108 IT Security Specialists jobs in the Philippines
Information Security Auditor
Posted today
Job Viewed
Job Description
**Work with Us. Change the World.**
At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the world's most complex challenges and build legacies for future generations.
There has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world.
We're one global team driven by our common purpose to deliver a better world. Join us.
**Job Description**
**Job Brief**
The primary function is to perform advisory and assurance projects of Audit Services Group (ASG) focused on IT, information security and data privacy risks. ASG is responsible for evaluating the adequacy and effectiveness of the company's systems of internal controls that guide company activities toward accomplishing key business objectives.
**Duties and Responsibilities**
+ Participate in planning, scoping and execution of risk-based IT, information security, and data privacy assurance and advisory projects in accordance with the Institute of Internal Auditors (IIA) and ASG standards
+ Perform test of design and operating effectiveness of controls
+ Effectively communicate audit results to management
+ Work with stakeholders to develop actions plans that address root cause of findings
+ Anticipate the impact of new technologies and strategic initiatives of the Company on its information security and privacy risk profile
+ Demonstrate up-to-date knowledge in information security and privacy and apply this to the development, execution and improvement of audit programs and recommendations
+ Develop and maintain productive working relationships with stakeholders, while maintaining independence and objectivity.
+ Contribute to various department initiatives to streamline processes, improve stakeholder experience, and increase productivity.
+ Contribute specialized expertise to different assigned projects and may provide key updates to Project Lead and Manager.
**Qualifications**
**Minimum Requirements**
+ Bachelor's degree in management information systems, computer science, accounting, finance, or other IT related fields is required
+ 2-4 years of IT auditing, technology, information security, privacy or other relevant work experience is required
+ Must have strong verbal and written communication skills; fluency in English is required
+ Knowledge of auditing cloud services, encryption technology, mobile technology, application security, software development methodologies, and common security frameworks preferred
+ Ability to travel up to 30% including international travel (valid passport required)
+ Professional certifications (e.g., CIA, CISA, CISSP) are preferred
**Additional Information**
**About AECOM**
AECOM is proud to offer comprehensive benefits to meet the diverse needs of our employees. Depending on your employment status, AECOM benefits may include medical, dental, vision, life, AD&D, disability benefits, paid time off, leaves of absences, voluntary benefits, perks, flexible work options, well-being resources, employee assistance program, business travel insurance, service recognition awards, retirement savings plan, and employee stock purchase plan.
AECOM is the global infrastructure leader, committed to delivering a better world. As a trusted professional services firm powered by deep technical abilities, we solve our clients' complex challenges in water, environment, energy, transportation and buildings. Our teams partner with public- and private-sector clients to create innovative, sustainable and resilient solutions throughout the project lifecycle - from advisory, planning, design and engineering to program and construction management. AECOM is a Fortune 500 firm that had revenue of $16.1 billion in fiscal year 2024. Learn more at aecom.com.
**What makes AECOM a great place to work**
You will be part of a global team that champions your growth and career ambitions. Work on groundbreaking projects - both in your local community and on a global scale - that are transforming our industry and shaping the future. With cutting-edge technology and a network of experts, you'll have the resources to make a real impact. Our award-winning training and development programs are designed to expand your technical expertise and leadership skills, helping you build the career you've always envisioned. Here, you'll find a welcoming workplace built on respect, collaboration and community - where you have the freedom to grow in a world of opportunity.
As an Equal Opportunity Employer, we believe in your potential and are here to help you achieve it. All your information will be kept confidential according to EEO guidelines.
