Governance and Information Security Analyst

InnovaThink Corporation

Metro Manila

On-site

PHP 800,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

InnovaThink Corporation in Metro Manila is looking for a Governance and Information Security Analyst to enhance its security posture by implementing effective security controls and managing incidents. The ideal candidate will deploy enterprise security technologies, participate in incident response operations, and conduct vulnerability assessments. Strong knowledge in security governance, risk management, and compliance is required along with excellent analytical and communication skills.

Qualifications

  • Experience with enterprise security tools such as EDR, DLP, SIEM, SOAR, PAM, and Vulnerability Management.
  • Incident response and security operations experience.
  • Knowledge of security governance, risk, and compliance concepts.
  • Familiarity with audit processes and regulatory requirements.

Responsibilities

  • Deploy and optimize enterprise security technologies.
  • Participate in 24x7 security incident response rotation.
  • Conduct regular vulnerability assessments and analyze scan results.
  • Support internal and external audits.
  • Track emerging security threats and evaluate threat intelligence.
  • Perform additional duties to support security initiatives.

Skills

Enterprise security tools experience
Incident response and security operations
Knowledge of security governance
Analytical skills
Documentation skills
Stakeholder communication skills

Job description

Governance and Information Security Analyst

Governance and Information Security

Job Title: Governance and Information Security Analyst
Location: Local
Department: Governance and Information Security

Job Summary:

The Security Analyst / Cybersecurity Analyst is responsible for implementing, operating, and continuously improving the organization’s security controls, incident response capabilities, vulnerability management, and compliance posture. This role supports governance objectives by ensuring security technologies, processes, and controls are aligned with business requirements, regulatory standards, and defined security SLAs.

Key Responsibilities:

1. Security Technology Implementation & Operations

  • Deploy, configure, and continuously optimize enterprise security technologies, including but not limited to:
    • Endpoint Detection & Response (EDR)
    • Data Loss Prevention (DLP)
    • Privileged Access Management (PAM)
    • Vulnerability Management solutions
    • Secure Web Gateway (SWG)
    • Network Detection & Response (NDR)
  • Integrate security tools withSIEM,SOAR, and IT service management (ITSM) workflows.
  • Ensure security controls operate effectively and generate measurable detection and prevention outcomes.

Outcome:
Stable, effective, and measurable security controls that enhance the organization’s overall security posture.

2. 24×7 Incident Response Operations

  • Participate in the24×7 security incident response rotation, including on-call duties as required.
  • Investigate, respond to, and manageSeverity 1 and Severity 2 security incidents.
  • Perform containment, eradication, and recovery activities in accordance with incident response procedures.
  • Escalate incidents to internal stakeholders and leadership when necessary.

Outcome:
Rapid incident response with minimized business impact to critical systems and operations.

3. Vulnerability Management & Security Engineering Enablement

  • Conduct regularvulnerability assessmentsand analyze scan results.
  • Recommend, track, and validate remediation actions in coordination with IT and business teams.
  • Monitor remediation progress and report on risk posture and SLA adherence.
  • Align security controls with business and IT requirements.
  • Supportsecure-by-designprinciples in system changes, enhancements, and deployments.

Outcome:
Reduced security risk aligned with defined SLAs and improved integration of security into IT change processes.

4. Audit, Compliance, and Risk Support

  • Support internal and external audits by providing evidence, documentation, and control validation.
  • Assist in remediation of audit findings and track closure of observations.
  • Support access reviews, control testing, and compliance reporting activities.
  • Coordinate with governance, risk, and compliance (GRC) stakeholders as required.

Outcome:
Timely audit support, reduced audit observations, and strengthened compliance and governance posture.

5. Threat Intelligence & Security Posture Improvement

  • Track emerging security threats, vulnerabilities, and regulatory requirements.
  • Evaluate threat intelligence and recommend security enhancements.
  • Contribute to the continuous improvement of the organization’s security roadmap and control maturity.

Outcome:
Ongoing improvement of security posture through informed and proactive control enhancements.

6. Ad-hoc and Operational Support

  • Perform additional duties as required to support evolving security initiatives, incidents, or governance priorities.

Outcome:
Responsive and adaptable security support aligned with organizational and risk priorities.

Qualifications:
  • Experience with enterprise security tools (EDR, DLP, SIEM, SOAR, PAM, Vulnerability Management)
  • Incident response and security operations experience
  • Knowledge of security governance, risk, and compliance concepts
  • Familiarity with audit processes and regulatory requirements
  • Strong analytical, documentation, and stakeholder communication skills
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

Sterling Global Call Center, Inc. • Pasig

On-site
PHP 900,000 - 1,300,000
Information Technology Governance Analyst
Information Technology Governance Analyst

RBox International Solutions Inc. • Philippines

On-site
PHP 600,000 - 900,000
Information Security Architect
Information Security Architect

KMC Solutions • Metro Manila

On-site
PHP 1,200,000 - 1,800,000
Information Security Analyst
Information Security Analyst

Satellite Office • Taguig

On-site
PHP 700,000 - 900,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
Cybersecurity Analyst
Cybersecurity Analyst

Bounty Fresh Food, Inc. • Taguig

Hybrid
PHP 700,000 - 1,100,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
Cyber Governance, Risk and Compliance Specialist
Cyber Governance, Risk and Compliance Specialist

Virtual Business Partners Pty. Ltd. • Cebu City

On-site
PHP 800,000 - 1,200,000
HMO + Dental/Optical
Christmas vacation
Electricity & Data subsidies
+3
Security Analyst
Security Analyst

Artech Technology Inc. • Quezon City

On-site
PHP 3,527,000 - 5,292,000