7 Security Auditor jobs in the Philippines
Information Security Auditor
Posted 4 days ago
Job Viewed
Job Description
**Work with Us. Change the World.**
At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the world's most complex challenges and build legacies for future generations.
There has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world.
We're one global team driven by our common purpose to deliver a better world. Join us.
**Job Description**
**Job Brief**
The primary function is to perform advisory and assurance projects of Audit Services Group (ASG) focused on IT, information security and data privacy risks. ASG is responsible for evaluating the adequacy and effectiveness of the company's systems of internal controls that guide company activities toward accomplishing key business objectives.
**Duties and Responsibilities**
+ Participate in planning, scoping and execution of risk-based IT, information security, and data privacy assurance and advisory projects in accordance with the Institute of Internal Auditors (IIA) and ASG standards
+ Perform test of design and operating effectiveness of controls
+ Effectively communicate audit results to management
+ Work with stakeholders to develop actions plans that address root cause of findings
+ Anticipate the impact of new technologies and strategic initiatives of the Company on its information security and privacy risk profile
+ Demonstrate up-to-date knowledge in information security and privacy and apply this to the development, execution and improvement of audit programs and recommendations
+ Develop and maintain productive working relationships with stakeholders, while maintaining independence and objectivity.
+ Contribute to various department initiatives to streamline processes, improve stakeholder experience, and increase productivity.
+ Contribute specialized expertise to different assigned projects and may provide key updates to Project Lead and Manager.
**Qualifications**
**Minimum Requirements**
+ Bachelor's degree in management information systems, computer science, accounting, finance, or other IT related fields is required
+ 2-4 years of IT auditing, technology, information security, privacy or other relevant work experience is required
+ Must have strong verbal and written communication skills; fluency in English is required
+ Knowledge of auditing cloud services, encryption technology, mobile technology, application security, software development methodologies, and common security frameworks preferred
+ Ability to travel up to 30% including international travel (valid passport required)
+ Professional certifications (e.g., CIA, CISA, CISSP) are preferred
**Additional Information**
Shift schedule: Morning shift (9AM to 6PM)
**About AECOM**
AECOM is proud to offer comprehensive benefits to meet the diverse needs of our employees. Depending on your employment status, AECOM benefits may include medical, dental, vision, life, AD&D, disability benefits, paid time off, leaves of absences, voluntary benefits, perks, flexible work options, well-being resources, employee assistance program, business travel insurance, service recognition awards, retirement savings plan, and employee stock purchase plan.
AECOM is the global infrastructure leader, committed to delivering a better world. As a trusted professional services firm powered by deep technical abilities, we solve our clients' complex challenges in water, environment, energy, transportation and buildings. Our teams partner with public- and private-sector clients to create innovative, sustainable and resilient solutions throughout the project lifecycle - from advisory, planning, design and engineering to program and construction management. AECOM is a Fortune 500 firm that had revenue of $16.1 billion in fiscal year 2024. Learn more at aecom.com.
**What makes AECOM a great place to work**
You will be part of a global team that champions your growth and career ambitions. Work on groundbreaking projects - both in your local community and on a global scale - that are transforming our industry and shaping the future. With cutting-edge technology and a network of experts, you'll have the resources to make a real impact. Our award-winning training and development programs are designed to expand your technical expertise and leadership skills, helping you build the career you've always envisioned. Here, you'll find a welcoming workplace built on respect, collaboration and community - where you have the freedom to grow in a world of opportunity.
As an Equal Opportunity Employer, we believe in your potential and are here to help you achieve it. All your information will be kept confidential according to EEO guidelines.
