Cybersecurity Risk and Compliance Specialist | GSC (Client-based)

Hammerjack Pty Ltd

Philippines

Hybrid

PHP 2,790,000 - 3,410,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work schedule
Night shifts

Job summary

Hammerjack Pty Ltd seeks an experienced cybersecurity auditor to perform risk and security assessments across enterprise apps, cloud services, data pipelines and AI-enabled solutions. You will evaluate policies, controls and threat surfaces, prepare reports, and present findings to leadership.

Hybrid work 1–2 days on site weekly; Makati-based office in Ayala/Legazpi Village. Candidates have 3–7 years in TRA, strong knowledge of NIST, ISO27001, SOC 2, PCI DSS, and security operations.

Qualifications

  • Bachelor's or Master's degree in Cybersecurity, Information Security, Computer Science, or related field.
  • 3-7 years of experience in cybersecurity audits, threat and risk assessments, security risk management, and assessments of organizations, third‑party environments, or technology solutions.

Responsibilities

  • Conduct cyber assessments for organizations, technology environments, and solutions to identify security gaps, vulnerabilities, and risks.
  • Assess diverse solution types including enterprise applications, cloud platforms, data/integration pipelines, third-party solutions, and AI-enabled solutions.
  • Evaluate security policies, procedures, governance practices, and technical controls for compliance with standards such as NIST CSF, NIST 800-30, ISO 27001, NIST AI RMF, OWASP GenAI guidance, etc.
  • Identify cyber threats, attack vectors, and potential risks impacting operations and delivery.
  • Evaluate solution-specific risks and controls including access management, data protection, secure configuration, API/integration security, vendor dependencies, and AI-related risks.
  • Recommend risk mitigation strategies to strengthen cyber resilience.
  • Provide cyber risk assurance by aligning security controls with business objectives.
  • Assess effectiveness of technical security controls like access management, encryption, endpoint, network, and cloud security.
  • Recommend improvements to security architecture and IT infrastructure to reduce risks.
  • Prepare detailed assessment reports, risk documentation, and executive summaries.
  • Present findings and recommendations to senior leadership and technical teams.

Skills

Analytical skills
Problem solving
Communication skills
Collaboration

Education

Bachelor's or Master's in Cybersecurity / Information Security

Job description

Responsibilities:
  • Conduct cyber assessments for organizations, technology environments, and solutions (e.g., threat & risk assessments, cyber maturity assessments, compliance assessments, due diligence, solution assessments, and AI-enabled solution assessments) to identify security gaps, vulnerabilities, and risks.
  • Assess diverse solution types, including enterprise applications, cloud platforms, data/integration pipelines, third-party or vendor solutions, and AI-enabled or generative AI solutions.
  • Evaluate security policies, procedures, governance practices, and technical controls to ensure compliance with industry standards such as NIST CSF, NIST 800-30, ISF IRAM2, ISO 27001, NIST AI RMF, OWASP LLM/GenAI guidance, etc., where applicable.
  • Identify cyber threats, attack vectors, and potential risks impacting business operations and solution delivery.
  • Evaluate solution-specific risks and controls, including access management, data protection, secure configuration, API/integration security, vendor dependencies, and AI-related risks such as prompt injection, data/model poisoning, model theft, and excessive agency.
  • Recommend risk mitigation strategies to strengthen organizational cyber resilience.
  • Provide cyber risk assurance by aligning security controls with business objectives.
  • Assess the effectiveness of technical security controls such as access management, encryption, endpoint security, network security, and cloud security.
  • Recommend improvements to security architecture and IT infrastructure to reduce cyber risks.
  • Prepare detailed assessment reports, risk assessment documentation, and executive summaries.
  • Present security risks findings and recommendations to senior leadership and technical teams.
Qualifications:
  • Bachelor's or Master's degree in Cybersecurity, Information Security, Computer Science, or a related field.
  • 3-7 years of experience in cybersecurity audits, threat and risk assessments (TRA), security risk management, and assessments of organizations, third-party environments, or technology solutions.
  • Strong knowledge of cybersecurity frameworks (e.g., NIST CSF, NIST 800-30, NIST AI RMF, ISO 27001, SOC 2, PCI DSS, CIS Controls, OWASP LLM/GenAI guidance, etc.).
  • Hands-on experience with security risk assessment tools and methodologies.
  • Understanding of security operations, threat intelligence, and incident response.
  • Proficiency in network security, cloud security (AWS, Azure, GCP), application security, data security, and third-party/vendor risk considerations.
  • Experience assessing enterprise applications, cloud services, integrations/APIs, vendor platforms, and AI-enabled or generative AI solutions is preferred.
  • Excellent analytical, problem-solving, and communication skills.
  • Ability to work collaboratively with technical and non-technical stakeholders.
  • Certifications preferred:
  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified Information Systems Security Professional)
  • CRISC (Certified in Risk and Information Systems Control)

Working Set-up: Hybrid - 1-2x a week ONSITE / Nightshift

Office Location: Makati (Ayala or Legazpi Village site)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Associate Consultant - Onsite (A-ACY)
Cybersecurity Associate Consultant - Onsite (A-ACY)

Sourcefit Philippines Inc. • Quezon City

On-site
PHP 334,800 - 558,000
Cyber Risk & Assurance Specialist
Cyber Risk & Assurance Specialist

Michael Page • Philippines

Hybrid
Confidential
Hybrid work setup
Competitive salary and benefits
Professional development opportunities
Senior Specialist, GRC
Senior Specialist, GRC

LaVie • Manila

On-site
PHP 1,200,000 - 1,800,000
Cybersecurity Governance and Risk Manager
Cybersecurity Governance and Risk Manager

Our Clients • Makati

Hybrid
PHP 960,000 - 1,440,000
Information Security Manager
Information Security Manager

Recruitify_HR • Taguig

Hybrid
PHP 900,000 - 1,500,000
Medical
Miscellaneous allowance
Dental
+1
Cybersecurity Operations Engineer
Cybersecurity Operations Engineer

RecruitNest Consulting • Taguig

On-site
PHP 1,200,000 - 1,800,000
Cybersecurity & Compliance Consultant
Cybersecurity & Compliance Consultant

Sourcefit • Philippines

On-site
PHP 350,000 - 650,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Copeland India Private Ltd. • Quezon City

Hybrid
PHP 700,000 - 1,000,000
Flexible benefits plans
Paid parental leave
Vacation and holiday leave
Hybrid GRC Cybersecurity Analyst | Risk & Compliance
Hybrid GRC Cybersecurity Analyst | Risk & Compliance

Copeland India Private Ltd. • Quezon City

Hybrid
PHP 700,000 - 1,000,000
Flexible benefits plans
Paid parental leave
Vacation and holiday leave
Technology Risk & Compliance Officer - BGC - Manila
Technology Risk & Compliance Officer - BGC - Manila

Dotco Pte. Ltd. • Taguig

On-site
PHP 1,200,000 - 1,900,000