Security Consulting and Risk Officer
6 days ago
Job Summary
Responsible for securing data, network, and applications in system development or system
implementations. Perform threat modeling, business and technical process analysis, application
security and architecture reviews to evaluate, identify vulnerabilities and enforce security
controls in IT and application systems. Ensures coordination of penetration testing support and
vulnerability validation scans of systems project.
Specific Duties & Responsibilities
• Work closely with cross-functional teams - ITG Infrastructure team, ITG DevOps team,
Developers, Solutions and Enterprise Architects, Technical Project Managers, Delivery
Managers and Project Proponents.
• Helps to improve the security health of the application systems, information processing
facilities and connected services of the bank by:
Providing security consulting services on information security related matters for on
premise and cloud-based project implementations and deployments.
Serves as project security technical point of contact for system development as it relates
to automation, continuous integration/continuous deployment activities and
products/services being developed and deployed across the full application development
life cycle.
Ensure enforcement of security requirements across all new application systems and API
deployments.
Performs threat modeling and business/technical process analysis to identify
vulnerabilities/weaknesses on processes and technology implementations thru a
documented analysis and assessment report.
Standardize the technical, functional and administrative security requirements covering
areas of application system, technical design and architecture.
Ensures that the security requirements align with the business objective of the application
systems to be implemented.
Provides consulting on technical designs and solutions to address infrastructure security
and application security related weaknesses.
Collaborate with relevant stakeholders to implement security improvements.
• Collaborate with the appropriate subject matter expert in Security Architecture and
Innovation Department in reviewing security architecture and addressing architecture
concerns in a project.
• Ensures that source code reviews are performed and validated across all platforms and
frameworks.
• Coordinates application vulnerability scanning and penetration testing remediation activities
with ITG developers.
• Assist with vulnerability prioritization and provide guidance on resolution.
• Ensures that standard security requirements are kept updated.
• Maintains an expert knowledge in the field of Information Security and the related issues,
systems, processes, products, and services. Stay current with best security practices.
• Collaborates with other ITG Servicing units and application teams to harden its operating
systems and application systems to better protect user data when implemented.
• Proactively works with the Department Head in implementing programs for the continuous
improvement of the bank's information security posture.
• Perform other information security governance, risk and compliance related duties and
responsibilities as directed by the Department Head.
Job Specifications
• Graduate of any college degree in Computer Science or Information Security, or related
technical field of expertise.
• General understanding of regulatory compliance and how it relates to application security
and privacy.
• Certification training may include is CISA, CISM, SANS GIAC, CISSP, PCI-DSS, etc.)
• Understanding of network and application security risks and how to address them.
• History of designing, developing, or customizing application systems a plus.
• Extensive and deep technical knowledge/understanding of system development, typically
ranging from front-end user interfaces all the way to the back-end systems of both on
premise and cloud deployment.
• Working knowledge of on premise and cloud architectures.
• Strong familiarity with web protocols and web services, networking concepts and
encryption.
• Understanding of Microsoft, Linux/Unix security architecture.
• Strong attention to detail, analytical, and problem-solving skills. Thinking logically and
intuitively; strong learning agility with the ability to learn new processes/patterns
• Result-orientated in terms of disposition for corrective action and security remediation.
• Have good teamwork and collaboration skills, a good team player with the ability to lead.
• Good written and verbal communication skills: to effectively articulate and explain complex
security topics in simple language and easy to understand concepts.
• Possess excellent time management skills, thrive in a fast paced demanding environment
• Be a self-managed, self-starter with good organizational skills to include good follow-up
skills
• Knowledge in using MS office tools such as PowerPoint, word, excel and project
-
Senior Security Consultant
6 days ago
Taguig, National Capital Region, Philippines Asia Select Full timeJob title:SENIOR SECURITY CONSULTANTJob type:Full-TimeEmp type:Full-timeFunctional Expertise:CONSULTINGINFORMATION TECHNOLOGY & TELECOMMUNICATIONSSkills:CONSULTINGSUPPLY CHAINRISK ASSESSMENTLocation:BGC, Taguig CityJob published: Job ID:48688JOB DESCRIPTIONKey Responsibilities:Assess supply chain security risk: Conduct third-party and supply chain security...
