227 Cyber Risk jobs in the Philippines
Associate, Cyber Risk
Posted today
Job Viewed
Job Description
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you'll contribute to a supportive and collaborative work environment that empowers you to excel.
Kroll's Cyber Risk team works on over 2,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client's data, people, operations and reputation with innovative assessments, investigations, and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.
Clients count on us for quick and expert support in the event of and in preparation against a cyber incident; from incident response to risk assessments, and complex forensics to breach notification and ID theft remediation we help clients – of all sizes – respond with confidence.
At Kroll, your work will help deliver clarity to our clients' most complex governance, risk, and transparency challenges. Apply now to join One team, One Kroll.
Launch Your Cybersecurity Career with
Kroll Cyber Academy
Are you passionate about cybersecurity and eager to start your journey in this dynamic field? Kroll Cyber Academy (KCA) is looking for driven, enthusiastic individuals ready to become the next generation of cybersecurity professionals.
Why Join Kroll Cyber Academy?
At Kroll Cyber Academy, we're dedicated to providing a comprehensive training experience that will prepare you for a successful career in cybersecurity. This is more than just a job – it's a pathway to growth and professional development.
Join Our Waiting List:
Don't miss this exciting opportunity
Join our waiting list to be notified when a slot in the academy opens up. This will be your chance to step into a role perfectly suited to your skills and ambitions, leading to your growth in the cybersecurity industry with Kroll.
What We Offer:
- Extensive Training: Get trained in various cybersecurity roles such as First Line Support, Cyber SOC Analyst, Security Platform Administration, Technical Account Management, Service Operations, Cyber Project Management, Cyber Threat Intel, and Detection Engineering.
- Hands-On Experience: Work with a wide range of cutting-edge security tools and technologies.
- Personal Development: Benefit from our defined syllabi, designed to help you excel and promote within the company.
- Real-World Application: Learn how to apply your knowledge in a live enterprise environment.
- Supportive Environment: Join a team that values effective communication, understanding, and continuous learning.
What We're Looking For:
- Technical Proficiency: Basic knowledge of Windows OS and Linux.
- Communication Skills: Ability to articulate technical information clearly, both written and verbally.
- Commitment to Learning: Fast learners who are dedicated to personal and professional growth.
- Attention to Detail: Strong time management skills and an eye for detail.
Nice to Have:
- ITIL Service Desk Experience
- Cybersecurity Certification
- Background in Cybersecurity
- Understanding of Networking and Data Protection Laws
Associate, Cyber Risk
Posted today
Job Viewed
Job Description
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of
One team, One Kroll,
you'll contribute to a supportive and collaborative work environment that empowers you to excel.
Kroll's Cyber Risk team works on over 2,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client's data, people, operations and reputation with innovative assessments, investigations, and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.
Clients count on us for quick and expert support in the event of and in preparation against a cyber incident; from incident response to risk assessments, and complex forensics to breach notification and ID theft remediation we help clients – of all sizes – respond with confidence.
At Kroll, your work will help deliver clarity to our clients' most complex governance, risk, and transparency challenges. Apply now to join
One team, One Kroll.
Launch Your Cybersecurity Career with
Kroll Cyber Academy
Are you passionate about cybersecurity and eager to start your journey in this dynamic field? Kroll Cyber Academy (KCA) is looking for driven, enthusiastic individuals ready to become the next generation of cybersecurity professionals.
Why Join Kroll Cyber Academy?
At Kroll Cyber Academy, we're dedicated to providing a comprehensive training experience that will prepare you for a successful career in cybersecurity. This is more than just a job – it's a pathway to growth and professional development.
Join Our Waiting List
Don't miss this exciting opportunity
Join our waiting list to be notified when a slot in the academy opens up. This will be your chance to step into a role perfectly suited to your skills and ambitions, leading to your growth in the cybersecurity industry with Kroll.
What We Offer
- Extensive Training: Get trained in various cybersecurity roles such as First Line Support, Cyber SOC Analyst, Security Platform Administration, Technical Account Management, Service Operations, Cyber Project Management, Cyber Threat Intel, and Detection Engineering.
- Hands-On Experience: Work with a wide range of cutting-edge security tools and technologies.
