Information Security Analyst
1 day ago
As a Business Unit Security Officer (BUSO) within the Information Risk Management team under Global Wealth Asset Management (GWAM) Information Technology First Line of Defense, you will play a critical role in safeguarding the organization's IT environment. This role involves conducting risk assessments for new and existing applications, infrastructure, and platforms—both on premises and cloud-based. You will be responsible for identifying threats, evaluating their potential impact, validating appropriate protection measures, providing security advisory to stakeholders, and leading cross-functional collaboration to address complex information risk concerns.
Position Responsibilities:
- Perform information risk assessments in compliance with the global Information Risk Assessment methodology, policies, and standards.
- Ensure each completed information risk assessment is peer-reviewed and communicated to various stakeholders.
- Develop and enhance security requirements for DevOps environments and collaborate with developers, engineers, and support teams to help implement those requirements in applications, CI/CD pipelines, container workloads, etc.
- Provide training and advise key stakeholders on requirements, processes, standards, and best practices around information security and risk management.
- Respond to audits, second line of defense review, regulatory reviews, risk and control self-assessments.
- Lead and facilitate cross-functional discussions to resolve information risk concerns, ensuring alignment with company standards across technology, business, and risk stakeholders.
- Provide ad-hoc support for ServiceNow (SNOW) request handling, including reviewing and approving firewall and security group requests when required.
- Track and manage identified information risk issues and associated corrective action plans (CAPs), ensuring timely resolution and closure in alignment with governance requirements.
- Candidate must be flexible to work in the morning or in a hybrid environment, as required.
Required Qualifications:
Experience in application security including secure software assessment tools like SAST, DAST, SCA, IAST, RASP, etc. or similar areas.
IT risk management experience in areas such as vendor risk management, project risk management, IT audit, or IT controls assessment.
- Strong Knowledge of security controls, frameworks, regulatory requirements and standards, concepts (e.g. ISO 270XX, MAS, etc.), and industry best practices (e.g. OWASP, CSA, CIS).
- Post-secondary education in information security, computer science, information technology, software engineering, or equivalent professional education.
- Strong communication, presentation, time management, and facilitation skills to all levels and audiences.
- Knowledgeable in AKS, Azure, AI Foundry and GitHub
- Exceptional attention to detail, ensuring accuracy and completeness in risk documentation and issue tracking.
- Strong interpersonal and collaboration skills to effectively engage with diverse teams and stakeholders
- Problem solving, analytical, and innovative mindset.
- A team player who can also work independently.
- Amenable to work on a day/mid shift schedule
- Amenable to work on a hybrid set-up (3x a week onsite)
Preferred Qualifications:
- Experience with container orchestration, infrastructure as code, scripting and coding languages (e.g. Terraform, Bash, PowerShell, Python) is an asset.
- Relevant professional certifications (e.g. CISSP, CCSP, CRISC, etc.) is an asset.
- Understanding of Generative AI (GenAI) concepts and practical applications.
- Experience using tools like Power Automate and Copilot Studio to develop solutions that enhance work efficiency and automate tasks.
When you join our team:
- We'll empower you to learn and grow the career you want.
- We'll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
- As part of our global team, we'll support you in shaping the future you want to see.
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit .
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact .
Working Arrangement
Hybrid
-
Information Security Analyst
2 weeks ago
Manila, National Capital Region, Philippines SCALABLE OS CORP. Full time ₱1,200,000 - ₱2,400,000 per yearSUMMARYWe are looking for Information Security Analyst, who is responsible for establishing and maintaining a corporate-wide information security management program to ensure that information assets are adequately protected. This position is responsible for identifying, evaluating, and reporting on information security risks in a manner that meets compliance...
-
Senior Information Security Analyst
7 days ago
Manila, National Capital Region, Philippines Mega Prime Foods Inc. Full time ₱1,200,000 - ₱2,400,000 per yearJob Summary:We are seeking a dedicated and detail-oriented Junior Information Security Analyst to join our team and support our organization's digital transformation goals. This role is essential in safeguarding our organization's digital assets and ensuring the security framework is protected from cyber threats and potential attacks. The ideal candidate...
-
Manila, National Capital Region, Philippines Planit Full time ₱80,000 - ₱120,000 per yearDescriptionPlanit are world leaders in application testing and quality engineering. We provide solutions that support organisations to deliver high quality systems, applications, and IT architecture. Planit is now a proud NRI company and part of a global movement to deliver a sustainable and secure future through better Information Technology exchanges.Our...
-
L1 SOC Analyst
2 weeks ago
Manila, National Capital Region, Philippines Graybox Security Full time ₱300,000 - ₱600,000 per yearLocation: Remote / Anywhere in the PhilippinesEmployment Type: Full-Time | Entry-Level | Flexible Shifts (24x7 Coverage)Industry: Cybersecurity / Managed Security Operations Center (MSOC)About UsGraybox Security is a trusted information security, data privacy, and cybersecurity firm dedicated to protecting organizations from evolving digital threats. We...
-
Senior Security Analyst
5 days ago
Manila, National Capital Region, Philippines QBE Insurance Group Full time ₱60,000 - ₱120,000 per yearPrimary DetailsTime Type: Full timeWorker Type: EmployeeWe are seeking a highly skilled and motivated Senior Security Analyst to join our Global Security Operations Centre based in the Philippines. Reporting to the Global Security Operations Centre Lead, the Senior Security Analyst will be a key member of our rapidly growing Global team. This role is...
-
L1 Cyber Security Analyst
7 days ago
Manila, National Capital Region, Philippines SecureOps Full time ₱25,000 - ₱1,200,000 per yearSOC - Cyber Security Analyst L1The primary responsibilities of the Level 1 Cyber Security Analyst are to sort, filter, analyze, qualify and escalate various cyber-security alerts inside log aggregation tools (SIEM) such as ArcSight, Splunk, and QRadar. The Analyst is also responsible for incident follow-up, process suggestions, and basic automation. This...
-
Security Compliance Analyst
7 days ago
Manila, National Capital Region, Philippines OpsArmy Careers Full time ₱40,000 - ₱80,000 per yearJob SummaryWere hiring aSecurity Compliance Analystto help strengthen client trust and support our sales growth through clear, reliable security communication. Youll play a key role in maintaining compliance documentation, managing security questionnaires, and ensuring our responses to clients reflect the companys strong security posture.This role is ideal...
-
Security Operations Analyst
7 days ago
Manila, National Capital Region, Philippines Kroll Global Solutions Inc. Full time ₱1,200,000 - ₱2,400,000 per yearOur professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you'll discover a supportive...
-
Security Analyst, Technology
7 days ago
Manila, National Capital Region, Philippines Kroll Full time ₱1,200,000 - ₱2,400,000 per yearDescriptionOur professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you'll discover a...
-
Security Analyst, Technology
3 days ago
Manila, National Capital Region, Philippines Kroll Full time ₱900,000 - ₱1,200,000 per yearOur professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you'll discover a supportive...