On-site - Mandaluyong 1-3 Yrs Exp Bachelor Full-time
Government Mandated Benefits
QUALIFICATIONS
- Education: Bachelor’s degree in Information Technology, Computer Science, Engineering, or related field.
- Experience: 1–2 years of experience in IT service operations, ITSM, or governance, risk and compliance role.
- At least one (1) year experience performing enterprise IT risk assessments based on ISO 31000.
- At least one (1) year experience conducting vendor security assessments based on ISO27001:2013.
- Experience coordinating with managed service providers and third-party vendors.
- Experience creating service bulletins and presentation materials (PowerPoint) to support incident communication, change awareness, and operational reporting.
- Certifications (Preferred): ITIL Foundation certification is preferred.
SKILLS AND COMPETENCIES
- Working knowledge of IT service management (ITSM) processes, including Incident, Problem, Change, and Service Level Management, and their impact on operational stability and risk.
- Ability to remain effective under pressure while supporting incidents and major incident response through clear communication, structured coordination, and adherence to established procedures.
- Strong analytical and problem‑solving skills, with experience supporting root cause analysis, identifying recurring incident trends, and assessing risk and control effectiveness.
- Skilled in performing, documenting, and maintaining governance, risk, and compliance (GRC) activities, including risk assessments, control evaluations, and remediation tracking.
- General working knowledge of information security governance frameworks (e.g., COBIT) and compliance practices supporting ISMS implementation and operation.
- Understanding of common information security standards and regulatory requirements, such as the Data Privacy Act of 2012, ISO 27001, PCI‑DSS, SOC 1, and SOC 2.
- Familiarity with ITSM and GRC tools (e.g., ServiceNow, Jira) and the use of basic service performance, risk, and compliance metrics and reporting.
DUTIES & RESPONSIBILITIES
Governance, Risk, and Compliance (GRC)
- Implement and support information security controls, risk assessment frameworks, and compliance programs aligned with regulatory and corporate requirements, ensuring documented and sustainable compliance that supports business objectives.
- Evaluate IT and information security risks and assist in the development, maintenance, and implementation of security policies, standards, procedures, and controls.
- Support the Information Security Management System (ISMS) by maintaining governance documentation, policies, standards, and control mappings aligned with frameworks such as ISO 27001, NIST, and PCI.
- Support third‑party and vendor security governance by assisting in the definition and enforcement of security requirements for vendors, suppliers, contractors, partners, and other external parties.
- Ensure compliance with Company policies (including information security), processes, and procedures.
Risk Assessment, Monitoring, and Analysis
- Participate in conducting information security and IT risk assessments in accordance with established risk management methodologies and frameworks.
- Implement and support processes to automate and continuously monitor information security controls, exceptions, risks, and testing activities.
- Assist in analyzing security‑related activities and assessment results, including incidents, vulnerability scans, patching status, secure configuration baselines, penetration test results, phishing simulations, and social engineering tests.
- Assess risks associated with third‑party services and system implementations, including risks introduced through system development, acquisition, and procurement activities.
- Identify control weaknesses, gaps, and non‑compliance issues requiring remediation.
Reporting, Metrics, and Remediation Tracking
- Document and report control failures, risk issues, and compliance gaps to IT Management.
- Prepare recommendations and maintain documentation to track remediation plans, corrective actions, and closure status.
- Assist in creating reports, dashboards, and GRC metrics for presentation to IT Management and other stakeholders.
- Develop, maintain, and manage evidence artifacts required for ISMS activities, audits, third‑party reviews, and management reporting.
- Track remediation progress related to audit findings, risk assessments, third‑party reviews, and secure system implementation activities.
Awareness and Capability Development
- Support ISMS and audit readiness activities by assisting with internal compliance assessments, audit preparation, and coordination with internal and external auditors.
- Support certification and accreditation activities by ensuring required security controls, assessments, and documentation are completed prior to releasing new systems into production.
- Assist in implementing and maintaining security controls across the system development and procurement lifecycle, supporting secure SDLC practices.
- Develop and deliver information security awareness materials using appropriate technologies to enhance effectiveness and retention.
- Keep abreast of developments in IT risk management frameworks, information security standards, secure SDLC practices, and awareness methodologies to continuously improve governance and security capabilities.
Communication
- Liaise with MISD Groups and Vendors on service availability, planned changes, and operational risks.
- Communicate planned outages, incident updates, and change‑related impacts to users in a clear and timely manner using approved messaging.
- Translate technical issues into business‑relevant terms for MISD Management.
- Identify recurring issues, service gaps, and opportunities to improve service reliability and operational efficiency.
- Support process improvements through accurate documentation, knowledge base updates, and adherence to standard procedures.
- Contribute operational feedback to support service readiness and continuous improvement initiatives.