- Personal Development: Benefit from our defined syllabi, designed to help you excel and promote within the company.
- Real-World Application: Learn how to apply your knowledge in a live enterprise environment.
- Supportive Environment: Join a team that values effective communication, understanding, and continuous learning.
What We're Looking For
- Technical Proficiency: Basic knowledge of Windows OS and Linux.
- Communication Skills: Ability to articulate technical information clearly, both written and verbally.
- Commitment to Learning: Fast learners who are dedicated to personal and professional growth.
- Attention to Detail: Strong time management skills and an eye for detail.
Nice To Have
- ITIL Service Desk Experience
- Cybersecurity Certification
- Background in Cybersecurity
- Understanding of Networking and Data Protection Laws
How To Apply
- Submit Your Resume and Cover Letter: Show us your passion for cybersecurity and any relevant experience you have.
- Take the Quiz: If your application fits our criteria, we will send you a quiz to assess your basic knowledge and skills.
- Interview: If you pass the quiz, you will be invited for an interview to discuss your fit and potential with KCA.
- Join the Waiting List: Successful candidates will be placed on a waiting list for the next available slot in the KCA.
Apply Now
Ready to take the next step? Submit your resume and a cover letter detailing your passion for cybersecurity and any relevant experience.
Contact Us
For more information or to apply, contact
Embark on a rewarding journey with Kroll Cyber Academy and transform your passion for cybersecurity into a successful career. We can't wait to welcome you to our team
About Kroll
Kroll is the world's premier provider of services and digital products related to governance, risk and transparency. We work with clients across diverse sectors in the areas of valuation, expert services, investigations, cyber security, corporate finance, restructuring, legal and business solutions, data analytics and regulatory compliance. Our firm has nearly 5,000 professionals in 30 countries and territories around the world. For more information, visit
Associate, Cyber Risk
Posted today
Job Viewed
Job Description
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you'll contribute to a supportive and collaborative work environment that empowers you to excel.
Kroll's Cyber Risk team works on over 2,000 cases a year, including some of the most complex and highest profile matters in the world. With experts based around the world, supported by ground-breaking technology, we help protect our client's data, people, operations and reputation with innovative assessments, investigations, and intelligence. We are the only company in the world with the expertise and resources to deliver global, end-to-end cyber risk management, supporting organizations through every step of their journey toward cyber resilience.
Clients count on us for quick and expert support in the event of and in preparation against a cyber incident; from incident response to risk assessments, and complex forensics to breach notification and ID theft remediation we help clients – of all sizes – respond with confidence.
At Kroll, your work will help deliver clarity to our clients' most complex governance, risk, and transparency challenges. Apply now to join One team, One Kroll.
The Kroll Cyber Academy is looking to bring in driven, inexperienced Cyber enthusiasts who have a want to further themselves and their career.
The applicant should be proficient in Windows OS as well as having an understanding of Linux.
Awareness of the following roles with a knowledge of at least one:
First Line Support
Cyber SOC Analyst
Security Platform Administration – i.e. SIEM or EDR
Technical Account Management
Service Operations – Workflow
Cyber Project Management
Must Have:
- Ability to articulate with a customer or team member written or verbally
- Ability to listen and understand
- Proven technical know how
- Ability to use knowledge and apply in enterprise environment
- Commitment to furthering themselves
- Fast Learning
- Ability to relate education to live application
- Excellent attention to detail
Excellent Time Management – adhering to SLA's
Nice to have:
- ITIL service desk experience
- Cyber Security Certification
- Security experience / background
- Solid understanding of networking and utilizing this knowledge in troubleshooting
- Understanding of data protection laws and policies
- Excellent communication and interpretation skills
- Excellent numerical and analytical skills
About Kroll
Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients' value? Your journey begins with Kroll.
Kroll is committed to equal opportunity and diversity, and recruits people based on merit.
In order to be considered for a position, you must formally apply via
LI-DNICyber Application Engineer – Risk Management
Posted today
Job Viewed
Job Description
Cyber Application Engineer – Risk Management
Location:
Makati City, Philippines
Work Setup:
Hybrid (2 Days Onsite / 3 Days WFH)
Schedule:
Dayshift (with U.S. Time Zone Overlaps for Collaboration)
Strategic Staffing Solutions (S3) is looking for a
Cyber Application Engineer – Risk Management
to join a high-performing DevOps team. This role focuses on supporting SaaS applications, as well as developing and maintaining internally built solutions that enable effective
IT risk identification, detection, management, and response
.
