Information Security Specialist

Hammerjack Pty Ltd

Philippines

On-site

PHP 500,000 - 900,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

PLDT Group seeks a cybersecurity risk professional to determine risk posture for existing systems, products, and services, aligning with internal standards and regulatory requirements.

You will perform risk assessments across multiple projects, identify and mitigate security risks, and ensure timely remediation and documentation of findings and compliance activities.

Qualifications

  • Bachelor's degree in IT, CS, Engineering, or related field.
  • 4-5 years in analyst or cybersecurity roles.
  • Experience with risk assessments and regulatory compliance.

Responsibilities

  • Perform risk assessments for projects and initiatives across the PLDT Group.
  • Identify and mitigate security risks within defined risk tolerances.
  • Conduct security risk assessments per company standards and best practices.
  • Review project information to support cybersecurity risk assessments.
  • Analyze designs and architectures to identify vulnerabilities and recommend controls.
  • Create and monitor risk treatment plans and timelines.
  • Track remediation of vulnerabilities and ensure compliance before deployment.
  • Facilitate checkpoint meetings and document assessment results and reports.
  • Assess requests deviating from cybersecurity policies and standards.
  • Perform vulnerability scans and manage remediation reports.
  • Lead project risk assessments and maintain thorough records.

Skills

Information Security
IT & Cybersecurity
Regulatory Compliance
Risk Assessment
Cloud Security
Threat Intelligence

Education

Bachelor's degree

Job description

Determine the enterprise's cybersecurity risk posture for existing systems, products, and services across the PLDT Group, ensuring alignment with internal standards and full regulatory compliance.

Responsibilities
  • Perform risk assessments for multiple critical projects and initiatives involving new assets, technologies, products, and services across the PLDT Group.
  • Identify, assess, and mitigate security-related risks within Executive Management's defined risk tolerance levels.
  • Conduct security risk assessments and validations in accordance with company standards, processes, and industry best practices.
  • Gather and review project information, including scope, network architecture, data flow diagrams, evidence, and artifacts to support cybersecurity risk assessments.
  • Analyze solution designs, data flow diagrams, and network architecture diagrams to identify vulnerabilities and recommend security controls.
  • Create and monitor risk treatment plans, including risk findings, mitigation controls, residual risks, and implementation timelines.
  • Track implementation of risk treatments and cybersecurity compliance requirements before production deployment or launch.
  • Facilitate regular checkpoint meetings with project teams and document assessment results, compliance status, and reports.
  • Assess requests that deviate from cybersecurity policies and standards, including non-standard internet access, application access, local administrator rights, and VPN access requests.
  • Perform vulnerability scans on project-related applications, servers, and assets.
  • Track and coordinate remediation of identified vulnerabilities and produce vulnerability management reports.
  • Lead project risk assessment activities, facilitate meetings, ensure timely completion of deliverables, and maintain accurate project records and documentation.
Qualifications
Education
  • Bachelor's Degree in Information Technology, Computer Science, Engineering, or any related course/discipline.
Work Experience
  • 4-5 years of experience as an Analyst, Specialist, or related role within Information Technology or Cybersecurity.
Skills & Knowledge
  • Experience in Information Security, Information Technology, Telecommunications Technology, Information Systems Audit, Operational Risk, Process and Policy Development, or Regulatory Compliance.
  • Knowledge of cloud service models (IaaS, PaaS, SaaS) and associated security services.
  • Familiarity with security technologies and solutions.
  • Understanding of common cyber threats, including DDoS, brute-force attacks, SQL injection, and malware infections.
  • Knowledge of risk assessment frameworks and methodologies, cybersecurity frameworks, cybersecurity tools, technology risk, laws and regulations impacting technology-driven businesses, on-premise and cloud infrastructure, project management, and requirements analysis.
Preferred Certifications
  • CISA, CISM, CRISC, Security+, CISSP, CEH, or similar industry-recognized certifications.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Risk Assessment Specialist
Cyber Security Risk Assessment Specialist

PLDT • Makati

On-site
PHP 600,000 - 900,000
Specialist - Threat Intel and Incident Investigation
Specialist - Threat Intel and Incident Investigation

Smart Communications, Inc. • Makati

On-site
PHP 600,000 - 1,000,000
Cybersecurity Incident Investigation Information Security Sr. Specialist
Cybersecurity Incident Investigation Information Security Sr. Specialist

Smart Communications, Inc. • Makati

On-site
PHP 400,000 - 800,000
Cybersecurity Risk and Compliance Specialist | Global Services Center
Cybersecurity Risk and Compliance Specialist | Global Services Center

Hammerjack Pty Ltd • Philippines

Hybrid
PHP 900,000 - 1,500,000
Information Security Analyst Subject Matter Expert (SME) - Project-based
Information Security Analyst Subject Matter Expert (SME) - Project-based

Umpisa Inc • Makati

On-site
PHP 900,000 - 1,200,000
Information Security and Data Protection Specialist
Information Security and Data Protection Specialist

SYCiP SECROU HERNANDEZ & GATMAITAN • Philippines

On-site
PHP 600,000 - 1,000,000
Threat Intel & Incident Investigation Specialist
Threat Intel & Incident Investigation Specialist

Smart Communications, Inc. • Makati

On-site
PHP 600,000 - 1,000,000
IT Security QA
IT Security QA

Questronix Corporation • Pasig

On-site
PHP 800,000 - 1,200,000
Information Security Analyst Subject Matter Expert (SME) - Project-based
Information Security Analyst Subject Matter Expert (SME) - Project-based

Umpisa Inc. • Hinoba-an

On-site
PHP 700,000 - 1,200,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Santo Niño 1st

On-site
PHP 1,200,000 - 1,800,000