27 Cism jobs in the Philippines
Information Security Auditor
Posted 4 days ago
Job Viewed
Job Description
**Work with Us. Change the World.**
At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the world's most complex challenges and build legacies for future generations.
There has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world.
We're one global team driven by our common purpose to deliver a better world. Join us.
**Job Description**
**Job Brief**
The primary function is to perform advisory and assurance projects of Audit Services Group (ASG) focused on IT, information security and data privacy risks. ASG is responsible for evaluating the adequacy and effectiveness of the company's systems of internal controls that guide company activities toward accomplishing key business objectives.
**Duties and Responsibilities**
+ Participate in planning, scoping and execution of risk-based IT, information security, and data privacy assurance and advisory projects in accordance with the Institute of Internal Auditors (IIA) and ASG standards
+ Perform test of design and operating effectiveness of controls
+ Effectively communicate audit results to management
+ Work with stakeholders to develop actions plans that address root cause of findings
+ Anticipate the impact of new technologies and strategic initiatives of the Company on its information security and privacy risk profile
+ Demonstrate up-to-date knowledge in information security and privacy and apply this to the development, execution and improvement of audit programs and recommendations
+ Develop and maintain productive working relationships with stakeholders, while maintaining independence and objectivity.
+ Contribute to various department initiatives to streamline processes, improve stakeholder experience, and increase productivity.
+ Contribute specialized expertise to different assigned projects and may provide key updates to Project Lead and Manager.
**Qualifications**
**Minimum Requirements**
+ Bachelor's degree in management information systems, computer science, accounting, finance, or other IT related fields is required
+ 2-4 years of IT auditing, technology, information security, privacy or other relevant work experience is required
+ Must have strong verbal and written communication skills; fluency in English is required
+ Knowledge of auditing cloud services, encryption technology, mobile technology, application security, software development methodologies, and common security frameworks preferred
+ Ability to travel up to 30% including international travel (valid passport required)
+ Professional certifications (e.g., CIA, CISA, CISSP) are preferred
**Additional Information**
Shift schedule: Morning shift (9AM to 6PM)
**About AECOM**
AECOM is proud to offer comprehensive benefits to meet the diverse needs of our employees. Depending on your employment status, AECOM benefits may include medical, dental, vision, life, AD&D, disability benefits, paid time off, leaves of absences, voluntary benefits, perks, flexible work options, well-being resources, employee assistance program, business travel insurance, service recognition awards, retirement savings plan, and employee stock purchase plan.
AECOM is the global infrastructure leader, committed to delivering a better world. As a trusted professional services firm powered by deep technical abilities, we solve our clients' complex challenges in water, environment, energy, transportation and buildings. Our teams partner with public- and private-sector clients to create innovative, sustainable and resilient solutions throughout the project lifecycle - from advisory, planning, design and engineering to program and construction management. AECOM is a Fortune 500 firm that had revenue of $16.1 billion in fiscal year 2024. Learn more at aecom.com.
**What makes AECOM a great place to work**
You will be part of a global team that champions your growth and career ambitions. Work on groundbreaking projects - both in your local community and on a global scale - that are transforming our industry and shaping the future. With cutting-edge technology and a network of experts, you'll have the resources to make a real impact. Our award-winning training and development programs are designed to expand your technical expertise and leadership skills, helping you build the career you've always envisioned. Here, you'll find a welcoming workplace built on respect, collaboration and community - where you have the freedom to grow in a world of opportunity.
As an Equal Opportunity Employer, we believe in your potential and are here to help you achieve it. All your information will be kept confidential according to EEO guidelines.
**ReqID:** J10134928
**Business Line:** Geography OH
**Business Group:** DCS
**Strategic Business Unit:** GBS
**Career Area:** Finance
**Work Location Model:** Hybrid
**Legal Entity:** AECOM Global Business Services - Philippines ROHQ
Information Security Architect (Hybrid)
Posted 7 days ago
Job Viewed
Job Description
As a Security Architect, you will engage across various domains within information security, focusing on: br>Evaluating and auditing existing security controls and solutions.