If you're a proactive problem-solver with strong system support and development skills, this is an excellent opportunity to grow in a collaborative, agile environment.
Key Responsibilities
- Provide
system support and troubleshooting
to resolve technical issues. - Collaborate with stakeholders and cross-functional teams to enhance system performance.
- Support
IT risk management processes
, ensuring safeguards and compliance are in place. - Develop and optimize solutions, delivering prioritized user stories in an agile environment.
- Communicate effectively with technical and business teams to align on requirements and deliverables.
- Stay updated with
industry trends and emerging technologies
to improve system effectiveness.
Requirements
- Bachelor's or Master's degree in
Information Technology, Computer Science, Engineering, or related STEM field
. - Experience with tools such as
ServiceNow, OneTrust, Microsoft Power Platform, or SecurityScorecard
. - Strong troubleshooting skills and experience supporting
Microsoft Azure environments
. - Knowledge of
databases (SQL)
and experience with
Power BI
. - Familiarity with
API programming and integration technologies
.
Preferred Qualifications
- Experience working in an
agile environment (Scrum / Kanban)
. - Background in developing and documenting
functional specifications
. - Familiarity with
testing methodologies and tools
. - Ability to manage issues, conflicts, and multiple priorities effectively.
- Strong planning, organizational, and leadership skills.
- Experience leading
small cross-functional projects
. - Knowledge of
information risk management processes
and
integration patterns (API, Messaging, Data Integration)
.
Why Join Strategic Staffing Solutions (S3)?
Full-Time Permanent Employment
Competitive Salary Package
Hybrid Work Setup:
Ayala Makati (2 Days Onsite / 3 Days Remote)
HMO Coverage:
Up to 500K
Leave Credits:
Prorated, applicable on first day
Government Benefits
13th Month Pay
Cyber Security Specialist(Risk)
Posted today
Job Viewed
Job Description
Job Summary:
The Cyber Security Risk Officer is responsible for identifying, assessing, mitigating, and monitoring cyber risks across the organization. This role ensures the company's digital assets, infrastructure, and data are protected from internal and external cyber threats. The officer collaborates with IT, legal, compliance, and business units to develop and implement risk-based security strategies aligned with regulatory and organizational requirements.
Key Responsibilities:
1.Risk Assessment & Management
- Conduct regular cyber risk assessments, threat modeling, and vulnerability assessments.
- Develop and maintain the organization's cybersecurity risk register.
- Evaluate risks associated with new projects, systems, or vendors, and provide mitigation strategies.
2.Cybersecurity Policies & Frameworks
- Assist in the development and enforcement of cybersecurity policies, standards, and procedures.
- Align policies with global standards and frameworks such as NIST, ISO 27001, COBIT, or CIS Controls.
3.Monitoring & Incident Support
- Work closely with the Security Operations Center (SOC) or IT security team to monitor for threats and assess incident impact.
- Support incident response and forensic investigations from a risk perspective.
4.Compliance & Regulatory Support
- Ensure adherence to industry standards and local/international cybersecurity regulations (e.g., Data Privacy Act, GDPR, PCI-DSS).
- Prepare for and support internal/external audits, risk assessments, and regulatory inspections.
5.Training & Awareness
- Support the delivery of cybersecurity awareness and training programs across the company.
- Promote a culture of cybersecurity and risk awareness.
6.Reporting & Metrics
- Prepare and present cybersecurity risk reports and dashboards to leadership and governance committees.
- Track key risk indicators (KRIs) and risk mitigation progress.
Qualifications:
- Education:
Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field. - Certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are preferred.
- Experience:
Minimum 3–5 years of relevant experience in cybersecurity, IT risk management, or information security roles. - Experience with risk assessment methodologies and tools.
- Skills & Competencies:
Strong understanding of cybersecurity frameworks and risk management principles. - Excellent analytical, communication, and report-writing skills.