**ReqID:** J10134928
**Business Line:** Geography OH
**Business Group:** DCS
**Strategic Business Unit:** GBS
**Career Area:** Finance
**Work Location Model:** Hybrid
**Legal Entity:** AECOM Global Business Services - Philippines ROHQ
Information Security Analyst
Posted today
Job Viewed
Job Description
- Bachelor’s degree in Information Technology, Computer Science or any related course
- With a minimum of 1 year related experience
- With Information Security-related trainings, preferably on Data Privacy Act of 2012 (RA 10173)
- Strong analytical, composition, and prioritizing skills
- Detail-oriented and with good organization and coordination skills
- Ability to maintain confidentiality
- Good written and oral communication skills
- **Duties and Responsibilities**_
- Implements security policy/measures and recommends improvements, as necessary
- Coordinates with all departments to ensure conformity to the PSMBFI Data Privacy Manual
- Aids in the conduct of routine review and inspection of security system infrastructure
- Coordinates with the IT department for the analysis of suspected information security breaches, and escalates such to the Head, Information Security Office, as necessary
- Provides administrative assistance in the conduct of periodic data privacy and information security awareness programs such as orientation and information campaigns to employees of the Company
- Assists in the preparation of various communications memoranda and departmental reports
- Receives and records incoming and outgoing communications of the department
- Maintains neat and orderly files of the department and ensures completeness, proper documentation and confidentiality
- Manages office and computer supplies as well as office equipment to ensure availability of resources for use by the department
- Performs tasks as provided for in the updated and approved PSMBFI Operations Manual
- Performs other related functions as directed by superior
**Job Types**: Full-time, Permanent
**Salary**: Php17,000.00 - Php20,000.00 per month
Schedule:
- 8 hour shift
- Monday to Friday
Supplemental Pay:
- 13th month salary
- Overtime pay
Information Security Officer
Posted today
Job Viewed
Job Description
- Evaluate and assess security issues, gaps, and risks and recommend/implement necessary change or corrective action processes for continuous improvement
- Provide assistance in auditing and ensuring internal and external compliance with the established security standards
- Assist in generating reports and documentation related to information security and risk management
- Perform client security assessment and privacy security assessment
- Facilitate information security management training and orientation
**Qualifications**:
- Graduate of a Bachelor's/College Degree in Computer Science, Information Technology, or any four-year course
- With at least 3 years of experience in Information Security Management or Information Technology Risk Management
- Being certified in CISM, CISSP, CRISC, etc. is a plus
- Knowledgeable in IT Security and Risk Management Framework (such as COBIT, Risk IT, ISO 27001)
- With excellent verbal and written communication skills
**Benefits**:
- Cash Convertible Leave Credits
- Non-taxable Allowances
- HMO Card
- HMO Card for dependent
- Medical Reimbursement
- Life & Accident Insurance
- Employee Referral Incentives
- Loyalty Incentive
- Government-Mandated Benefits
- Trainings
- Positive Working Environment and Work-Life Balance
**Job Types**: Full-time, Permanent
**Benefits**:
- Additional leave
- Company events
- Flexible schedule
- Free parking
- Health insurance
- Life insurance
- Opportunities for promotion
- Paid training
- Pay raise
- Promotion to permanent employee
- Transportation service provided
- Work from home
Schedule:
- 8 hour shift
- Flexible shift
- Monday to Friday
Supplemental Pay:
- 13th month salary
- Overtime pay
- Performance bonus
Information Security Manager
Posted today
Job Viewed
Job Description
- Evaluate and assess security issues, gaps, and risks and recommend/implement necessary change or corrective action processes for continuous improvement
- Audit and ensure internal and external compliance with the established security standards
- Generate reports and documentation related to information security and risk management
- Performing client security assessment and privacy security assessment
- Facilitate information security management training and orientation
- Manage and oversee the Information Security Team
**Qualifications**:
- Graduate of a Bachelor's/College Degree in Computer Science, Information Technology, or any four-year course
- With at least 5 years of experience in Information Security Management or Information Technology Risk Management
- Being certified in CISM, CISSP, CRISC, etc. is a plus
- Knowledgeable in IT Security and Risk Management Framework (such as COBIT, Risk IT, ISO 27001)
- With excellent verbal and written communication skills
**Benefits**:
- Cash Convertible Leave Credits
- Non-taxable Allowances
- HMO Card
- HMO Card for dependent
- Medical Reimbursement
- Life & Accident Insurance
- Employee Referral Incentives
- Loyalty Incentive
- Government-Mandated Benefits
- Trainings
- Positive Working Environment and Work-Life Balance
**Job Types**: Full-time, Permanent
**Benefits**:
- Additional leave
- Company events
- Flexible schedule
- Flextime
- Free parking
- Health insurance
- Life insurance
- Opportunities for promotion
- Paid training
- Pay raise
- Promotion to permanent employee
- Work from home
Schedule:
- 8 hour shift
- Flexible shift
- Monday to Friday
Supplemental Pay:
- 13th month salary
- Performance bonus
Information Security Officer
Posted today
Job Viewed
Job Description
- Excellent verbal, written communication and presentation skills - with experience in writing policies, procedures and manuals.
- Excellent in analytical and problem-solving abilities to identify and fix security risks.
- Applicants must be willing to work in 1174 Sotto Yuvienco Bldg. General Luna St., Paco Manila.
