Get more replies from employers
Send a job-specific resume in minutes.
Metropolitan Bank & Trust Company is seeking a Security Assurance and Assessment Officer in Metro Manila to lead third-party and system risk assessments and strengthen information security controls. You will develop risk frameworks, coordinate with business units, and produce actionable risk reports to guide mitigation actions.
The role requires a Bachelor's degree and experience in IT controls, auditing, and risk assessments, with familiarization in security best practices and relevant
The Security Assurance and Assessment Officer is responsible for developing and maintaining the bank's third-party information security risk management framework, ensuring it aligns with the overall enterprise risk strategy. This role conducts security risk assessments on third parties, systems, applications, and information assets. It reviews processes, systems, and network security controls to identify potential risks and recommend appropriate mitigation strategies. The officer also evaluates the security of production environments and provides recommendations to protect the confidentiality, integrity, and availability of the bank's information, systems, and services.
Develop and implement plans for conducting information security, third-party, and system risk assessments.
Identify critical assets, threats, and vulnerabilities, and evaluate the effectiveness of existing security controls.
Assess and monitor the security performance of third-party vendors handling client data.
Perform threat modeling and risk assessments for IT systems and assets.
Evaluate the impact of process changes, system upgrades, and third-party engagements on security risks.
Review and ensure adequate controls are in place to protect the confidentiality, integrity, and availability of information.
Recommend and help develop information security policies and procedures based on assessment results.
Coordinate with business units and stakeholders to gather information for risk assessments.
Prepare and communicate risk assessment reports, including findings and recommended mitigation actions.
Track and follow up on risk mitigation activities and maintain an updated risk register.
Bachelor's degree in a relevant field
Experience in IT general controls, auditing, and system security risk assessments
Strong understanding of risk assessment and the ability to evaluate and prioritize security risks
Able to analyze business risks and clearly explain recommendations and trade-offs
Experience in project security reviews and risk assessments
Strong analytical skills with the ability to identify risks and recommend appropriate actions
Updated knowledge of security best practices and emerging threats
Relevant certifications (e.g., CISA, CISM, CRISC, PCI-DSS, ISO 27001) are a plus