- Ability to collaborate across technical and non-technical teams.
- Detail-oriented with a proactive problem-solving mindset.
Engineer, Information Security and Risk - Cyber Threat Intelligence
Posted 1 day ago
Job Viewed
Job Description
Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.
**About the Role**
As a P3 Engineer within the Cyber Threat Intelligence (CTI) team, you will support a Fortune 15 healthcare enterprise in identifying, analyzing, and mitigating threats to the organization's digital presence and global operations. This role will focus heavily on **Brand Monitoring** and **Geopolitical Intelligence** , while also contributing to other CTI functions such as **URL Whitelisting** , **Threat Research** , and **Threat Hunting** .
You will work closely with global CTI analysts, security engineers, and business stakeholders to deliver actionable intelligence that protects the organization's reputation, assets, and people.
**Key Responsibilities**
+ Monitor and analyze digital platforms, social media, and open-source channels for brand misuse, impersonation, fraud, and reputational threats.
+ Track geopolitical developments and assess their potential impact on business operations, supply chains, and personnel safety.
+ Conduct OSINT investigations to support threat assessments and incident response.
+ Collaborate with internal stakeholders to escalate and mitigate brand-related threats.
+ Support the CTI team in URL whitelisting reviews, threat research, and intelligence production.
+ Contribute to the development of threat models, risk assessments, and strategic intelligence reports.
+ Maintain documentation, metrics, and dashboards to support CTI program objectives.
+ Assist in tuning and optimizing threat intelligence tools and platforms.
**Required Qualifications**
+ Bachelor's degree in Cybersecurity, Political Science, International Relations, or a related field; or equivalent work experience.
+ 3+ years of experience in threat intelligence, brand protection, or geopolitical analysis.
+ Strong OSINT skills and familiarity with tools such as Anomali, Splunk, CrowdStrike or similar.
+ Experience with social media monitoring, dark web research, and digital risk protection platforms.
+ Excellent analytical, writing, and communication skills in English.
+ Ability to work independently and collaboratively in a remote, global team environment.
**Preferred Qualifications**
+ Experience in the healthcare or pharmaceutical sector.
+ Familiarity with the MITRE ATT&CK framework and threat actor profiling.
+ Exposure to SIEM platforms (e.g., Splunk) and scripting languages (e.g., Python).
+ Understanding of brand enforcement workflows and takedown procedures.
+ Knowledge of geopolitical risk frameworks and regional threat landscapes.
**What We Offer**
+ Opportunity to work with a global cybersecurity team in a mission-critical industry.
+ Exposure to advanced threat intelligence tools and methodologies.
+ Professional development and training in CTI, OSINT, and digital risk protection.
+ A collaborative and inclusive work culture with global impact.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (
Sr Analyst, Information Security and Risk - Cyber Threat Intelligence
Posted 1 day ago
Job Viewed
Job Description
Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments.
**About the Role**
As a P2 Senior Analyst supporting the Cyber Threat Intelligence (CTI) team, you will play a key role in maintaining and enhancing our enterprise security posture through the vetting and approval of URLs for business use and conducting open-source research to support threat intelligence initiatives. This role is ideal for a detail-oriented, analytical thinker with a passion for cybersecurity and a strong interest in threat research.
**Key Responsibilities**
+ Review and analyze URL submissions for business use, applying security and reputational risk criteria to approve or deny requests.
+ Conduct open-source intelligence (OSINT) research to support threat investigations and intelligence reporting.
+ Maintain documentation and audit trails for whitelisting decisions.
+ Collaborate with global CTI team members to support ongoing threat research and intelligence production.
+ Assist in identifying emerging threats, trends, and vulnerabilities relevant to the healthcare sector.
+ Contribute to the development and refinement of whitelisting processes and research methodologies.
+ Support the creation of intelligence summaries and reports for internal stakeholders.
**Required Qualifications**
+ Bachelor's degree in Cybersecurity, Information Technology, or a related field; or equivalent work experience.
+ 1-2 years of experience in cybersecurity, threat intelligence, or a related field (internships or academic projects acceptable).
+ Familiarity with OSINT tools and techniques (e.g., VirusTotal, URLScan, WHOIS, Shodan).
