Cyber Security Risk Assessment Specialist
Cyber Security Operations Group (CSOG)
About the Role
Before a new app, cloud service, or AI tool goes live across one of the Philippines' largest telco groups, someone has to ask: what could go wrong, and how do we stop it before it reaches production? That's you.
As a Cyber Security Risk Assessment Specialist, you'll review architecture diagrams, hunt for the security gaps other teams miss, and shape how PLDT and Smart evaluate risk before major projects launch. You'll work directly with engineering and project teams, build risk treatment plans that actually get implemented (not just filed), and grow your expertise across on-premise and cloud environments, on a technical/specialist career track built for depth, not just tenure.
We welcome applicants from cybersecurity, IT audit, compliance, or engineering backgrounds who bring curiosity and a security-first mindset, you don't need every box checked on paper to be the right fit for this team.
What You'll Do
- Execute risk assessments across multiple concurrent projects, evaluating new technologies, products, and services against company-approved standards and industry best practices.
- Analyze solution designs, network architecture, and data flow diagrams to identify vulnerabilities and recommend the security controls needed before production deployment.
- Build and track risk treatment plans, from findings and residual risk to mitigation timelines, ensuring required controls are implemented before launch.
- Run vulnerability scans across project-related applications and infrastructure, and drive remediation to closure in coordination with project teams.
- Review non-standard access requests (internet, admin rights, VPN) against cybersecurity policy and issue risk-based recommendations.
- Present risk assessment reports and compliance dashboards, and lead checkpoint meetings to keep security requirements on track across projects.
- Guide project teams on cybersecurity requirements and deliver risk assessments within committed timelines and service-level objectives.
What We're Looking For
Required
- Bachelor's degree in Information Technology, Computer Science, Engineering, or a related field.
- 3-5 years of experience in IT, Cybersecurity, Information Security, Risk Management, or a related discipline.
- Strong analytical and problem-solving skills.
- Excellent verbal and written communication skills.
- Ability to engage both technical and non-technical stakeholders.
Preferred Experience
Experience in one or more of the following:
- Information Security
- Telecommunications Technology
- Information Systems Audit
- Regulatory Compliance
Technical Knowledge
- Cybersecurity concepts and frameworks
- Cloud technologies and security services
- Network and infrastructure security
- Common cyber threats such as malware, DDoS, brute-force attacks, and web application attacks
- Technology architecture and solution reviews
Why Join Us?
- Work on large-scale enterprise and digital transformation initiatives.
- Gain exposure to diverse technologies, platforms, and cloud environments.
- Partner with cybersecurity, infrastructure, application, and business leaders across the organization.
- Play a key role in strengthening security posture before projects reach production.