Designing and implementing new security measures.
Providing expert counsel within the department and beyond.
Assisting in the design and optimization of our SIEM/MDR solutions.
Conducting risk assessments for infrastructure, applications, and vendors.
Qualifications:
Bachelor's degree in any field; degrees in Information Security, Computer Science, or Software Engineering preferred but not mandatory.
Certifications such as Azure Architect, Azure Security, OSCP, OSEP, CISSP, Security+, ISO 27001, CISM, or CRISC are advantageous but not required.
Excellent English communication skills.
Knowledge in areas such as:
Risk Management
Third-Party Risk Management
Control Management
Security Frameworks (ISO 27001/27002/27005, NIST 800-53, NIST CSF)
Policy and Procedure Development
Infrastructure and Cloud Security (Azure)
MDR/SIEM/Log Analytics
Incident Response
Vulnerability and Penetration Testing
Identity and Access Management (IAM)
Technical Security and Risk Assessments
Disaster Recovery Planning
Willingness to engage with the CISO on professional matters.
Information Security Analyst II

Posted 20 days ago
Job Viewed
Job Description
To manage all RX security assessments and play a key part in ensuring RX's security compliance optimization. Monitor assessments while ensuring that Reed Exhibitions internal systems are compliant with RELX and industry standards. Proactively manage the third-party risk assessments, compliance evidence gathering of their IT services, infrastructure, applications and relevant services against their Security policies and related frameworks. Training and development will be provided in all areas of the role as required.
Key Responsibilities:
Security Assessment Management
+ Serve as an advanced technical advisor for third-party assessments, providing detailed security insights and solutions.
+ Perform in-depth security reviews and risk assessments for new and existing third-party vendors, ensuring compliance with organizational and regulatory requirements.
+ Demonstrate advanced knowledge in RELX security compliance policies and procedures.
+ Stay current with updates and developments in security standards such as OWASP Top 10, ISO27001, and SOC 2, and ensure their proper implementation across the organization.
+ Develop and deliver training and awareness on security policies and standards to business units.
+ Gain in-depth knowledge of the organization's major infrastructure security controls, ensuring they align with RELX Policies and Standards, industry best practices, and regulatory requirements.
+ Coordinate with technology/service owners and business owners to conduct annual security audits, vulnerability assessments, and penetration tests where applicable.
+ Work collaboratively within all business areas and key stakeholders to ensure the review and approach of all security governance, risk, and compliance scope is appropriate and proactive.
+ Ensure continuous monitoring and reporting of compliance and risk status against NIST2.0, RELX Framework, ISO27001, SOC2, PCI DSS, regional and global regulations, and all other relevant standards.
+ Support internal and external audits by providing detailed documentation and evidence of security controls and practices.
+ Perform RX Business Unit and Third-Party security audits according to the CISO office strategic plan and produce detailed documentation and evidence against security controls and practices tested.
+ Act as a point of escalation for security-related incidents, providing advanced security support and guidance to Level I Analysts and other team members.
+ Provide regular updates and at least monthly metric reports to senior management on security compliance and risk posture.
+ Escalation of high impact security issues to Security Compliance Manager.
Ideal candidate profile:
Technical Skills:
+ Bachelor's Degree holder.
+ Background in IT, compliance, and/or information security.
+ Ability to work across all levels of seniority within business teams to drive a working partnership.
+ Strong analytical and critical thinking skills.
+ Understanding of industry standards for IT security (e.g., ISO27001/2, SOC 2, PCI DSS).
+ Basic understanding of IT security applications (e.g., firewalls, intrusion detection, virus protection).
+ Understanding of IT security testing and vulnerability management, and Threat Modeling.
+ Understanding in Cloud Environment (e.g., AWS, Azure or GCP)
+ Understanding of Service Level Management.
+ Desired understanding of OneTrust portal or Similar.
+ With CompTIA Security+ or Similar or Higher.
Personal Skills:
+ Ability to work across all levels of seniority within the organization and suppliers to drive a working partnership.
+ Good communication skills at all levels, both oral and written.
