Information Security Analyst Subject Matter Expert (SME) - Project-based

Umpisa Inc.

Hinoba-an

On-site

PHP 700,000 - 1,200,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Umpisa Inc. in the Philippines is seeking an Information Security Analyst to design, implement, and maintain security controls across the organization. You will serve as a subject matter expert, ensuring secure operations while aligning with ISO 27001, NIST, and other standards.

You will monitor security events, support audits, and advise IT, engineering and business teams. The role demands strong communication, problem solving, and the ability to translate complex security concepts into

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, IT, or a related field (or equivalent experience).
  • At least 5 years of experience in information security, cybersecurity, or IT risk roles.
  • Strong understanding of information security principles and frameworks (NIST, ISO 27001, PCI DSS, SOC 2).
  • Experience in hands-on SME or fast-growing organizations.
  • Experience communicating policies and compliance requirements with technical and non-technical audiences at various levels.

Responsibilities

  • Act as the organization’s Subject Matter Expert on information security concepts, risks, and controls.
  • Identify, assess, and manage information security risks across systems, applications, and processes.
  • Monitor security events, incidents, and alerts; investigate and coordinate remediation actions.
  • Conduct regular vulnerability assessments and support penetration testing activities.
  • Develop, review, and maintain information security policies, standards, and procedures.

Skills

Strong communication skills
Problem solving
Analytical skills
Security frameworks knowledge

Education

Bachelor’s degree in Information Security, Computer Science, IT, or related field

Tools

SIEM
Endpoint security
Vulnerability scanners

Job description

At Umpisa Inc., our mission is to make the Philippines be known globally as a tech hub.

Umpisa Inc. is a progressive technology services company that partners with select industries, clients and people to work on pioneering and industry-changing solutions via digital transformation, modern software development and venture building.

We create a set of world-class and impactful products and solutions to help organizations and individuals live better lives. We offer demanding, challenging and rewarding careers in software development, product development, emerging technologies, and more for the right candidates.

As Information Security Analyst, you will:

  • The Information Security Analyst (SME) is responsible for protecting the organization’s information assets by designing, implementing, and maintaining security controls, policies, and best practices. As a Subject Matter Expert, this role provides hands‑on technical expertise, risk assessment, and advisory support across the business, ensuring compliance with security standards while enabling secure business operations.
  • Compliance Monitoring: Support the implementation and monitoring of security policies to ensure compliance with applicable laws, regulations, and industry standards (e.g. ISO 27001, NIST)
  • Participate in internal, external or regulatory audits as required.
  • Other work or projects as assigned.

Essential Skills:

  • Aligns with our values: Excellence, Integrity, Professionalism, People Success, Customer Success, Fun, Innovation and Diversity
  • Strong communication skills
  • Strong problem solving and analytical skills
  • Excellent problem‑solving ability
Key Responsibilities
Security Operations & Risk Management
  • Act as the organization’s Subject Matter Expert on information security concepts, risks, and controls
  • Identify, assess, and manage information security risks across systems, applications, and processes
  • Monitor security events, incidents, and alerts; investigate and coordinate remediation actions
  • Conduct regular vulnerability assessments and support penetration testing activities
Policy, Governance & Compliance
  • Develop, review, and maintain information security policies, standards, and procedures
  • Ensure alignment with industry standards (e.g., ISO 27001, NIST, SOC 2, or equivalent)
  • Support internal and external audits, client security assessments, and compliance requirements
  • Provide security guidance for data protection, access management, and secure handling of information
Advisory & Enablement
  • Serve as a trusted security advisor to IT, Engineering, HR, and Business teams
  • Review system designs, architecture, and changes to ensure security-by-design principles
  • Support third‑party risk assessments and vendor security reviews
  • Translate complex security concepts into clear, actionable guidance for non‑technical stakeholders
Awareness & Continuous Improvement
  • Lead or support information security awareness and training programs
  • Stay current with emerging threats, vulnerabilities, and security best practices
  • Recommend and implement improvements to tools, processes, and controls

Minimum Requirements:

  • Bachelor’s degree in Information Security, Computer Science, IT, or a related field (or equivalent experience)
  • at least 5 years of experience in information security, cybersecurity, or IT risk roles
  • Strong understanding of:
    • Information security principles and frameworks
    • Risk assessment and vulnerability management
    • Identity and access management (IAM)
    • Data protection and privacy concepts
  • Experience working in a hands‑on, SME or fast‑growing organization
  • Experience communicating policies and compliance requirements with both technical and non‑technical audiences at various levels in the organization.
  • Good experience in establishing and performing policy, standard and procedure assessment in a cloud‑based environment, technologies, and services.
  • Good experience defining, revising, and implementing corporate information security policies, standards, processes, guideline, and related regulatory expectations.
  • Familiarity with various industry frameworks and requirements including NIST framework, ISO 27001, PCI DSS, SOC 2, etc.
  • Passionate in ensuring the confidentiality, integrity, and availability of our critical assets and contributing to our organization's information security initiatives by applying your knowledge and attention to details.
  • Able to work and communicate well with different stakeholders.
  • Remains composed when decisions have to be made quickly.

Preferred:

  • Relevant certifications (any of the following):
    • CISSP, CISM, CISA
    • ISO 27001 Lead Implementer / Auditor
    • Security+, CEH, or equivalent
  • Experience with cloud security (AWS, Azure, or GCP)
  • Familiarity with security tools (SIEM, endpoint security, vulnerability scanners)
  • Good understanding of regulatory requirements in different markets the organization operates (e.g., MAS, HKMA, FSC, BNM, BSP, BOT).
  • Good understanding of security risk and compliance assessment, process, and procedures
  • Good to have Cybersecurity Fundamental certifications such as CompTIA Security+, ISC, etc
  • Able to develop and implement new and improved ways of doing work; encourage staff and guide organization and foster a positive security behavior and posture.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst Subject Matter Expert (SME) - Project-based
Information Security Analyst Subject Matter Expert (SME) - Project-based

Umpisa Inc. • Philippines

On-site
PHP 1,200,000 - 2,400,000
Senior Information Security SME & Risk Advisor
Senior Information Security SME & Risk Advisor

Umpisa Inc. • Hinoba-an

On-site
PHP 700,000 - 1,200,000
Information Security SME & Risk Advisory Lead
Information Security SME & Risk Advisory Lead

Umpisa Inc. • Philippines

On-site
PHP 1,200,000 - 2,400,000
IT Security QA
IT Security QA

Questronix Corporation • Pasig

On-site
PHP 800,000 - 1,200,000
Security Analyst
Security Analyst

Booth & Partners • Philippines

On-site
PHP 500,000 - 640,000
Information Security Analyst
Information Security Analyst

Satellite Office • Metro Manila

On-site
PHP 1,200,000 - 1,600,000
Information Security Officer
Information Security Officer

Ubiquity • Philippines

On-site
PHP 700,000 - 1,100,000
Security Analyst (Remote)
Security Analyst (Remote)

Prime System Solutions • Philippines

On-site
PHP 1,200,000 - 1,600,000
HMO coverage
Paid time off
Career development and certification
+2
Information Security Analyst
Information Security Analyst

Satellite Office • Pasig

Hybrid
PHP 1,000,000 - 2,000,000
NETWORK SECURITY ENGINEER
NETWORK SECURITY ENGINEER

Metrobank • Taguig

On-site