+ Strong analytical and critical thinking skills.
+ Excellent written and verbal communication skills in English.
+ Ability to work independently and manage time effectively in a remote environment.
**Preferred Qualifications**
+ Experience with URL filtering or whitelisting processes.
+ Basic understanding of threat intelligence frameworks (e.g., Diamond, MITRE ATT&CK).
+ Exposure to SIEM platforms (e.g., Splunk) and basic query writing.
+ Familiarity with scripting languages (e.g., Python) or Excel for data analysis.
+ Knowledge of the healthcare threat landscape or interest in learning.
**What We Offer**
+ Opportunity to work with a Fortune 15 company in a mission-critical industry.
+ Exposure to global cybersecurity operations and threat intelligence practices.
+ Supportive and collaborative team environment.
+ Professional development and training opportunities.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (
Be The First To Know
About the latest Cyber risk Jobs in Philippines !
Information Security
Posted today
Job Viewed
Job Description
As the
AVP for Internal Audit and Regulatory Response,
you will help sustain the operational requirements of the Security and Architecture Group (SAG) - MNL Governance, Risk and Compliance, including the Audit and Controls Assurance function. Currently, these responsibilities are being handled full-time by one person and part-time by the SAG MNL Head. With the addition of a new permanent staff member, we are expanding our capacity to focus more deeply on regulatory compliance and advisory efforts.
How You'll Make an Impact
- Assists the Cybersecurity Manager in preparing regular reports to Management, including internal controls assessments, analysis of newly released Information Security or Cybersecurity regulations, and policy compliance with Head Office and regional standards for the MNL Branch.
- Supports in monitoring control programs and remediation activities and help coordinate internal and external system and information security audits.
- Help maintain IS policies and procedures and assist in administering reviews related to overall system security compliance programs.
- Conduct assessments to identify potential risk and root causes of ineffective IS controls and provide actionable recommendations for resolution.
- Perform other duties as assigned by GPAPD Management and Cybersecurity Manager, as needed.
What Sets You Apart
- Graduate of Computer Science, Accountancy, or related course
- Solid understanding and hands-on experience with Identity Access Management (IAM)
- Brings at least 5 years of experience in Information Security, Technology Risk, or Operational Risk
- Upholds ethical business practices, doing the right thing while ensuring full compliance with internal controls and legal/regulatory standards
- Strong problem-solving skills and can adapt quickly when demands and priorities shift
- You use relevant information to make sound, informed recommendations
- You collaborate well with others and communicate effectively across teams and cultures
- You're open-minded and flexible in your interactions with others
- You have a good aptitude for learning and mastering new technology
- Oral and written communication skills are clear, professional, and effective
Manager, Information Security
Posted today
Job Viewed
Job Description
OPENTEXT - THE INFORMATION COMPANY
OpenText is a global leader in information management, where innovation, creativity, and collaboration are the key components of our corporate culture. As a member of our team, you will have the opportunity to partner with the most highly regarded companies in the world, tackle complex issues, and contribute to projects that shape the future of digital transformation.
AI-First. Future-Driven. Human-Centered.
At OpenText, AI is at the heart of everything we do—powering innovation, transforming work, and empowering digital knowledge workers. We're hiring talent that AI can't replace to help us shape the future of information management. Join us.
The Opportunity:
The Manager, Security Operation Center is a member of the Information Protection Center team reporting to the Sr. Manager, Information Security. This position works across Corporate and Production teams to ensure the successful implementation of security tools, services, and technology. The Security operations center manager provides oversight and management of the SOC including security operations management and security incident response, incident detection and analysis, containment, and eradication of cybersecurity incidents. This position will manage resources, priorities, and internal projects, and manage the team directly when responding to business-critical security incidents. Ideally, this role will 8-5pm eastern standard time.