+ Good interpersonal skills.
+ Ability to produce effective influence and persuasive arguments in support of security assessment process goals.
+ Highly driven and self-motivated individuals.
+ Skilled in project management and able to work independently in a fast-paced environment.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1- .
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here .
Please read our Candidate Privacy Policy .
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:
EEO Know Your Rights .
RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.
Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.
Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.
Chief Information Security Officer (CISO)
Posted 15 days ago
Job Viewed
Job Description
Network Security Manager (47312) - Makati
Posted 21 days ago
Job Viewed
Job Description
- Bachelor’s degree in: Information Technology, Computer Science, or related fields. br>- At least 5 years of experience in IT networking and cybersecurity.
- At least 5 years in a managerial role handling security and network teams.
- Proficiency in Japanese (at least JLPT N3) and English.
- Strong knowledge of firewalls, penetration testing, and security protocols.
- Proficiency in MS Office, Google Suites, and IT security tools.
-Certifications (Preferred but not required):
*CompTIA Security+ < r>*CISSP (Certified Information Systems Security Professional) < r>*CISM (Certified Information Security Manager) < r>*CCNP Security (Cisco) < r>*Fortinet NSE < r>*CCNA (Cisco Certified Network Associate) < r>*Juniper JNCIA-Junos < r>
Responsibilities:
Cybersecurity Leadership:
・Oversee cybersecurity for Asia & Oceania branches. < r>・Analyze and address vulnerabilities in IT infrastructure and systems. < r>・Develop and implement security policies for IT, infrastructure monitoring, incident response, and penetration testing. < r>
Network Security & Risk Management:
・Ensure robust firewall and security measures to prevent cyber threats. < r>・Implement change management and incident response procedures. < r>・Propose strategies for improving IT security across the company. < r>
Compliance & System Integrity:
・Ensure compliance with industry standards and best practices. < r>・Regularly test and update security frameworks to mitigate risks. < r>・Collaborate with IT teams and stakeholders to enhance security measures.
Assistant Security Manager - Conrad Manila

Posted 25 days ago
Job Viewed
Job Description
**What will I be doing?**
As an Assistant Security Manager, you will be responsible for directing and coordinating the activities of security personnel, work with Department Heads to confirm all staff understands security procedures, and organising patrolling of the property to deliver a safe Guest and Member experience. An Assistant Security Manager will also be required to ensure that hotel is in compliance with all local safety regulations and is conversant with hotel emergency procedures. Specifically, you will be responsible for performing the following tasks to the highest standards:
+ Maintain good communication and work relationships in all areas of the hotel
+ Liaise with government and law enforcement agencies as necessary
+ Coordinate additional personnel for Conference and Banqueting functions
+ Organise patrolling of all boundary areas, bedrooms, offices, storage areas, public areas, and function rooms
+ Assist the hotel in complying with Local Fire Safety Legislation
+ Assist the hotel with Local Safety Legislation to ensure compliance of the security department
+ Knowledge of the codes of practice for P.A.C.E.
+ Ensure tours are carried out for the purpose of fire prevention, safe means of escape, and security
+ Inquire as necessary into and report upon any thefts within the hotel using your discretion in connection with any of these matters that you deem should be reported to the police
+ Direct and coordinate the activities of all security personnel, engage in the implementation of safety and security procedures for the department, and provide assistance and advice to other departments in relation to security
+ Prepare incident reports and ensure all allegations are properly followed up
+ Liaise with Departmental Heads to ensure hotel staff is aware of their security responsibilities
+ Plan, deliver and facilitate regular staff awareness training
+ Be fully conversant of company terrorist procedures and convey to staff
+ Be fully conversant with hotel Fire and Emergency procedures
+ Responsible for management of key control within all departments
**What are we looking for?**
An Assistant Security Manager serving Hilton brands is always working on behalf of our Guests and working with other Team Members. To successfully fill this role, you should maintain the attitude, behaviours, skills, and values that follow:
+ Organised and systematic approach to problem solving
+ Security industry experience in supervisory capacity
+ SIA trained and licensed
+ Ability to listen and respond to demanding guest needs
+ Good leadership, interpersonal and communication skills
+ Accountable and resilient
+ Committed to delivering high levels of customer service
+ Ability to work under pressure
+ Flexibility to respond to a range of different work situations
+ Good grooming standards
It would be advantageous in this position for you to demonstrate the following capabilities and distinctions:
+ Previous experience in same or similar role
+ First Aid
+ Fire fighting qualification
+ IT proficiency
**What will it be like to work for Hilton?**
Hilton is the leading global hospitality company, spanning the lodging sector from luxurious full-service hotels and resorts to extended-stay suites and mid-priced hotels. For nearly a century, Hilton has offered business and leisure travelers the finest in accommodations, service, amenities and value. Hilton is dedicated to continuing its tradition of providing exceptional guest experiences across its global brands ( . Our vision "to fill the earth with the light and warmth of hospitality" unites us as a team to create remarkable hospitality experiences around the world every day. And, our amazing Team Members are at the heart of it all!
