IT, Security and Internal Control Audit Analyst

Vertere Global Solutions, Inc.

Makati

On-site

PHP 600,000 - 820,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Vertere Global Solutions, Inc. is seeking an IT, Security and Internal Control Audit Analyst to identify risks, strengthen controls, and partner with key teams.

You will plan and execute IT, information security, and technology audits; assess ITGC and security controls; document findings and support remediation; and contribute to governance and risk reporting.

Qualifications

  • Bachelor’s degree in IT, Cybersecurity, Audit, Risk Management, or related discipline.
  • 2–5 years of experience in IT audit, information security, controls, or cybersecurity.
  • Hands-on experience with IT control testing, risk assessments, or security evaluations.
  • Knowledge of ITGC, security principles, and key areas like access, change, and vulnerability management.
  • Certifications such as CISA or CISSP are a plus.

Responsibilities

  • Support the planning and execution of IT, information security, and technology-related audits and assurance reviews.
  • Assess the design and operating effectiveness of IT general controls and security controls.
  • Perform testing of controls related to access management, change management, IT operations, backup and recovery, incident management, vulnerability management, and data protection.
  • Review IT processes, policies, procedures, system configurations, and supporting documentation to identify control weaknesses and potential risks.
  • Document testing results, observations, and supporting evidence in accordance with established internal control methodology.
  • Assist in identifying control deficiencies, root causes, risk implications, and opportunities for improvement.
  • Prepare clear and concise findings and recommendations for management.
  • Support the tracking and validation of remediation activities and management action plans, ensuring timely and effective closure.
  • Prepare risk assessments for new and existing systems, applications, vendors and technology processes.
  • Support the development and maintenance of the risk register, ensuring risks are well-described, assessed and updated.
  • Monitor KRIs and provide insights on emerging risks or trends.
  • Prepare dashboards and reports highlighting risk insights for senior management.
  • Assist in drafting, updating and reviewing IT policies, standards and procedures to align with regulatory, industry best practices and internal group policies.
  • Support compliance with applicable regulatory requirements and internal governance standards.
  • Contribute to periodic governance reporting and technology risk presentations.
  • Contribute to improving IT and security control frameworks, internal control methodologies, and assurance processes.
  • Identify opportunities to enhance the efficiency and effectiveness of control testing and monitoring.
  • Stay informed about emerging cybersecurity threats, technology risks, regulatory developments, and industry practices relevant to IT audit and security.

Skills

IT audit
Information security
Cybersecurity
Risk management
Data protection
Regulatory knowledge
Communication skills
Analytical thinking
Problem-solving
Stakeholder collaboration

Education

Bachelor’s degree in IT, Cybersecurity, Audit, Risk Management, or related discipline

Job description

Make an impact as an IT, Security and Internal Control Audit Analyst by identifying risks, strengthening controls, and partnering with key teams to protect the organization.

IT & Security Controls Evaluation and Assurance Activities
  • Support the planning and execution of IT, information security, and technology-related audits and assurance reviews.
  • Assess the design and operating effectiveness of IT general controls and security controls.
  • Perform testing of controls related to areas such as access management, change management, IT operations, backup and recovery, incident management, vulnerability management, and data protection.
  • Review IT processes, policies, procedures, system configurations, and supporting documentation to identify control weaknesses and potential risks.
  • Document testing results, observations, and supporting evidence in accordance with established internal control methodology.
  • Assist in identifying control deficiencies, root causes, risk implications, and opportunities for improvement.
  • Prepare clear and concise findings and recommendations for management.
  • Support the tracking and validation of remediation activities and management action plans, ensuring timely and effective closure.
Risk Assessment and Monitoring:
  • Perform risk assessments for new and existing systems, applications, vendors and technology processes.
  • Support the development and maintenance of the risk register, ensuring risks are well-described, assessed and updated.
  • Monitor key risk indicators (KRIs) and provide insights on emerging risks or trends.
  • Prepare dashboards and reports highlighting risk insights for senior management.
Governance, Policies and Compliance:
  • Assist in drafting, updating and reviewing IT policies, standards and procedures to align with regulatory, industry best practices and internal group policies.
  • Support compliance with applicable regulatory requirements and internal governance standards.
  • Contribute to periodic governance reporting and technology risk presentations.
Continuous Improvement
  • Contribute to improving IT and security control frameworks, internal control methodologies, and assurance processes.
  • Identify opportunities to enhance the efficiency and effectiveness of control testing and monitoring.
  • Stay informed about emerging cybersecurity threats, technology risks, regulatory developments, and industry practices relevant to IT audit and security.
Education and Experience
  • Bachelor’s degree in IT, Cybersecurity, Audit, Risk Management, or related discipline.
  • 2–5 years of experience in IT audit, information security, controls, or cybersecurity.
  • Hands‑on experience with IT control testing, risk assessments, or security evaluations.
  • Good understanding of ITGC, security principles, and key areas like access, change, and vulnerability management.
  • Knowledge of frameworks such as ISO 27001, COBIT, or NIST; relevant certifications (e.g., CISA, CISSP) are a plus.
Skills and Competencies
  • Strong analytical, critical‑thinking, and problem‑solving abilities, with expertise in identifying control weaknesses and assessing their impact.
  • Excellent attention to detail, with a solid understanding of technology, cybersecurity risks, and audit evidence.
  • Effective communication skills—both written and verbal—and the ability to challenge processes constructively.
  • Strong organizational and project management capabilities, capable of handling multiple activities and deadlines independently.
  • High integrity, objectivity, and a proactive mindset focused on continuous improvement and stakeholder collaboration.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Technology Auditor
Information Technology Auditor

ACCLIME RISK ADVISORY PTE. LTD. • Santo Niño 1st

On-site
PHP 600,000 - 900,000
IT Audit and Compliance Specialist
IT Audit and Compliance Specialist

CPS Asia Pacific • Metro Manila

On-site
PHP 900,000 - 1,200,000
Technology Controls Senior Analyst
Technology Controls Senior Analyst

Vault Outsourcing OPC • Muntinlupa

On-site
PHP 600,000 - 900,000
Information Technology Auditor
Information Technology Auditor

City Savings Bank • Pasig

On-site
PHP 600,000 - 1,000,000
IT Audit Senior Manager
IT Audit Senior Manager

PM Consulting • Pasig

On-site
PHP 1,800,000 - 3,000,000
IT Compliance Analyst
IT Compliance Analyst

Satellite Office • Pasig

On-site
PHP 700,000 - 1,000,000
IT Auditor - 3yrs exp - Sal: 24k - 27k
IT Auditor - 3yrs exp - Sal: 24k - 27k

Dempsey Resource Management • San Juan

On-site
PHP 420,000 - 860,000
Information System Auditor
Information System Auditor

City Savings Bank • Pasig

On-site
PHP 520,000 - 900,000
IT AUDIT OFFICER
IT AUDIT OFFICER

City Government of Muntinlupa - Government • Muntinlupa

On-site
PHP 600,000 - 900,000
IT Audit Specialist
IT Audit Specialist

Macroasia Corporation • Makati

On-site
PHP 600,000 - 1,000,000