IT.Junior Information System Security Officer
4 days ago
Makati, Metro Manila, Philippines
The Citco Group Limited
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
By continuing, you agree to our Terms & Privacy Policy.
IT Security
- Information Systems Security Office Team (‘ISSO Team’) is a group-wide resource, which covers all the divisions within the Citco Group of companies as defined on www.citco.com. The ISSO Team strategy is to uphold, maintain and continuously improve the Role Based Access Group (RBAG) framework within Citco’s User Access Management process. The ISSO Team has resources based in Amsterdam (The Netherlands), Manila (The Philippines), Hyderabad (India) and Toronto (Canada). The Junior Information Systems Security Officer (Junior ISSO) will support access governance for production applications under the Role Based Access Group (RBAG) framework which is within Citco’s User Access Management process. The Junior ISSO will assist with access reviews, onboarding/offboarding of applications to Citco’s Intake/Outtake/RBAG process, monitoring production application access, and remediation activities while operating in a second-line, check and-challenge capacity.
• Work within the ISSO Team for providing an efficient and effective method to manage information security risk, improve the effectiveness of information security and user access control to ensure the organization’s information and information systems are protected from unauthorized access, use and disclosure. This includes: o Partner with the business and other group functions to develop and execute the User Access Management Framework. o Conduct monthly monitoring reviews in accordance with the monitoring plans and report results to relevant stakeholders.
• Engage with Business and Support Function Management across the Citco Divisions to further improve the control environment in a collaborative manner.
• Complete the tasks assigned by ISSO Management and effectively achieve the established goals and objectives.
• Collaborate with IT Security team members to effectively and efficiently accomplish departmental goals and objectives.
• Reports to ISSO Management and cultivates and maintains positive, professional working relationships with ISSO staff.
• Supports access governance processes by reviewing access requests and approvals for production applications in accordance with Citco’s User Access Management and Role-Based Access Group (RBAG) processes.
• Assists with client access certification campaigns and reviews Active Directory (AD) security groups to ensure appropriate access and compliance with established security policies and procedures.
• Monitors application access records, identifies potential anomalies or irregularities, and escalates issues to the ISSO Management for investigation and resolution.
• Validates access provisioning activities against approved access requests and collaborates with provisioning teams to investigate and resolve discrepancies.
• Maintains accurate and up-to-date documentation of access controls, remediation activities, and related security processes.
• Supports audit and compliance requests by providing accurate documentation, access records, and relevant information in a timely manner.
• Participate in the onboarding of new applications to Citco’s User Access Management and Role-Based Access Group (RBAG) processes, ensuring alignment with established access control and security requirements.
• Attends meetings with business and technical stakeholders, documents action items, and tracks assigned owners to support timely completion.
• Completes assigned ISSO tasks within agreed timelines and in line with function objectives.
• Monitors ACL control effectiveness and work with the team to improve application match rates 100%.
• Identifies root causes of control breaks and supports preventive actions.
• Maintains expertise through continuous learning and training to stay abreast of emerging and proposed developments in Information Security, Risk Management, and Auditing, leveraging insights from various industryorganizations and assessing their potential impact on the company. Requirements
Education:
• The candidate should possess at least a relevant bachelor’s degree. Optional Qualification(s)/Certification(s):
• CIA, CISA, CRISC, or other relevant IT/Risk/Audit/IT Security certifications. Professional
Experience:
• One up to three years of experience in progressive Risk Management, Internal Controls, Internal Audit, or IT Audit function within a financial institution or Big 4 audit firm, ideally with experience in IT and/or IT Security functions. Computer Application(s):
• Hands-on experience with automated internal audit applications and tools, such as ACL Analytics and SQL, is an advantage. Proficiency in Microsoft Word, Excel, PowerPoint, and Visio is also expected. Language(s): Excellent written and spoken English is required. Key Competencies: Client Focus. Effective Communication. Sound Decision-Making. Results-Oriented Personal Characteristics: Confident and articulate, with the ability to communicate clearly, concisely, and effectively, both oral and written. Strong attention to detail, with a commitment to accuracy and quality. Diplomatic and professional, with the tenacity and persistence required to achieve objectives and complete tasks. A strong team player who works effectively within the ISSO function and collaborates successfully with colleagues and stakeholders to deliver a high quality service. Creative, innovative, and open to new ideas and approaches. Willing to take on responsibility and work independently with minimal supervision.
Working Hours
/Conditions: This role requires flexibility in providing cross-regional support. Prepared to partake on a shifting schedule -
- APAC, EMEA and Americas. Occasional public holidays or weekend support may be required. Note: This
job description
is not intended to be all-inclusive. Employees may perform other related duties to meet the ongoing needs of the organisation. Qualifications Your Benefits Your well-being is of paramount importance to us, and central to our success. We provide a range of benefits, training and education support, and flexible working arrangements to help you achieve success in your career while balancing personal needs. Ask us about specific benefits in your location. We embrace diversity, prioritizing the hiring of people from diverse backgrounds. Our inclusive culture is a source of pride and strength, fostering innovation and mutual respect. Citco welcomes and encourages applications from people with disabilities. Accommodations are available upon request for candidates taking part in all aspects of the selection.
