Information Technology Governance Analyst

RBox International Solutions Inc.

Philippines

On-site

PHP 600,000 - 900,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RBox International Solutions Inc. is seeking a Security GRC Analyst to support IT governance, risk, and compliance. This role centers on SOC 2 readiness and remediation while operating the security program across Microsoft 365, Azure, and internal platforms.

You will work closely with engineering, IT admins, and business teams to strengthen controls, investigate alerts, and help mature the organization’s security posture over time.

Qualifications

  • 4 to 6 years experience in IT governance, GRC, security operations, or IT risk management.
  • Experience supporting SOC 2, ISO 27001, or similar security frameworks.
  • Experience investigating security alerts or supporting incident response activities.
  • Working knowledge of identity and access management, vulnerability management, and security monitoring processes.
  • Familiarity with Microsoft 365 security features, Entra ID, and Azure environments.
  • Strong documentation, investigation, and communication skills.

Responsibilities

  • Monitor and triage alerts from MDR and other security monitoring tools.
  • Investigate suspicious activity or unusual behavior/patterns.
  • Document investigation findings, coordinate remediation actions with IT and engineering teams.
  • Support root cause analysis and corrective actions following security incidents.
  • Maintain investigation records and evidence to support security monitoring controls.
  • Assist with remediation of SOC 2 control gaps and readiness activities for the upcoming audit.
  • Map remediation tasks to SOC 2 control objectives and track implementation progress in Azure DevOps.
  • Draft, revise, and operationalize policies and SOPs related to information security and governance.
  • Maintain the control library, RACI assignments, and governance review calendar in SharePoint.
  • Assist with insider risk monitoring and improvements in monitoring, detection, and response processes.

Skills

Security operations
Governance
Incident investigation
Documentation
Communication

Tools

Azure DevOps
Microsoft 365 security
Entra ID

Job description

As a Security GRC Analyst, you will support and operate key security and governance processes within the IT department. Reporting to the Senior Director of IT, this role combines security operations, governance execution, and compliance readiness. The immediate focus is assisting with SOC 2 readiness and remediation while helping operate the company's security program across Microsoft 365, Azure, and internal platforms.

This role is ideal for a security-focused analyst who enjoys investigating alerts, improving security controls, and strengthening governance processes. You will work closely with engineering, IT administrators, and business teams to ensure security controls operate effectively and that the organization continues to mature its security posture over time.

Key Responsibilities:
Security operations and incident investigation
  • Monitor and triage alerts from Arctic Wolf MDR and other security monitoring tools.
  • Investigate suspicious activity or unusual behavior/patterns.
  • Document investigation findings, coordinate remediation actions with IT and engineering teams, and track closure of security issues.
  • Support root cause analysis and corrective actions following security incidents.
  • Maintain investigation records and evidence to support security monitoring controls.
SOC 2 readiness and remediation
  • Assist with remediation of SOC 2 control gaps and readiness activities for the upcoming audit.
  • Map remediation tasks to SOC 2 control objectives and track implementation progress in Azure DevOps.
  • Coordinate with control owners to implement and test controls.
  • Build and maintain audit evidence repositories with traceability from policy to procedure to operational artifacts.
  • Participate in internal readiness reviews and assist with auditor requests.
Policy, controls, and governance operations
  • Draft, revise, and operationalize policies and SOPs related to information security, access control, change management, incident response, acceptable use, and business continuity.
  • Maintain the control library, RACI assignments, and governance review calendar in SharePoint.
  • Ensure policies and procedures remain aligned with SOC 2 and internal operational practices.
Insider risk monitoring and security posture improvement
  • Support the development of insider risk monitoring processes and investigations.
  • Assist with identifying abnormal internal behavior patterns that may indicate security or data protection concerns.
  • Contribute to improvements in monitoring, detection, and security response processes.
Qualifications:
  • 4 to 6 years experience in IT governance, GRC, security operations, or IT risk management.
  • Experience supporting SOC 2, ISO 27001, or similar security frameworks.
  • Experience investigating security alerts or supporting incident response activities.
  • Working knowledge of identity and access management, vulnerability management, and security monitoring processes.
  • Familiarity with Microsoft 365 security features, Entra ID, and Azure environments.
  • Strong documentation, investigation, and communication skills.
  • Experience collaborating with both technical teams and business stakeholders.
Why Join Us?
  • Competitive compensation and benefits package.
  • Integral role in a highly stable team within a rapidly growing company.
  • Opportunities for professional development and career progression.
  • Emphasis on work-life balance as a core element of our culture.
  • Involvement in cutting-edge projects leveraging the latest cloud technologies.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance and Information Security Analyst
Governance and Information Security Analyst

InnovaThink Corporation • Metro Manila

On-site
PHP 800,000 - 1,200,000
Information Security Architect
Information Security Architect

KMC Solutions • Metro Manila

On-site
PHP 1,200,000 - 1,800,000
Cyber Security Specialist
Cyber Security Specialist

Sterling Global Call Center, Inc. • Pasig

On-site
PHP 900,000 - 1,300,000
SOC 2 Readiness & Security GRC Analyst
SOC 2 Readiness & Security GRC Analyst

RBox International Solutions Inc. • Philippines

On-site
PHP 600,000 - 900,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Copeland India Private Ltd. • Quezon City

Hybrid
PHP 700,000 - 1,000,000
Flexible benefits plans
Paid parental leave
Vacation and holiday leave
Senior SOC Analyst: Advanced Incident Response
Senior SOC Analyst: Advanced Incident Response

Integrity360 • España

On-site
PHP 4,972,000 - 8,523,000
Cyber Governance, Risk and Compliance Specialist
Cyber Governance, Risk and Compliance Specialist

Virtual Business Partners Pty. Ltd. • Cebu City

On-site
PHP 800,000 - 1,200,000
HMO + Dental/Optical
Christmas vacation
Electricity & Data subsidies
+3
Senior Governance Risk and Compliance Analyst
Senior Governance Risk and Compliance Analyst

Permhunt • Metro Manila

On-site
Competitive salary
Benefit package
On-call support
L3 SOC Analyst - Madrid
L3 SOC Analyst - Madrid

Integrity360 • España

On-site
PHP 4,972,000 - 8,523,000
SOC Analyst
SOC Analyst

Scrubbed, Accounting that Matters • San Fernando

Hybrid
PHP 600,000 - 900,000