Security Consulting and Risk Officer
4 days ago
Responsible for securing data, network, and applications in system development or system implementations. Perform threat modeling, business and technical process analysis, application security and architecture reviews to evaluate, identify vulnerabilities and enforce security controls in IT and application systems. Ensures coordination of penetration testing support and vulnerability validation scans of systems projects.
Key Responsibilities:
● Work closely with cross-functional teams - ITG Infrastructure team, ITG DevOps team, Developers, Solutions and Enterprise Architects, Technical Project Managers, Delivery Managers and Project Proponents.
● Helps to improve the security health of the application systems, information processing
facilities and connected services of the bank by:
● Providing security consulting services on information security related matters for on premise and cloud-based project implementations and deployments.
● Serves as project security technical point of contact for system development as it relates to automation, continuous integration/continuous deployment activities and products/services being developed and deployed across the full application development life cycle.
● Ensure enforcement of security requirements across all new application systems and API deployments.
● Performs threat modeling and business/technical process analysis to identify vulnerabilities/weaknesses on processes and technology implementations thru a documented analysis and assessment report.
● Standardize the technical, functional and administrative security requirements covering areas of application system, technical design and architecture.
● Ensures that the security requirements align with the business objective of the application systems to be implemented.
● Provides consulting on technical designs and solutions to address infrastructure security and application security related weaknesses.
● Collaborate with relevant stakeholders to implement security improvements.
● Collaborate with the appropriate subject matter expert in Security Architecture and Innovation Department in reviewing security architecture and addressing architecture concerns in a project.
● Ensures that source code reviews are performed and validated across all platforms and frameworks.
● Coordinates application vulnerability scanning and penetration testing remediation activities with ITG developers.
● Assist with vulnerability prioritization and provide guidance on resolution.
● Ensures that standard security requirements are kept updated.
● Maintains an expert knowledge in the field of Information Security and the related issues, systems, processes, products, and services. Stay current with best security practices.
● Collaborates with other ITG Servicing units and application teams to harden its operating systems and application systems to better protect user data when implemented.
● Proactively works with the Department Head in implementing programs for the continuous improvement of the bank's information security posture.
● Perform other information security governance, risk and compliance related duties and responsibilities as directed by the Department Head.
Requirements
Qualifications
● Graduate of any college degree in Computer Science or Information Security, or related technical field of expertise.
● General understanding of regulatory compliance and how it relates to application security and privacy.
● Certification training may include CISA, CISM, SANS GIAC, CISSP, PCI-DSS, etc.)
● Understanding of network and application security risks and how to address them.
● History of designing, developing, or customizing application systems is a plus.
● Extensive and deep technical knowledge/understanding of system development, typically ranging from front-end user interfaces all the way to the back-end systems of both on premise and cloud deployment.
● Working knowledge of on premise and cloud architectures.
● Strong familiarity with web protocols and web services, networking concepts and encryption.
● Understanding of Microsoft, Linux/Unix security architecture.
● Strong attention to detail, analytical, and problem-solving skills. Thinking logically and intuitively; strong learning agility with the ability to learn new processes/patterns
● Result-orientated in terms of disposition for corrective action and security remediation.
● Have good teamwork and collaboration skills, a good team player with the ability to lead.
● Good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.
● Possess excellent time management skills, thrive in a fast paced demanding environment
● Be a self-managed, self-starter with good organizational skills to include good follow-up skills
● Knowledge in using MS office tools such as PowerPoint, word, excel and project
-
Risk and Security Assessment Consultant
4 days ago
Makati City, National Capital Region, Philippines HRTX Full time ₱1,500,000 - ₱3,000,000 per yearConducts security and/or risk assessments in a fast-paced environment and provides timely, practical recommendations to mitigate identified risksPerforms security and/or risk assessments in alignment with industry standards (ISO 27001/2, NIST, CIS, PCI DSS, SWIFT CSP, CSA CCM), regulatory requirements (BSP circulars and others), and best practicesCarries out...
