standards such as NIST CSF, NIST , ISO...


  • Taguig, National Capital Region, Philippines WHR Global Consulting Full time

    POSITION TITLE:Risk Management OfficerWORK SETUP: Full Time, OnsiteWORK LOCATION: Arca South, Taguig CityJOB SUMMARY:The Risk Management Officer supports the organization by identifying potential operational risks across various processes, departments and functions. The Risk Management Officer collaborates with the Risk Management Associate and other...


  • Taguig, National Capital Region, Philippines HRTX Full time

    The Technology Risk Senior Consultant - Cloud Control, specifically within Financial Services, focuses on assessing and managing technology risks related to cloud computing for financial institutions. This role involves leading teams, conducting risk assessments, developing and implementing controls, and ensuring compliance with relevant regulations and...

  • Security Consultant

    2 days ago


    Taguig, National Capital Region, Philippines Theos Cyber Solutions Ltd. Full time

    About TheosOur mission is to empower businesses to thrive in the new digital security age by helping define and execute strategies to achieve cyber resilience. Practical steps instead of silver bullets. We are a team of experts in key security domains, including Penetration Testing, Red Teaming, Managed Detection & Response, and Digital Forensics and...

  • IT Risk Supervisor

    6 days ago


    Taguig, National Capital Region, Philippines WHR Global Consulting Full time

    About the CompanyLocation: Near Arca South, Taguig, Metro ManilaTerm: Full Time - On siteEarn up to 40k monthly (depending on your skills) + allowancesAbout the Role• Analytical and problem-solving skills with attention to detail.• Strong communication and stakeholder management abilities.• Knowledge of operational risk frameworks (RCSA, KRI, Incident...


  • Taguig, National Capital Region, Philippines Private Advertiser Full time

    Security Officer/ Security Guard Openings - Taguig City, Metro ManilaTaguig City, Metro Manila - Job Duties and Tasks for Security Officer/ Security Guard· Customer Service - While their primary role is to ensure security, guards also serve as a point of contact for visitors and employees, providing directions, answering questions, and assisting with...


  • Taguig, National Capital Region, Philippines Marsh Full time

    We are seeking a talented individual to join our Marsh Advisory team at Marsh Philippines. This role will be based in Taguig City. This is a hybrid role which is mostly output based, requires frequent travel and site visits.We are looking for someone who can deliver tailored advice and solutions to support client's risk management decisions and overall...

  • Third-Party Risk

    2 weeks ago


    Taguig, National Capital Region, Philippines Denova Consulting Full time

    We are seeking a skilled Third-Party Risk & Compliance Specialist to join us here in Denova as part of our exclusive talent poolWe are looking for people who can work mid-shift or night shift, depending on client's request.This role is open exclusively to candidates residing in the Philippines.Key responsibilities:Support the design, implementation and...


  • Taguig, National Capital Region, Philippines Theos Cyber Solutions Ltd. Full time

    About TheosOur mission is to empower businesses to thrive in the new digital security age by helping define and execute strategies to achieve cyber resilience. Practical steps instead of silver bullets. We are a team of experts in key security domains, including Penetration Testing, Red Teaming, Managed Detection & Response, and Digital Forensics and...