**Responsibilities**:
- Information Security Officer will be under the supervision of the IT Supervisor - help to improve and communicate the maturity levels of information security, state of cybersecurity, Data Privacy and IT risks practices across the company.
- Responsible for planning and implementation of security standards, Cyber Security, Data Protection and Privacy Laws based on ISO 27001.
- Develops and implements an actionable risk assessment program focused on information security and data privacy matters.
- Promote and create staff awareness in information security and data protection topics.
- Support development of policies and procedures for the information security, information technology and data privacy program.
**Job Types**: Full-time, Permanent
**Salary**: Php35,000.00 per month
Schedule:
- Day shift
Supplemental pay types:
- 13th month salary
- Overtime pay
Ability to commute/relocate:
- Manila: Reliably commute or planning to relocate before starting work (required)
Information Security Architect (Hybrid)
Posted 8 days ago
Job Viewed
Job Description
As a Security Architect, you will engage across various domains within information security, focusing on: br>Evaluating and auditing existing security controls and solutions.
Designing and implementing new security measures.
Providing expert counsel within the department and beyond.
Assisting in the design and optimization of our SIEM/MDR solutions.
Conducting risk assessments for infrastructure, applications, and vendors.
Qualifications:
Bachelor's degree in any field; degrees in Information Security, Computer Science, or Software Engineering preferred but not mandatory.
Certifications such as Azure Architect, Azure Security, OSCP, OSEP, CISSP, Security+, ISO 27001, CISM, or CRISC are advantageous but not required.
Excellent English communication skills.
Knowledge in areas such as:
Risk Management
Third-Party Risk Management
Control Management
Security Frameworks (ISO 27001/27002/27005, NIST 800-53, NIST CSF)
Policy and Procedure Development
Infrastructure and Cloud Security (Azure)
MDR/SIEM/Log Analytics
Incident Response
Vulnerability and Penetration Testing
Identity and Access Management (IAM)
Technical Security and Risk Assessments
Disaster Recovery Planning
Willingness to engage with the CISO on professional matters.
Information Security Analyst II

Posted 21 days ago
Job Viewed
Job Description
To manage all RX security assessments and play a key part in ensuring RX's security compliance optimization. Monitor assessments while ensuring that Reed Exhibitions internal systems are compliant with RELX and industry standards. Proactively manage the third-party risk assessments, compliance evidence gathering of their IT services, infrastructure, applications and relevant services against their Security policies and related frameworks. Training and development will be provided in all areas of the role as required.
Key Responsibilities:
Security Assessment Management
+ Serve as an advanced technical advisor for third-party assessments, providing detailed security insights and solutions.
+ Perform in-depth security reviews and risk assessments for new and existing third-party vendors, ensuring compliance with organizational and regulatory requirements.
+ Demonstrate advanced knowledge in RELX security compliance policies and procedures.
+ Stay current with updates and developments in security standards such as OWASP Top 10, ISO27001, and SOC 2, and ensure their proper implementation across the organization.
+ Develop and deliver training and awareness on security policies and standards to business units.
+ Gain in-depth knowledge of the organization's major infrastructure security controls, ensuring they align with RELX Policies and Standards, industry best practices, and regulatory requirements.
+ Coordinate with technology/service owners and business owners to conduct annual security audits, vulnerability assessments, and penetration tests where applicable.
+ Work collaboratively within all business areas and key stakeholders to ensure the review and approach of all security governance, risk, and compliance scope is appropriate and proactive.
+ Ensure continuous monitoring and reporting of compliance and risk status against NIST2.0, RELX Framework, ISO27001, SOC2, PCI DSS, regional and global regulations, and all other relevant standards.
+ Support internal and external audits by providing detailed documentation and evidence of security controls and practices.
+ Perform RX Business Unit and Third-Party security audits according to the CISO office strategic plan and produce detailed documentation and evidence against security controls and practices tested.
+ Act as a point of escalation for security-related incidents, providing advanced security support and guidance to Level I Analysts and other team members.
+ Provide regular updates and at least monthly metric reports to senior management on security compliance and risk posture.
+ Escalation of high impact security issues to Security Compliance Manager.
Ideal candidate profile:
Technical Skills:
+ Bachelor's Degree holder.
+ Background in IT, compliance, and/or information security.
+ Ability to work across all levels of seniority within business teams to drive a working partnership.
+ Strong analytical and critical thinking skills.
+ Understanding of industry standards for IT security (e.g., ISO27001/2, SOC 2, PCI DSS).
+ Basic understanding of IT security applications (e.g., firewalls, intrusion detection, virus protection).