**ReqID:** J10134928
**Business Line:** Geography OH
**Business Group:** DCS
**Strategic Business Unit:** GBS
**Career Area:** Finance
**Work Location Model:** Hybrid
**Legal Entity:** AECOM Global Business Services - Philippines ROHQ
Vulnerability Assessment Analyst - Pasay City
Posted 8 days ago
Job Viewed
Job Description
Position: Vulnerability Assessment Analyst br>Company Industry: BPO Company
Work Location: MOA Pasay
Work Schedule: Mid Shift (4:00 PM or 5:00 PM)
Salary: Php 60,000 – Php 70,000 < r>Work Set Up: Hybrid (1–2 times a month Return-to-Office) < r>
JOB REQUIREMENTS:
• Bachelor’s degree in Computer Science, Information Systems, Cyber Intelligence, or related field
• E perience creating Nuclei templates < r>• P actical experience with network and web application penetration testing tools such as: Burp Suite, Nmap, Fiddler, OWASP ZAP, Metasploit or Wireshark. < r>
JOB RESPONSIBILITIES:
• C nduct regular vulnerability assessments and support mitigation strategies < r>• I entify, analyze, and report on potential security threats < r>• C llaborate with internal teams to improve overall system security < r>• M intain and update security tools and scripts used for threat detection < r>• A sist in incident response and remediation activities < r>
RECRUITMENT PROCESS: (ONLINE)
HR Interview
Technical Assessment
Hiring Manager Interview
Job Offer
Information Security Architect (Hybrid)
Posted 7 days ago
Job Viewed
Job Description
As a Security Architect, you will engage across various domains within information security, focusing on: br>Evaluating and auditing existing security controls and solutions.
Designing and implementing new security measures.
Providing expert counsel within the department and beyond.
Assisting in the design and optimization of our SIEM/MDR solutions.
Conducting risk assessments for infrastructure, applications, and vendors.
Qualifications:
Bachelor's degree in any field; degrees in Information Security, Computer Science, or Software Engineering preferred but not mandatory.
Certifications such as Azure Architect, Azure Security, OSCP, OSEP, CISSP, Security+, ISO 27001, CISM, or CRISC are advantageous but not required.
Excellent English communication skills.
Knowledge in areas such as:
Risk Management
Third-Party Risk Management
Control Management
Security Frameworks (ISO 27001/27002/27005, NIST 800-53, NIST CSF)
Policy and Procedure Development
Infrastructure and Cloud Security (Azure)
MDR/SIEM/Log Analytics
Incident Response
Vulnerability and Penetration Testing
Identity and Access Management (IAM)
Technical Security and Risk Assessments
Disaster Recovery Planning
Willingness to engage with the CISO on professional matters.
Information Security Analyst II

Posted 20 days ago
Job Viewed
Job Description
To manage all RX security assessments and play a key part in ensuring RX's security compliance optimization. Monitor assessments while ensuring that Reed Exhibitions internal systems are compliant with RELX and industry standards. Proactively manage the third-party risk assessments, compliance evidence gathering of their IT services, infrastructure, applications and relevant services against their Security policies and related frameworks. Training and development will be provided in all areas of the role as required.
Key Responsibilities:
Security Assessment Management
+ Serve as an advanced technical advisor for third-party assessments, providing detailed security insights and solutions.
+ Perform in-depth security reviews and risk assessments for new and existing third-party vendors, ensuring compliance with organizational and regulatory requirements.
+ Demonstrate advanced knowledge in RELX security compliance policies and procedures.
+ Stay current with updates and developments in security standards such as OWASP Top 10, ISO27001, and SOC 2, and ensure their proper implementation across the organization.
+ Develop and deliver training and awareness on security policies and standards to business units.
+ Gain in-depth knowledge of the organization's major infrastructure security controls, ensuring they align with RELX Policies and Standards, industry best practices, and regulatory requirements.
+ Coordinate with technology/service owners and business owners to conduct annual security audits, vulnerability assessments, and penetration tests where applicable.
+ Work collaboratively within all business areas and key stakeholders to ensure the review and approach of all security governance, risk, and compliance scope is appropriate and proactive.
+ Ensure continuous monitoring and reporting of compliance and risk status against NIST2.0, RELX Framework, ISO27001, SOC2, PCI DSS, regional and global regulations, and all other relevant standards.
+ Support internal and external audits by providing detailed documentation and evidence of security controls and practices.
+ Perform RX Business Unit and Third-Party security audits according to the CISO office strategic plan and produce detailed documentation and evidence against security controls and practices tested.
+ Act as a point of escalation for security-related incidents, providing advanced security support and guidance to Level I Analysts and other team members.
+ Provide regular updates and at least monthly metric reports to senior management on security compliance and risk posture.
+ Escalation of high impact security issues to Security Compliance Manager.
Ideal candidate profile:
Technical Skills:
+ Bachelor's Degree holder.
+ Background in IT, compliance, and/or information security.
+ Ability to work across all levels of seniority within business teams to drive a working partnership.
+ Strong analytical and critical thinking skills.