**Job:** _Security and Loss Prevention_
**Title:** _Assistant Security Manager - Conrad Manila_
**Location:** _null_
**Requisition ID:** _HOT0BR5S_
**EOE/AA/Disabled/Veterans**
Japanese Network Security Manager (47312) - Makati
Posted 21 days ago
Job Viewed
Job Description
- Bachelor’s degree in: Information Technology, Computer Science, or related fields. br>- At least 5 years of experience in IT networking and cybersecurity.
- At least 5 years in a managerial role handling security and network teams.
- Proficiency in Japanese (at least JLPT N3) and English.
- Strong knowledge of firewalls, penetration testing, and security protocols.
- Proficiency in MS Office, Google Suites, and IT security tools.
-Certifications (Preferred but not required):
*CompTIA Security+ < r>*CISSP (Certified Information Systems Security Professional) < r>*CISM (Certified Information Security Manager) < r>*CCNP Security (Cisco) < r>*Fortinet NSE < r>*CCNA (Cisco Certified Network Associate) < r>*Juniper JNCIA-Junos < r>
Responsibilities:
Cybersecurity Leadership:
・Oversee cybersecurity for Asia & Oceania branches. < r>・Analyze and address vulnerabilities in IT infrastructure and systems. < r>・Develop and implement security policies for IT, infrastructure monitoring, incident response, and penetration testing. < r>
Network Security & Risk Management:
・Ensure robust firewall and security measures to prevent cyber threats. < r>・Implement change management and incident response procedures. < r>・Propose strategies for improving IT security across the company. < r>
Compliance & System Integrity:
・Ensure compliance with industry standards and best practices. < r>・Regularly test and update security frameworks to mitigate risks. < r>・Collaborate with IT teams and stakeholders to enhance security measures.
Be The First To Know
About the latest Cism Jobs in Philippines !
MIS Manager (Management Information Systems Manager)
Posted 21 days ago
Job Viewed
Job Description
Job summary: br>Oversees the development, implementation, and maintenance of a company's information systems to support business operations and strategic decision-making. They manage data processing systems, ensure data integrity and security, and provide technical support to users.
Key Responsibilities:
System Management:
Overseeing the installation, configuration, and maintenance of hardware and software systems, including databases and networks.
Data Management:
Ensuring data accuracy, consistency, and security across all systems, including implementing data management policies and procedures.
Reporting and Analysis:
Developing and generating reports, dashboards, and visualizations to support business intelligence and decision-making.
IT Support:
Providing technical support and training to staff on MIS-related functions and tools.
Strategic Planning:
Contributing to the development and implementation of IT strategies aligned with business goals.
Security and Compliance:
Implementing and maintaining security protocols to protect sensitive data and ensure compliance with relevant regulations.
Vendor Management:
Negotiating and managing contracts with vendors for hardware, software, and other IT services.
Team Leadership:
Managing and mentoring a team of IT professionals, providing guidance and support.
Budget Management:
Developing and managing the IT department's budget.
