IT Vendor Security Analyst

HRTX

Santa Rosa

On-site

PHP 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Verizon is seeking an IT Vendor Security Analyst to oversee third-party security assurance programs across supplier lifecycles, from onboarding through termination, with hands-on duties at supplier sites. You’ll review physical and logical controls and monitor risk and compliance, driving remediation with stakeholders.

You will conduct vulnerability assessments, investigate incidents, and ensure alignment with security standards, policies, and ISO-like controls across global supplier engagements.

Qualifications

  • Bachelor's degree or four or more years of work experience.
  • 4 or more years of relevant work experience in Physical Security, Information Security, Cybersecurity, Insider threat or related Security discipline.
  • 3 or more years of working experience in IT network security, risk management, vulnerability assessment, security breach investigation, ethical hacking, forensics investigation.

Responsibilities

  • Conduct regular security reviews and assessments of the Physical and Logical controls in place at a Secured Work Space at the Supplier facility
  • Identify Risks and Vulnerabilities in the overall Security infrastructure in place and ensuring the ongoing protection of assets and sensitive customer information
  • Drawing up test procedures to assess the effectiveness of the security controls in place
  • Assessing Risks and recommend effective controls to protect Verizon projects
  • Performing Event / Security Logs monitoring and Session monitoring
  • Reporting findings to the respective stakeholders and follow up for timely remediation / closure
  • Work with Leadership, Suppliers and Business to address security concerns
  • Establishing, implementing, and communicating Cybersecurity and Information Security Standards, Policies, Procedures and Tests
  • Conduct Investigations for reported possible violations and security breaches
  • Collaborating with Verizon Business and Support teams and work towards ensuring the required process are in place from a risk and compliance standpoint
  • Providing analytical and technical support to solve a wide range of complex security issues and to support projects within a functional area
  • Driving the Supplier Information Security Program to evaluate Suppliers Security practice in order to gauge security posture and readiness to support the business

Skills

Security reviews
Risk assessment
Incident reporting
Collaboration
Security standards

Education

Bachelor's degree or equivalent in related field
Active Security+ certification
CISSP/CISA/CISM certification

Job description

About the job IT Vendor Security Analyst

The Third-Party Security (TPS) enables the business by proactively identifying, assessing, and mitigating security risks.Protects the confidentiality, integrity, and availability of Verizon assets through robust security standards, rigorous due diligence, andcontinuous oversight. By using adaptive security monitoring and controls, we defend and protect against potential cyber and security threats and ensurealignment with evolving regulatory and industry requirements. Sustain a resilient and trusted environment, empowering our stakeholders to operatesecurely and confidently in an increasingly complex digital world.

This position will focus on the Third-Party Security Assurance programs throughout the various phases of the Supplier lifecycle, from onboarding throughtermination and will be based out of a Supplier location supporting the project. You will be integrated with the business operations performingcontinuous scheduled security activities to identify and monitor for threats, vulnerabilities, non-compliance and other areas that may elevate risk in directsupport of the business. You will be responsible and accountable for reviewing the Physical and Logical controls implemented at the SecuredWork Space at the Supplier facility.

  • Conducting regular security reviews and assessments of the Physical and Logical controls in place at a Secured Work Space at the Supplier facility
  • Identify Risks and Vulnerabilities in the overall Security infrastructure in place and ensuring the ongoing protection of assets and sensitive customer information
  • Drawing up test procedures to assess the effectiveness of the security controls in place
  • Assessing Risks and recommend effective controls to protect Verizon projects
  • Performing Event / Security Logs monitoring and Session monitoring
  • Reporting findings to the respective stakeholders and follow up for timely remediation / closure
  • Work with Leadership, Suppliers and Business to address security concerns
  • Establishing, implementing, and communicating Cybersecurity and Information Security Standards, Policies, Procedures and Tests
  • Conduct Investigations for reported possible violations and security breaches
  • Collaborating with Verizon Business and Support teams and work towards ensuring the required process are in place from a risk and
  • compliance standpoint
  • Providing analytical and technical support to solve a wide range of complex security issues and to support projects within a functional area
  • Driving the Supplier Information Security Program to evaluate Suppliers Security practice in order to gauge security posture and readiness to support the business

What we're looking for:

You understand the importance of information security for companies and their customers and appreciate the magnitude of the risk of emerging security threats to their reputations and businesses. Identifying risks or gaps in controls and analyzing and solving complex problems comes easily to you. You have a knack for conveying difficult messages to people at all levels, and you are willing to take a stand on important issues. You are self-motivated and you work well independently and with teams to achieve outstanding results.

  • Bachelor's degree or four or more years of work experience.
  • 4 or more years or relevant work experience in Physical Security, Information Security, Cybersecurity, Insider threat or related Security discipline.
  • 3 or more years of working experience in IT network security, risk management, vulnerability assessment, security breach investigation, ethical hacking, forensics investigation.

Even better if you have one or more of the following:

  • Professional certifications such as Active Security+, CISSP, CISA, CISM, CFE, or CEH.
  • Experience with network security, risk management, vulnerability assessment, security breach investigation, PCI DSS, ethical hacking, forensics investigation, ITIL, or COBIT frameworks.
  • Experience in cybersecurity, information security, or information assurance position including security verification, or security validation, or security audit based on ISO standards.
  • Experience with a broad range of security solutions to address complex control scenarios.
  • Project management and experience with risks associated with global operations, offshoring, or outsourcing.
  • Experience in physical security reviews and dealing with varying levels of user groups, senior executives, and technical personnel.
  • Attended training and security conferences, chairing forums, writing security/technical books and/or similar web content.
  • Demonstrated understanding of cyber security risk management concepts, cybersecurity frameworks, control standards, secure coding principles, and security technologies.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vendor Security Assurance Analyst
Vendor Security Assurance Analyst

HRTX • Santa Rosa

On-site
PHP 1,200,000 - 1,800,000
IT Security - Third Party Risk Management Specialist
IT Security - Third Party Risk Management Specialist

Socium - Teams Done Differently • Mandaluyong

Hybrid
PHP 900,000 - 1,300,000
Hybrid work arrangement
Career growth opportunities
Competitive compensation package
+1
Third Party Risk Management - IT Security Specialist
Third Party Risk Management - IT Security Specialist

John Clements Consultants, Inc. • Mandaluyong

On-site
PHP 800,000 - 1,200,000
Cybersecurity Analyst
Cybersecurity Analyst

ContactPoint360 • Cebu City

On-site
PHP 900,000 - 1,300,000
Third Party Vendor Analyst
Third Party Vendor Analyst

GR8 Global Philippines • Philippines

Hybrid
PHP 600,000 - 900,000
Information Security Analyst
Information Security Analyst

Satellite Office • Metro Manila

On-site
PHP 1,200,000 - 1,600,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
SOC Analyst
SOC Analyst

HRTX • Philippines

On-site
PHP 600,000 - 900,000
Associate Specialist, Governance, Risk and Compliance
Associate Specialist, Governance, Risk and Compliance

Concentrix • Angeles

On-site
PHP 600,000 - 900,000