+ Understanding of industry standards for IT security (e.g., ISO27001/2, SOC 2, PCI DSS).
+ Basic understanding of IT security applications (e.g., firewalls, intrusion detection, virus protection).
+ Understanding of IT security testing and vulnerability management, and Threat Modeling.
+ Understanding in Cloud Environment (e.g., AWS, Azure or GCP)
+ Understanding of Service Level Management.
+ Desired understanding of OneTrust portal or Similar.
+ With CompTIA Security+ or Similar or Higher.
Personal Skills:
+ Ability to work across all levels of seniority within the organization and suppliers to drive a working partnership.
+ Good communication skills at all levels, both oral and written.
+ Good interpersonal skills.
+ Ability to produce effective influence and persuasive arguments in support of security assessment process goals.
+ Highly driven and self-motivated individuals.
+ Skilled in project management and able to work independently in a fast-paced environment.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1- .
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here .
Please read our Candidate Privacy Policy .
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:
EEO Know Your Rights .
RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.
Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.
Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.
Chief Information Security Officer (CISO)
Posted 15 days ago
Job Viewed
Job Description
SAP Platform Security Leader Operations and Audit & Compliance

Posted 19 days ago
Job Viewed
Job Description
MANILA SIX/NEO OFFICE
Job Description
We seek a highly skilled and experienced professional to assume the Senior Manager of SAP Platform Security Operations and Audit & Compliance role. In this high impact position, you will support all security aspects beneath our SAP Basis Application - including Infrastructure, Operating Systems, Databases, and any horizontal software components shared across multiple applications. Your technical expertise will be crucial in maintaining the integrity of our SAP landscape and supporting the organization's overall security operations - including ensuring audit & compliance requirements and delivering key security projects.
As a Senior Security Engineer, you will be responsible for enhancing the security posture of our organization. You will handle day-to-day design, build, implementation, testing, deployment/release management, and monitoring of security solutions and platforms. You will engage in information security projects that evaluate existing security infrastructure and propose changes as defined by security leadership and architects. Additionally, you will communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business and gain support through influential messaging.
The SAP Platform Security Operations and Audit & Compliance Team oversees, assesses, and manages:
+ Security approach driven by business, compliance, and regulatory requirements.
+ Security solutions that align with the key principles outlined within P&G's Info Security policies.
+ Security structure that imposes the minimum administrative overhead from a sustainability perspective.
+ Restrict access authorizations to the user's job requirements and responsibilities.
+ Provide expertise, best practices, and guidance on SAP security standards.
+ Provide appropriate security monitoring to reduce the risk of any audit & compliance deviations.
Key Responsibilities:
Support the SAP Security Operations & Audit & Compliance Team on an operational level. He/she will deliver support that is consistent, of the highest quality, and complete as it relates to all security aspects beneath our SAP Basis Application - including Infrastructure, Operating Systems, Databases, and any horizontal software components shared across multiple applications.
+ Handle day-to-day design, build, implementation, testing, deployment/release management, and monitoring of security solutions and platforms.
+ Engage in information security projects that evaluate existing security infrastructure and propose changes as defined by security leadership and architects.
+ Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business.
+ Identify, analyze, and respond to malicious behaviors from a variety of sources and create action plans to mitigate future incidents.
+ Research new tactics, techniques, and procedures (TTPs) in public and closed forums, assessing risk and implementing/validating controls as necessary through the CI/CD pipeline.
Job Qualifications
+ Extensive experience (6+ years) in SAP Platform Security, SAP Basis, HANA DB, internal controls, compliance, or a related field, focusing on SAP systems.
+ Extensive and broad-based experience and expertise with all stacks of SAP Infrastructure and Application stack with demonstrated understanding of SAP Security and Compliance within a large and diverse enterprise environment or business community.
+ Strong understanding of SAP processes, modules, and configurations, including ECC, S/4HANA, BTP, SAP Platform, Basis, Integration, OS, and related technologies.
+ Ideally, knowledge of the P&G information security framework and SAP Enterprise Security Control
+ Knowledge of IT SAP security tools such as code scanners, GRC tools, or tools for SAP SoD monitoring.
+ Relevant certifications such as ITIL, SAP HANATEC, Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent are a plus.
+ Excellent communication, presentation, and interpersonal skills.