Staying Updated:
Keeping abreast of new technologies and recommending their adoption when appropriate.
Job qualifications:
Educational Background:
Typically requires a bachelor's degree in Information Technology, Computer Science, or a related field, with 5+ years of experience in IT management or a similar role
Technical Skills:
Strong understanding of MIS infrastructure, database management, data analysis, and cybersecurity.
Management Skills:
Proven ability to manage and motivate a team, strong project management skills, and experience in strategic planning.
Communication Skills:
Excellent communication and interpersonal skills, with the ability to effectively communicate technical information to both technical and non-technical audiences.
Problem-Solving Skills:
Strong analytical and problem-solving skills, with the ability to troubleshoot issues and implement effective solutions.
Japanese Bilingual Network Security Manager (47312) - Makati
Posted 5 days ago
Job Viewed
Job Description
br>Required Experience:
- Bachelor’s degree in: Information Technology, Computer Science, or related fields. < r>- At least 5 years of experience in IT networking and cybersecurity.
- At least 5 years in a managerial role handling security and network teams.
- Proficiency in Japanese (at least JLPT N3 level) and English.
- Strong knowledge of firewalls, penetration testing, and security protocols.
- Proficiency in MS Office, Google Suite, and IT security tools.
+ Security Certifications (Preferred but not required):
*CompTIA Security+ < r>*CISSP (Certified Information Systems Security Professional) < r>*CISM (Certified Information Security Manager) < r>*CCNP Security (Cisco) < r>*Fortinet NSE < r>+Network Certifications (Preferred but not required):
*CCNA (Cisco Certified Network Associate) < r>*Juniper JNCIA-Junos < r>
Responsibilities:
Cybersecurity Leadership:
・Oversee cybersecurity for Asia & Oceania branches. < r>・Analyze and address vulnerabilities in IT infrastructure and systems. < r>・Develop and implement security policies for IT, infrastructure monitoring, incident response, and penetration testing. < r>
Network Security & Risk Management:
・Ensure robust firewall and security measures to prevent cyber threats. < r>・Implement change management and incident response procedures. < r>・Propose strategies for improving IT security across the company. < r>
Compliance & System Integrity:
・Ensure compliance with industry standards and best practices. < r>・Regularly test and update security frameworks to mitigate risks. < r>・Collaborate with IT teams and stakeholders to enhance security measures.
Cyber Security Assistant Manager
Posted 17 days ago
Job Viewed
Job Description
Pasay | Hybrid | Mid Shift br>
Technical Skills
-- Good understanding of ISO 27001 and/or CompTIA
-- An industry-recognized certification like ITIL / ITSM is an advantage
-- Understanding of Project Management methodology
Process Specific Skills
-- Ability to interface and communicate at all levels within EXL and Client organizations
-- Understanding of Enterprise Business Processes, Information Security and IT Process, Service Delivery is vital
-- Working knowledge of MS Office
Soft Skills
-- Good presentation and interpersonal skills
-- Excellent problem-solving skills in a cross-functional environment
-- Client stakeholder management
-- Strong verbal and written communication skills
-- Strong customer service orientation and ability to connect with global customers and work with global teams
-- Good listening and consultative skills
Responsibilities
Essential Functions:
-- Cyber Team – Facilitates activities of Cyber Exemption Request, Client Business Security and acts as Cyber representative for Change Approval Board < r>-- Liaise with Business to understand Cyber Security, Privacy, and BCM requirements and effectively engage, communicate, and assign requests to the corresponding internal teams
-- Business Value Creation – responsible for identifying, implementing, and reviewing service catalog improvement initiatives. Drives productivity, efficiency, and improvements in service catalog operations < r>-- Promote awareness, adherence, and compliance with Company and Client’s Cyber Security, Privacy, and BCM policies and standards < r>
Qualifications
-- Graduate, preferably in Engineering or Information Technology
-- Industry-recognized certifications like ISO 27001, CompTIA, ITIL/ITSM, PMP are preferred
-- Minimum 1–3 years of experience managing Information Security service delivery < r>-- Willingness to work in a 24 x 7 environment