+ Understanding of IT security testing and vulnerability management, and Threat Modeling.
+ Understanding in Cloud Environment (e.g., AWS, Azure or GCP)
+ Understanding of Service Level Management.
+ Desired understanding of OneTrust portal or Similar.
+ With CompTIA Security+ or Similar or Higher.
Personal Skills:
+ Ability to work across all levels of seniority within the organization and suppliers to drive a working partnership.
+ Good communication skills at all levels, both oral and written.
+ Good interpersonal skills.
+ Ability to produce effective influence and persuasive arguments in support of security assessment process goals.
+ Highly driven and self-motivated individuals.
+ Skilled in project management and able to work independently in a fast-paced environment.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1- .
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here .
Please read our Candidate Privacy Policy .
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:
EEO Know Your Rights .
RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.
Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.
Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.
Be The First To Know
About the latest It security specialists Jobs in Philippines !
Information Security Compliance Officer
Posted today
Job Viewed
Job Description
Key Responsibilities and Duties
Ensure standard parameters of systems and network used by Entrego is within best practices
Coordinate the continuous development, implementation and updating of security and privacy policies, standards, guidelines, baselines, processes, and procedures in compliance with local regulations and standards.
Develop and manage the frameworks, processes, tools, and consultancy necessary for IT to properly manage risk and to make risk-based decisions to IT activities.
Proactive identification and mitigation of IT risks as well as responding to observations identified by the third-party auditors while assisting in the development of periodic reports and presenting the level of controls compliance and current IT risk posture.
Assist Entrego with the audits and facilitate management response and remediation efforts.
Ensure overall IT compliance with regulatory requirements through proactive planning and communication, ownership, and relationships.
Identify acceptable levels of residual risk and assist with action plans, policy, and procedural changes for risk mitigation. Provide strategic recommendation to key IT projects to help improve project results, quality of deliverables, risk optimizations security processes and compliance with regulations.
Facilitate information security management education and training including user awareness programs. Requirements
Bachelor's degree in computer science or Information management
Experience in risk, compliance, and information security policy
Knowledge of laws and regulations including but not limited to RA10173 or the Data privacy Act of 2012
Experience with development of cybersecurity educational and awareness programs
Excellent organizational and communication skills (both oral and written)
Knowledge of information security processes and controls including risk and control framework.
NIST Frameworks
ITIL v4 best practices
IT security and control best practices
Skills and Certifications that are good to have but not required:
Certification in information security
Advance knowledge in OSI framework
Responsible for overseeing information security, cybersecurity and IT risk management programs based on industry-accepted information security and risk management frameworks.
Information Security Grc Analyst
Posted today
Job Viewed
Job Description
- ***
The Principal Governance, Risk, & Compliance (GRC) Analyst reports directly to the Director of GRC and is responsible for fulfilling and maturing services provided by the GRC team.**Responsibilities**:
- Maintain, and mature GRC services as a primary or backup service owner (e.g., Policy Management, Risk Management, Customer Security Due Diligence, Business Continuity Planning, etc.)
- Track assigned information security risks through the Risk Management process.
- Perform data quality reviews for GRC process measurement.
- Prepare risk management metrics and reporting.
- Work with Deltek technical and business professionals to determine appropriate risk treatment decisions and plans.
- Utilize governance, risk, and compliance (GRC) tools to manage list of external authoritative sources, information technology controls, corporate policies and procedures, vendor management system, and risk management workflows.
- Facilitate gathering, reviewing, and assembling internal and external audit evidence.
- Support projects as assigned to enhance Deltek compliance capabilities.
- Maintain proficiency with applicable laws, regulations, and standards.
- Draft and maintain compliance documents (e.g., policies, standards, procedures, etc.).
- Coordinate the adoption of information security best practices throughout the enterprise.
**Qualifications**
**Requirements**:
- B.S. degree (Information Security, Computer Science, MIS, or equivalent program preferred)
- Minimum 3 years of combined experience in Information security, compliance, technology audit, or a related field.
- Experience with NIST SP 800-53, ISO 27001, PCI DSS, or SOC 1/2.
- Strong written and verbal communication skills.
- Experience working in a collaborative team environment.
**Preferences**:
- CISSP, CISA, or other related information security certification desired.
- FedRAMP, NIST 800-171, CSA CCM, CIS Security Framework experience desired.
- Experience with software development in a cloud environment desired.
**Travel Requirements**
- 10%
Chief Information Security Officer (CISO)
Posted 16 days ago
Job Viewed