Vulnerability Management Analyst

3 days ago


Makati City, National Capital Region, Philippines Chevron Full time ₱1,200,000 - ₱2,400,000 per year

Total Number of Openings

5

About Us

Chevron is a leading multinational energy company with operations in over 180 countries. Founded in 1879, Chevron has a rich history of innovation and growth, making significant contributions to the global energy landscape.

Chevron markets Caltex fuels, lubricants and other petroleum products in the Philippines. Our network of service stations, terminals and sales offices forms the backbone of our presence in the Philippines.

Chevron supports its operations in the Philippines and worldwide through two subsidiaries: Chevron Philippines Incorporated (CPI), which manages downstream operations and markets Caltex brand fuels, lubricants and petroleum products, and Chevron Holdings Incorporated (CHI), a global business services organization. Established in 1998, CHI provides business support services in finance and accounting, information technology, supply chain management, human resources, customer service and marketing. It serves Chevron affiliates around the world and has grown to be one of the leading global business services organizations in the Philippines. The company has received various recognition as one of the country's top employers and as a champion of diversity and inclusion in the workplace. 

At Chevron, we believe humanity can solve any challenge – including meeting the world's energy needs of today, while advancing a cleaner energy tomorrow.

About the Role

We have an exciting opportunity for a Vulnerability Management Analyst. This role will be based in 6750 Building, Makati City.

The Vulnerability Management Analyst will drive change within vulnerability management. Lead in defining processes and tool recommendations needed to identify vulnerabilities, tests Chevron's digital security defenses, analyzes malicious code, and leverages all authorized resources and analytic techniques to secure Chevron's environment. Support the Information Risk Strategy Management (IRSM) Vulnerability Management (VM) program reporting to the Vulnerability Management Team Lead.

Responsibilities include, but are not limited to, the following:

  • Manage the vulnerability remediation process to ensure weaknesses identified through vulnerability scanning and assessments / penetration tests along with any emergency concerns are assigned to owners and tracked to resolution.

  • Responsible for analyzing information/data collected from vulnerability assessments and scans; and in conjunction with the IRSM risk managers, helps recommend mitigations in the form of policies, standards, and controls as they apply to the major risk domains. This person will also support project initiatives to assess vulnerability of Chevron's IT assets.

  • Support project initiatives to assess vulnerabilities in Chevron's IT assets and perform validation testing of remediated vulnerabilities from business vulnerability assessments, as needed.

  • Foundational knowledge in cybersecurity and apply that knowledge toward remediation initiatives.

  • Foundational skills in cybersecurity toolsets including infrastructure and application scanning, phishing campaigns, cloud access security broker, and other cross functional security tools.

  • Engage technical resources and leaders across the enterprise to share results and gain commitment.

Technical

  • Demonstrated ability in vulnerability management or related field such as penetration testing, SOC, or threat intelligence.

  • Understanding of attacker mindset, exploitation, and how vulnerabilities are leveraged. 

  • Knowledge of Cybersecurity principles and various information security technologies (i.e., IDS/IPS, HIPS, DLP, firewalls, network engineering, database, etc.).

  • In-depth experience with cybersecurity concepts, vulnerability scanning tools, and other security techniques such as active/passive reconnaissance, vulnerability identification, exploitation, phishing, social engineering, and command and control techniques.

  • Broad understanding in one of the following information technology areas used to support and manage the business (i.e., web, networking, database, cloud, telephony, mobile, applications, etc.).

Domain Knowledge

  • Must understand IT systems (Operating Systems, databases, and applications).

  • Experience in one of the following areas: a system administrator, application developer, programmer familiarity with MS Windows or UNIX/Linux operating systems.

  • Strong desire to learn new tools and technologies highly motivated to apply that knowledge toward understanding and communicating the sources of vulnerabilities.

Communication

  • Candidates should demonstrate strong verbal, written and presentation skills, as well as an ability to communicate technical information to different audiences (management, non-technical, IT Professionals, PCN Professionals). Able to engage and interview stakeholders requesting vulnerability management services to capture key information needed to effectively understand, clearly articulate, and document remediation plans.

