IT Security Risk Assessment Officer

Metropolitan Bank & Trust Company

Metro Manila

On-site

PHP 900,000 - 1,200,000

Full time

30 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Metropolitan Bank & Trust Company is seeking a Security Assurance and Assessment Officer in Metro Manila to lead third-party and system risk assessments and strengthen information security controls. You will develop risk frameworks, coordinate with business units, and produce actionable risk reports to guide mitigation actions.

The role requires a Bachelor's degree and experience in IT controls, auditing, and risk assessments, with familiarization in security best practices and relevant

Qualifications

  • Bachelor's degree in a relevant field
  • Experience in IT general controls, auditing, and system security risk assessments
  • Strong understanding of risk assessment and ability to evaluate and prioritize security risks
  • Able to analyze business risks and clearly explain recommendations and trade-offs
  • Experience in project security reviews and risk assessments
  • Strong analytical skills with the ability to identify risks and recommend appropriate actions
  • Updated knowledge of security best practices and emerging threats
  • Relevant certifications (e.g., CISA, CISM, CRISC, PCI-DSS, ISO 27001) are a plus

Responsibilities

  • Develop and implement plans for conducting information security, third-party, and system risk assessments.
  • Identify critical assets, threats, and vulnerabilities, and evaluate the effectiveness of existing security controls.
  • Assess and monitor the security performance of third-party vendors handling client data.
  • Perform threat modeling and risk assessments for IT systems and assets.
  • Evaluate the impact of process changes, system upgrades, and third-party engagements on security risks.
  • Review and ensure adequate controls are in place to protect the confidentiality, integrity, and availability of information.
  • Recommend and help develop information security policies and procedures based on assessment results.
  • Coordinate with business units and stakeholders to gather information for risk assessments.
  • Prepare and communicate risk assessment reports, including findings and recommended mitigation actions.
  • Track and follow up on risk mitigation activities and maintain an updated risk register.

Skills

IT general controls
Auditing
Security risk assessments
Risk prioritization
Stakeholder communication
Threat modeling
Project security reviews
Analytical skills

Education

Bachelor's degree in a relevant field

Job description

About the role

The Security Assurance and Assessment Officer is responsible for developing and maintaining the bank's third-party information security risk management framework, ensuring it aligns with the overall enterprise risk strategy. This role conducts security risk assessments on third parties, systems, applications, and information assets. It reviews processes, systems, and network security controls to identify potential risks and recommend appropriate mitigation strategies. The officer also evaluates the security of production environments and provides recommendations to protect the confidentiality, integrity, and availability of the bank's information, systems, and services.

Key responsibilities
  • Develop and implement plans for conducting information security, third-party, and system risk assessments.

  • Identify critical assets, threats, and vulnerabilities, and evaluate the effectiveness of existing security controls.

  • Assess and monitor the security performance of third-party vendors handling client data.

  • Perform threat modeling and risk assessments for IT systems and assets.

  • Evaluate the impact of process changes, system upgrades, and third-party engagements on security risks.

  • Review and ensure adequate controls are in place to protect the confidentiality, integrity, and availability of information.

  • Recommend and help develop information security policies and procedures based on assessment results.

  • Coordinate with business units and stakeholders to gather information for risk assessments.

  • Prepare and communicate risk assessment reports, including findings and recommended mitigation actions.

  • Track and follow up on risk mitigation activities and maintain an updated risk register.

Qualification
  • Bachelor's degree in a relevant field

  • Experience in IT general controls, auditing, and system security risk assessments

  • Strong understanding of risk assessment and the ability to evaluate and prioritize security risks

  • Able to analyze business risks and clearly explain recommendations and trade-offs

  • Experience in project security reviews and risk assessments

  • Strong analytical skills with the ability to identify risks and recommend appropriate actions

  • Updated knowledge of security best practices and emerging threats

  • Relevant certifications (e.g., CISA, CISM, CRISC, PCI-DSS, ISO 27001) are a plus

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Risk Assessment Officer
IT Security Risk Assessment Officer

Metrobank • Philippines

On-site
PHP 650,000 - 900,000
SECURITY ASSURANCE AND ASSESSMENT OFFICER
SECURITY ASSURANCE AND ASSESSMENT OFFICER

Metrobank • Taguig

On-site
PHP 600,000 - 800,000
Opportunities for professional development
Community contribution initiatives
Risk and Security Assessment Consultant
Risk and Security Assessment Consultant

HRTX • Philippines

On-site
PHP 600,000 - 900,000
Third Party Risk Management - IT Security Specialist
Third Party Risk Management - IT Security Specialist

John Clements Consultants, Inc. • Mandaluyong

On-site
PHP 800,000 - 1,200,000
Strategic Information Security Risk Lead
Strategic Information Security Risk Lead

Metrobank • Philippines

On-site
PHP 650,000 - 900,000
IT Risk & Security Assessment Consultant
IT Risk & Security Assessment Consultant

HRTX • Philippines

On-site
PHP 1,200,000 - 2,100,000
IT Security Operations Analyst
IT Security Operations Analyst

CTBC Bank (Philippines) Corp. • Metro Manila

On-site
PHP 1,004,000 - 1,562,000
IT Information Security Manager
IT Information Security Manager

Manila Water Philippine Ventures • Philippines

On-site
PHP 1,200,000 - 1,800,000
Junior InfoSec Risk & Assurance Officer
Junior InfoSec Risk & Assurance Officer

Metrobank • Taguig

On-site
PHP 600,000 - 800,000
Opportunities for professional development
Community contribution initiatives
Cybersecurity Consultant (Risk & Security Assessment)
Cybersecurity Consultant (Risk & Security Assessment)

HRTX • Philippines

On-site
PHP 800,000 - 1,200,000