You Are Great At:
- Defining, managing, and implementing a comprehensive SOC service
- Be a leader in the expansion and growth of the SOC
- Lead the response to significant Security incidents, ensuring the SOC teams effective response
- Collaborate with client technical teams for issue resolution and mitigation
- Organizing and prioritizing assessments of security controls and services to ensure accurate coverage reporting and identification of coverage gaps
- Review personnel resources daily to assess workload and quality of work
- Coordinate with Incident Response, Threat Intelligence and Threat Hunting teams to create post-incident feedback loop to educate SOC analysts and enhance detection capability
- Implementing tools and processes to automate and visualize security metrics, reporting, and dashboards for varying audiences
- Develop and maintain Standard Operating Procedures for security analyst roles and responsibilities
- Interfacing with internal audit and compliance teams to produce required security artifacts
- Overseeing technical coordination/project management for security initiatives, projects, and integration of security tools and services
- Coordinating risk assessments for requested deviation to security policy/controls
- Security monitoring, managing security cases& tickets, security incident analysis, and other security tasks.
- Responding to incidents varying from endpoint to server systems
- Researching security advisories, e.g., CERT, and delivering appropriate course of action
- Creating documentation to ensure all team members can perform required tasks
- Creating meaningful and detailed metrics based on security events or activities
- Collecting evidence and artifacts to meet compliance requirements (ISO, SOX, HIPAA, SOC, etc.)
- Optimizing day-to-day shift resources and needs
- Ensuring appropriate staffing and coverage for assigned shifts
- Managing and communicating up effectively to leadership regarding staffing needs, events that occurred, etc
What It Takes:
- Creating and refining metrics to articulate and measure SOC performance.
- Knowledge and experience managing a SOC and security operations
- Experience in a delivery, operational or security program management role and previous experience in a leadership or supervisory role
- Demonstrated experience generating metrics to measure service and program effectiveness
- Understanding of compliance frameworks, like PCI, ISO 27001, NIST, etc.
- Excellent analytical skills, troubleshooting and problem solving
- Must be able to work in a fast paced and changing environment while handling multiple tasks, priorities, and directives. Capable of working under pressure.
- Excellent English writing and verbal communication skills
- BS in Computer Science, Cyber Security, or Information Security preferred
- 7+ years of information security experience
- 4+ years of experience working in a Security Operations Center
- 3+ years of experience managing a Security Operations Center
- CISSP, CISA, CISM, or other industry certifications preferred
OpenText's efforts to build an inclusive work environment go beyond simply complying with applicable laws. Our Employment Equity and Diversity Policy provides direction on maintaining a working environment that is inclusive of everyone, regardless of culture, national origin, race, color, gender, gender identification, sexual orientation, family status, age, veteran status, disability, religion, or other basis protected by applicable laws.
If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please contact us Our proactive approach fosters collaboration, innovation, and personal growth, enriching OpenText's vibrant workplace.
Information Security Auditor
Posted today
Job Viewed
Job Description
Job Brief
The primary function is to perform advisory and assurance projects of Audit Services Group (ASG) focused on IT, information security and data privacy risks. ASG is responsible for evaluating the adequacy and effectiveness of the company's systems of internal controls that guide company activities toward accomplishing key business objectives.
Duties and Responsibilities
- Participate in planning, scoping and execution of risk-based IT, information security, and data privacy assurance and advisory projects in accordance with the Institute of Internal Auditors (IIA) and ASG standards
- Perform test of design and operating effectiveness of controls
- Effectively communicate audit results to management
- Work with stakeholders to develop actions plans that address root cause of findings
- Anticipate the impact of new technologies and strategic initiatives of the Company on its information security and privacy risk profile
- Demonstrate up-to-date knowledge in information security and privacy and apply this to the development, execution and improvement of audit programs and recommendations
- Develop and maintain productive working relationships with stakeholders, while maintaining independence and objectivity.
- Contribute to various department initiatives to streamline processes, improve stakeholder experience, and increase productivity.
- Contribute specialized expertise to different assigned projects and may provide key updates to Project Lead and Manager.
Minimum Requirements
- Bachelor's degree in management information systems, computer science, accounting, finance, or other IT related fields is required
- 2-4 years of IT auditing, technology, information security, privacy or other relevant work experience is required
- Must have strong verbal and written communication skills; fluency in English is required
- Knowledge of auditing cloud services, encryption technology, mobile technology, application security, software development methodologies, and common security frameworks preferred
- Ability to travel up to 30% including international travel (valid passport required)
- Professional certifications (e.g., CIA, CISA, CISSP) are preferred