Chevron participates in E-Verify in certain locations as required by law.



  • Makati City, National Capital Region, Philippines Avaloq Full time ₱1,500,000 - ₱4,200,000 per year

    Founded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 12 countries, and more than 170 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers,...


  • Makati City, National Capital Region, Philippines myGwork - LGBTQ+ Business Community Full time $80,000 - $120,000 per year

    This job is with Avaloq, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.Company DescriptionFounded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 12 countries, and more than...

  • SOC Analyst

    3 days ago


    Makati City, National Capital Region, Philippines ALL ABOUT PEOPLE CONSULTING Full time ₱420,000 - ₱540,000 per year

    Junior SOC Analyst – Job DescriptionA Junior Security Operations Center (SOC) Analyst is responsible for monitoring, detecting, analyzing, and responding to cybersecurity incidents within an organization's IT environment. They work under the guidance of senior analysts to protect company systems and data from threats.Key ResponsibilitiesMonitoring and...


  • Makati City, National Capital Region, Philippines weSource Management Consultancy Firm Full time ₱100,000 - ₱200,000 per year

    We are looking for a IT Business Analyst for our bank client in MakatiSalary: up to 200kSet up: On siteA Business Analyst (BA) in the IT sector plays a crucial role in bridging the gap between technology and business objectives. Here's a typical job description for an IT Business Analyst:Job Summary:The IT Business Analyst is responsible for analyzing...


  • Quezon City, National Capital Region, Philippines J-K Network Manpower Services Full time

    Company Profile: A global business and technology transformation partner that helps firms accelerate their dual transition to a digital and sustainable future while making tangible difference for businesses and society.Position: Information Security AnalystIndustry: IT CompanyLocation: Quezon CitySchedule: Night Shift / ShiftingSalary: 60,000-120,000Work...

  • ty Analyst

    3 days ago


    Makati City, National Capital Region, Philippines The Citco Group Limited Full time ₱1,500,000 - ₱3,000,000 per year

    Position is responsible for working as team member to complete all aspects of application/network penetration test, risk assessment and other security activities as assigned to the Red Team. This position will involve working closely with development and projects teams to ensure that internal, secure development processes are adhered to and applications...

  • Business Analyst

    1 day ago


    Makati City, National Capital Region, Philippines weSource Management Consultancy Firm Full time ₱1,500,000 - ₱2,500,000 per year

    Role: Business AnalystIndustry: BankingLevel: Sr ManagerDirect Manager: Sr VPShift: Mon to FriSet Up: OnsiteLocation: Makati CitySalary: Open up to 170K monthly based on Experience and Current/Last Compensation PackageInterviews: Multiple Levels (Online and Face to Face)RESPONSIBILITIESResponsible for assisting the company's requirements and defining/shaping...

  • SOC Analyst

    1 day ago


    Quezon City, National Capital Region, Philippines Richard Fleischman & Associates Full time ₱800,000 - ₱1,200,000 per year

    Working shift - 2:00AM – 11:00 AM PHT  Mon-Friday As a member of the RFA Security Operations Center, a SOC Analyst monitors and analyzes the output from various security monitoring and scanning tools to detect malicious or anomalous activity on behalf of RFA clients. The SOC Analyst recommends actions per established procedures for the detection,...


  • Makati City, National Capital Region, Philippines Mizuho Full time

    Job Description:Provide support related to the implementation of various cybersecurity initiatives/projects;Liaise with Head Office & Asia Pacific Corporate Function Coordination Department (APCF) on matters related to Cybersecurity;Provide support in the conduct of annual Cyber Risk Assessment (CRA) & Vulnerability Assessment as required by Head...


  • Makati City, National Capital Region, Philippines myGwork - LGBTQ+ Business Community Full time ₱120,000 - ₱180,000 per year

    This job is with Avaloq, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.Company DescriptionFounded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 10 countries, and more than...