+ Ability to manage conflicting priorities and multiple tasks incl. reasoning and problem-solving skills (especially in the task force phase).
+ Traditional/waterfall and agile project management skills.
+ Strong analytical and problem-solving abilities, with keen attention to detail.
+ Experience in working with regulatory requirements and industry standards (e.g., SOX, GDPR) SAP systems.
+ Create an atmosphere of trust, leverage diverse views, and encourage improvement and innovation.
+ Prior success in roles managing in a professional services firm or large enterprise as a consultant, auditor or business process specialist is preferred.
+ Demonstrates breadth of applied IT skills across at least two IT job profiles.
+ Applies Integrated Risk Management, IT Operations, IT Project Management, and Enterprise Architecture skills relevant to the work.
+ Requires at least two relevant roles with experience managing or influencing people or organizations to achieve significant IT outcomes.
+ Demonstrates ability to define strategy and leads the delivery and transformation of business outcomes through IT within major sub-OU services, products, or programs.
About us
We produce globally recognized brands and we grow the best business leaders in the industry. With a portfolio of trusted brands as diverse as ours, it is paramount our leaders are able to lead with courage the vast array of brands, categories and functions. We serve consumers around the world with one of the strongest portfolios of trusted, quality, leadership brands, including Always®, Ariel®, Gillette®, Head & Shoulders®, Herbal Essences®, Oral-B®, Pampers®, Pantene®, Tampax® and more. Our community includes operations in approximately 70 countries worldwide. Visit to know more.
We are an equal opportunity employer and value diversity at our company. We do not discriminate against individuals on the basis of race, color, gender, age, national origin, religion, sexual orientation, gender identity or expression, marital status, citizenship, disability, HIV/AIDS status, or any other legally protected factor.
"At P&G, the hiring journey is personalized every step of the way, thereby ensuring equal opportunities for all, with a strong foundation of Ethics & Corporate Responsibility guiding everything we do.
All the available job opportunities are posted either on our website - pgcareers.com, or on our official social media pages, for the convenience of prospective candidates, and do not require them to pay any kind of fees towards their application."
Job Schedule
Full time
Job Number
R000132511
Job Segmentation
Experienced Professionals
Info Security Risk Consultant - IT IS Compliance/Audit, HITRUST, ISO 27001, SOC 2 Type II
Posted 25 days ago
Job Viewed
Job Description
**Primary Responsibilities:**
+ Ensure third-party supplier's compliance to business requirements - business agreement, policies, procedures, and regulations
+ Lead third-party supplier security risk assessment and remediation activities
+ Research, understand and analyze information security risks applicable to a supplier
+ Conduct discovery call and perform risk-based assessment
+ Review evidence and supporting documentations from the supplier
+ Communicate identified security gaps, provide recommendations, and monitor/track progress until its completion
+ Collaborate with internal stakeholders and management for any process deviations, delays, or escalations
+ Oversee and supervise assigned analyst's work to ensure risk assessment and remediation activities are carried out effectively and efficiently
+ Perform reviews of risk assessment documentation and remediation completion
+ Attend and observe risk assessment and remediation meetings
+ Provide support, guidance and assistance to any inquiries, concerns, or challenges
+ Track completion and ensure that SLA is met
+ Assist with the execution of the Information Risk Governance program
+ Participate in solving complex problems, address issues and challenges
+ Develop or support solutions for process improvement
+ Contribute to training program implementation
+ Lead or participates on special projects
+ Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
**Required Qualifications:**
+ 5+ years of experience in IT or IS compliance/audit
+ 5+ years of experience with various compliance frameworks and regulations like HITRUST, ISO 27001, SOC 2 Type II, PCI DSS, NIST, etc.
+ Advance level experience in MS Office 365
+ Knowledge and understanding of different security products (MFA, encryption, threat & vulnerability, antivirus, network protection, etc.)
+ Proven solid communication (listening, verbal, written) and presentation skills
+ Proven ability to develop effective relationships with team members, suppliers, and internal stakeholders
**Preferred Qualification:**
+ Certifications: Sec+, CISA, CRISC, CISM, ISO 27001 Lead Auditor, ISC2 CC
_At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission._
_Optum is a drug-free workplace. © 2025 Optum Global Solutions (Philippines) Inc. All rights reserved._
Be The First To Know
About the latest Security auditor Jobs in Philippines !