-
Operational Risk Manager
4 days ago
Makati City, National Capital Region, Philippines Security Bank Corporation Full time ₱1,200,000 - ₱2,400,000 per yearAbout the RoleAs an Operational Risk Manager, you are responsible for carrying out operational risk governance, oversight, consulting, and risk management activities as part of the Bank's Second Line of Defense. Supports the identification, assessment, mitigation, monitoring, and reporting of operational risks by the various businesses and functions within...
-
Security Officer/ Security Guard
6 days ago
Makati City, National Capital Region, Philippines Skyhawk Security Services, Inc. Full time ₱15,000 - ₱25,000 per yearTasks for Security Officer/ Security Guard - Makati City, Metro ManilaEnsure all guests sign in and out upon arrival and departureInform guests of any rules or regulations that must be followedRemove any trespassers or unwanted individuals from the propertyContact the appropriate authorities in case of a crime or accidentRegularly report to...
-
Credit Risk Officer
4 days ago
Makati City, National Capital Region, Philippines Private Advertiser Full time ₱900,000 - ₱1,200,000 per yearOversee adherence to applicable banking laws, rules and regulations, and internal policies and controls;Ensure that it is updated on all new regulations/laws affecting the Company, as disseminated by Compliance Group, and could consult the latter on new regulations to ensure its clear interpretation and application and further cascaded to all personnel...
-
Cyber Security Specialist(Risk)
4 days ago
Makati City, National Capital Region, Philippines Rockwell Land Corporation Full time ₱1,200,000 - ₱2,400,000 per yearJob Summary:The Cyber Security Risk Officer is responsible for identifying, assessing, mitigating, and monitoring cyber risks across the organization. This role ensures the company's digital assets, infrastructure, and data are protected from internal and external cyber threats. The officer collaborates with IT, legal, compliance, and business units to...
-
Security Training Officer
6 days ago
Makati City, National Capital Region, Philippines The 8 Group of Companies Full time ₱1,200,000 - ₱3,600,000 per yearThe Security Training Officer will be responsible to help us develop, deploy, maintain, and monitor compliance of the security awareness program. You will be working closely with the Different Teams, under the supervision of the Chief Information Security Officer.Responsibilities:Reduce risk to our organization by ensuring all employees, staff and...
-
IT Risk
4 days ago
Makati City, National Capital Region, Philippines HRTX Full time ₱1,200,000 - ₱2,400,000 per yearJob Description:Conduct security and risk assessments, providing practical recommendations for risk mitigationEnsure assessments align with industry standards (ISO, NIST, CIS, PCIDSS, SWIFT CSP, CSA CCM) and regulatory requirements (e.g., BSP circulars)Perform cybersecurity and IT maturity assessmentsLead and participate in discovery workshops with...
-
Remote Security Consultant
6 days ago
Makati City, National Capital Region, Philippines Emapta Full time ₱3,000,000 - ₱4,500,000 per yearBuild Compliance Frameworks That Protect Worldwide Systems Hack your way into a global career without leaving your home. Dive into compliance mazes, decrypt complex security challenges, and fortify digital infrastructures alongside international experts. Every project you touch strengthens systems worldwide, sharpens your skills, and propels your...
-
Security Risk Management Specialist
6 days ago
Makati City, National Capital Region, Philippines Canonical - Jobs Full time ₱900,000 - ₱1,200,000 per yearIn security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To support...
-
Security Officer/ Security Guard
6 days ago
Mandaluyong City, National Capital Region, Philippines Skyhawk Security Services, Inc. Full time ₱15,000 - ₱30,000 per yearTasks for Security Officer/ Security Guard - Mandaluyong City, Metro ManilaPatrol assigned areas on foot or by vehicle to monitor for suspicious activityMonitor surveillance systems and control access to facilitiesRespond promptly to alarms and investigate disturbancesEnforce company policies, rules, and regulationsWrite accurate daily activity reports and...