Consultant - Risk & Security Assessments (Lead Level)

Nexus Recruitment Group

Makati

On-site

PHP 600,000 - 1,000,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Nexus Recruitment Group is seeking a skilled Risk & Security Consultant (Lead Level) to oversee information security assessments across enterprise environments in the Philippines. You will identify risks, evaluate controls, and deliver actionable remediation plans while mentoring junior staff.

The role emphasizes collaboration with IT, legal, and business stakeholders, producing clear reports and dashboards, and maintaining up-to-date knowledge of threat landscapes and regulatory changes.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Information Systems, or related field.
  • 4-7 years of experience in information security, IT audit, or risk management roles.
  • Strong knowledge of risk and control frameworks such as ISO 27001, NIST, SOC 2, PCI-DSS, or similar.
  • Experience in performing or leading security assessments, audits, or third-party risk reviews.
  • Familiarity with governance, risk, and compliance (GRC) tools is an advantage.
  • Excellent written and verbal communication skills with the ability to present technical findings to non-technical audiences.
  • Detail-oriented and highly organized, with the ability to manage multiple assessments simultaneously.

Responsibilities

  • Conduct risk and security assessments across applications, infrastructure, third-party vendors, and internal controls.
  • Evaluate and document risk exposure, security posture, and compliance against established frameworks (e.g., ISO 27001, NIST, CIS, COBIT).
  • Prepare detailed assessment reports, including identified risks, control gaps, and actionable recommendations.
  • Support the development and implementation of risk mitigation strategies and remediation plans.
  • Collaborate with cross-functional teams including IT, legal, compliance, and business stakeholders to understand and align security requirements.
  • Lead or contribute to the planning and execution of security assessments, audits, and readiness reviews.
  • Stay up to date with current threat landscapes, emerging risks, and relevant regulatory changes.
  • Support the preparation of risk dashboards and management reports.

Skills

Risk assessment
Information security
IT audit
GRC governance
Communication

Education

Bachelor's degree in Information Security / Computer Science

Tools

GRC tools
ISO 27001

Job description

Consultant - Risk & Security Assessments (Lead Level)

Job Openings Consultant - Risk & Security Assessments (Lead Level)

About the job Consultant - Risk & Security Assessments (Lead Level)
Job Summary:

We are seeking a detail-oriented and analytical Risk & Security Consultant to support and lead information security assessments across enterprise environments. This role will focus on identifying, evaluating, and mitigating security risks through structured assessments and consulting engagements. Depending on experience, this position can be scoped as Junior Lead Consultant or Lead Consultant, with increasing responsibility over project delivery, client engagement, and team mentoring.

The ideal candidate will bring a solid foundation in IT risk, cybersecurity frameworks, and control evaluation, along with strong interpersonal and documentation skills.

Key Responsibilities:
  • Conduct risk and security assessments across applications, infrastructure, third-party vendors, and internal controls.
  • Evaluate and document risk exposure, security posture, and compliance against established frameworks (e.g., ISO 27001, NIST, CIS, COBIT).
  • Prepare detailed assessment reports, including identified risks, control gaps, and actionable recommendations.
  • Support the development and implementation of risk mitigation strategies and remediation plans.
  • Collaborate with cross-functional teams including IT, legal, compliance, and business stakeholders to understand and align security requirements.
  • Lead or contribute to the planning and execution of security assessments, audits, and readiness reviews.
  • Stay up to date with current threat landscapes, emerging risks, and relevant regulatory changes.
  • Support the preparation of risk dashboards and management reports.
Qualifications:
  • Bachelors degree in Information Security, Computer Science, Information Systems, or a related field.
  • 4-7 years of experience in information security, IT audit, or risk management roles.
  • Strong knowledge of risk and control frameworks such as ISO 27001, NIST, SOC 2, PCI-DSS, or similar.
  • Experience in performing or leading security assessments, audits, or third-party risk reviews.
  • Familiarity with governance, risk, and compliance (GRC) tools is an advantage.
  • Excellent written and verbal communication skills with the ability to present technical findings to non-technical audiences.
  • Detail-oriented and highly organized, with the ability to manage multiple assessments simultaneously.
Preferred Certifications:
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)
  • CompTIA Security+ or equivalent foundational cert
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Lead Consultant - Security Architecture & Risk Assessment
Senior Lead Consultant - Security Architecture & Risk Assessment

Nexus Recruitment Group • Makati

On-site
PHP 1,800,000 - 2,400,000
Information Security Auditor / Security Compliance Specialist/ Security Analyst
Information Security Auditor / Security Compliance Specialist/ Security Analyst

Vertere Global Solutions, Inc. • Muntinlupa

On-site
PHP 800,000 - 1,100,000
Information Security & Compliance Senior Specialist
Information Security & Compliance Senior Specialist

CITADEL PACIFIC, LTD. - ROHQ • Taguig

On-site
PHP 600,000 - 900,000
IT Security Analyst
IT Security Analyst

John Clements Consultants, Inc. • Metro Manila

On-site
PHP 1,000,000 - 1,800,000
Governance, Risk and Compliance Specialist
Governance, Risk and Compliance Specialist

Concentrix • Mandaluyong

On-site
PHP 600,000 - 900,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Santo Niño 1st

On-site
PHP 1,200,000 - 1,800,000
Associate Specialist, Governance, Risk and Compliance
Associate Specialist, Governance, Risk and Compliance

cnx • Angeles, Mabalacat

On-site
PHP 350,000 - 700,000
IT Audit - Assistant Manager
IT Audit - Assistant Manager

Nexus Recruitment Group • Makati

On-site
PHP 900,000 - 1,300,000
Lead Risk & Security Assessments Consultant
Lead Risk & Security Assessments Consultant

Nexus Recruitment Group • Makati

On-site
PHP 600,000 - 1,000,000
Information Security & Compliance Lead
Information Security & Compliance Lead

Asticom Technology Inc • Taguig

On-site
PHP 2,500,000 - 4,000,000