MariBank Philippines, Inc. in Metro Manila is seeking a qualified professional for Information Security Risk Management. The successful candidate will conduct enterprise-wide security risk assessments, ensure compliance with security policies, and manage risks associated with third-party vendors. A minimum of 3 years of relevant experience in information security is required, along with a strong understanding of security standards like ISO 27001, NIST, and PCI DSS. The role requires candidates to be amenable to work in Ortigas, Mandaluyong City.
Qualifications
At least 3 years of relevant work experience in Information Security Risk and related functions.
Certification or training with information security risk, audit, or other security-related is a plus.
Amenable to work in Ortigas, Mandaluyong City.
Responsibilities
Conduct enterprise-wide security risk assessments and maintain a risk register.
Review security posture of vendors through questionnaires and audits.
Develop and enforce security policies and standards.
Identify IT system vulnerabilities and recommend remedial actions.
Present risk data and strategies to management.
Provide security awareness training to employees.
Skills
Information Security Risk Management
Third-Party Risk Management
Security Policy Compliance
Vulnerability Assessment
Security Awareness Training
Education
Certification or training in Information Security
Job description
Job Description
Risk Identification and Assessment: Conducting enterprise-wide security risk assessments, maintaining a risk register, and evaluating the likelihood and impact of potential security threats.
Third-Party Risk Management: Reviewing security posture of vendors and partners through questionnaires and audits (e.g., SOC reports)
Security Policy Compliance: Developing and enforcing security policies, standards, and best practices to ensure compliance with regulatory requirements. Familiarity or experience with ISO 27001, NIST, PCI DSS, and / or local BSP regulations.
Vulnerability Assessment and Mitigation: Identifying IT system vulnerabilities, analyzing risk level, and recommending remedial action to technical teams.
Reporting and Communication: Presenting risk data, metrics, and mitigation strategies to management and leadership teams.
Security Education: Providing security awareness training to employees, such as phishing simulations and training sessions
Requirements
At least 3 years of relevant work experience in Information Security Risk and other related-functions
Certification or training with information security risk, audit, or any information security-related is a plus