- Information Systems Security Office Team (‘ISSO Team’) is a group-wide resource, which covers all the divisions within the Citco Group of companies as defined on www.citco.com. The ISSO Team strategy is to uphold, maintain and continuously improve the Role Based Access Group (RBAG) framework within Citco’s User Access Management process. The ISSO Team has resources based in Amsterdam (The Netherlands), Manila (The Philippines), Hyderabad (India) and Toronto (Canada). The Junior Information Systems Security Officer (Junior ISSO) will support access governance for production applications under the Role Based Access Group (RBAG) framework which is within Citco’s User Access Management process. The Junior ISSO will assist with access reviews, onboarding/offboarding of applications to Citco’s Intake/Outtake/RBAG process, monitoring production application access, and remediation activities while operating in a second-line, check and-challenge capacity.
• Work within the ISSO Team for providing an efficient and effective method to manage information security risk, improve the effectiveness of information security and user access control to ensure the organization’s information and information systems are protected from unauthorized access, use and disclosure. This includes: o Partner with the business and other group functions to develop and execute the User Access Management Framework. o Conduct monthly monitoring reviews in accordance with the monitoring plans and report results to relevant stakeholders.
• Engage with Business and Support Function Management across the Citco Divisions to further improve the control environment in a collaborative manner.
• Complete the tasks assigned by ISSO Management and effectively achieve the established goals and objectives.
• Collaborate with IT Security team members to effectively and efficiently accomplish departmental goals and objectives.
• Reports to ISSO Management and cultivates and maintains positive, professional working relationships with ISSO staff.
• Supports access governance processes by reviewing access requests and approvals for production applications in accordance with Citco’s User Access Management and Role-Based Access Group (RBAG) processes.
• Assists with client access certification campaigns and reviews Active Directory (AD) security groups to ensure appropriate access and compliance with established security policies and procedures.
• Monitors application access records, identifies potential anomalies or irregularities, and escalates issues to the ISSO Management for investigation and resolution.
• Validates access provisioning activities against approved access requests and collaborates with provisioning teams to investigate and resolve discrepancies.
• Maintains accurate and up-to-date documentation of access controls, remediation activities, and related security processes.
• Supports audit and compliance requests by providing accurate documentation, access records, and relevant information in a timely manner.
• Participate in the onboarding of new applications to Citco’s User Access Management and Role-Based Access Group (RBAG) processes, ensuring alignment with established access control and security requirements.
• Attends meetings with business and technical stakeholders, documents action items, and tracks assigned owners to support timely completion.
• Completes assigned ISSO tasks within agreed timelines and in line with function objectives.
• Monitors ACL control effectiveness and work with the team to improve application match rates 100%.
• Identifies root causes of control breaks and supports preventive actions.
• Maintains expertise through continuous learning and training to stay abreast of emerging and proposed developments in Information Security, Risk Management, and Auditing, leveraging insights from various industryorganizations and assessing their potential impact on the company. Requirements
Education:
• The candidate should possess at least a relevant bachelor’s degree. Optional Qualification(s)/Certification(s):
• CIA, CISA, CRISC, or other relevant IT/Risk/Audit/IT Security certifications. Professional
Experience:
• One up to three years of experience in progressive Risk Management, Internal Controls, Internal Audit, or IT Audit function within a financial institution or Big 4 audit firm, ideally with experience in IT and/or IT Security functions. Computer Application(s):
• Hands-on experience with automated internal audit applications and tools, such as ACL Analytics and SQL, is an advantage. Proficiency in Microsoft Word, Excel, PowerPoint, and Visio is also expected. Language(s): Excellent written and spoken English is required. Key Competencies: Client Focus. Effective Communication. Sound Decision-Making. Results-Oriented Personal Characteristics: Confident and articulate, with the ability to communicate clearly, concisely, and effectively, both oral and written. Strong attention to detail, with a commitment to accuracy and quality. Diplomatic and professional, with the tenacity and persistence required to achieve objectives and complete tasks. A strong team player who works effectively within the ISSO function and collaborates successfully with colleagues and stakeholders to deliver a high quality service. Creative, innovative, and open to new ideas and approaches. Willing to take on responsibility and work independently with minimal supervision.
Working Hours
/Conditions: This role requires flexibility in providing cross-regional support. Prepared to partake on a shifting schedule -
- APAC, EMEA and Americas. Occasional public holidays or weekend support may be required. Note: This
job description
is not intended to be all-inclusive. Employees may perform other related duties to meet the ongoing needs of the organisation. Qualifications Your Benefits Your well-being is of paramount importance to us, and central to our success. We provide a range of benefits, training and education support, and flexible working arrangements to help you achieve success in your career while balancing personal needs. Ask us about specific benefits in your location. We embrace diversity, prioritizing the hiring of people from diverse backgrounds. Our inclusive culture is a source of pride and strength, fostering innovation and mutual respect. Citco welcomes and encourages applications from people with disabilities. Accommodations are available upon request for candidates taking part in all aspects of the selection.