-
Senior Security Consultant
4 days ago
Taguig, National Capital Region, Philippines Asia Select, Inc. (ASI) Full timeKEY RESPONSIBILITIESYou will:Assess supply chain security risk: Conduct third-party and supply chain security assessments, identifying systemic risks across vendors, service providers, and technology dependencies.Design supply chain security frameworks: Develop and implement supply chain security strategies aligned to standards such as NIST CSF, NIST , ISO...
-
Risk Management Officer
4 days ago
Taguig, National Capital Region, Philippines WHR Global Consulting Full timePOSITION TITLE:Risk Management OfficerWORK SETUP: Full Time, OnsiteWORK LOCATION: Arca South, Taguig CityJOB SUMMARY:The Risk Management Officer supports the organization by identifying potential operational risks across various processes, departments and functions. The Risk Management Officer collaborates with the Risk Management Associate and other...
-
Technology Risk Senior Consultant
2 days ago
Taguig, National Capital Region, Philippines HRTX Full timeThe Technology Risk Senior Consultant - Cloud Control, specifically within Financial Services, focuses on assessing and managing technology risks related to cloud computing for financial institutions. This role involves leading teams, conducting risk assessments, developing and implementing controls, and ensuring compliance with relevant regulations and...
-
Security Consultant
2 days ago
Taguig, National Capital Region, Philippines Theos Cyber Solutions Ltd. Full timeAbout TheosOur mission is to empower businesses to thrive in the new digital security age by helping define and execute strategies to achieve cyber resilience. Practical steps instead of silver bullets. We are a team of experts in key security domains, including Penetration Testing, Red Teaming, Managed Detection & Response, and Digital Forensics and...
-
IT Risk Supervisor
6 days ago
Taguig, National Capital Region, Philippines WHR Global Consulting Full timeAbout the CompanyLocation: Near Arca South, Taguig, Metro ManilaTerm: Full Time - On siteEarn up to 40k monthly (depending on your skills) + allowancesAbout the Role• Analytical and problem-solving skills with attention to detail.• Strong communication and stakeholder management abilities.• Knowledge of operational risk frameworks (RCSA, KRI, Incident...
-
Security Officer/ Security Guard Openings
2 days ago
Taguig, National Capital Region, Philippines Private Advertiser Full timeSecurity Officer/ Security Guard Openings - Taguig City, Metro ManilaTaguig City, Metro Manila - Job Duties and Tasks for Security Officer/ Security Guard· Customer Service - While their primary role is to ensure security, guards also serve as a point of contact for visitors and employees, providing directions, answering questions, and assisting with...
-
Consultant - Risk Consulting
4 days ago
Taguig, National Capital Region, Philippines Marsh Full timeWe are seeking a talented individual to join our Marsh Advisory team at Marsh Philippines. This role will be based in Taguig City. This is a hybrid role which is mostly output based, requires frequent travel and site visits.We are looking for someone who can deliver tailored advice and solutions to support client's risk management decisions and overall...
-
Third-Party Risk
2 weeks ago
Taguig, National Capital Region, Philippines Denova Consulting Full timeWe are seeking a skilled Third-Party Risk & Compliance Specialist to join us here in Denova as part of our exclusive talent poolWe are looking for people who can work mid-shift or night shift, depending on client's request.This role is open exclusively to candidates residing in the Philippines.Key responsibilities:Support the design, implementation and...
-
Senior Security Consultant
2 days ago
Taguig, National Capital Region, Philippines Theos Cyber Solutions Ltd. Full timeAbout TheosOur mission is to empower businesses to thrive in the new digital security age by helping define and execute strategies to achieve cyber resilience. Practical steps instead of silver bullets. We are a team of experts in key security domains, including Penetration Testing, Red Teaming, Managed Detection & Response, and Digital Forensics and...