Risk and Internal Controls Analyst

AXA Asian Markets Services

Makati

On-site

PHP 600,000 - 900,000

Full time

18 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

AXA Asian Markets Services seeks a Risk and Internal Control Analyst to support IT, operational, compliance and security audits. The role evaluates controls, risks, and remediation actions to strengthen the technology risk framework.

The ideal candidate has a Bachelor’s degree in IT, Risk Management or related field and 2–5 years in IT risk, IT audit or information security, with hands-on control testing experience and knowledge of ITGC, ISO 27001, COBIT or NIST.

Qualifications

  • Bachelor’s degree or equivalent in IT, Risk, Cybersecurity or related discipline.
  • 2–5 years of experience in IT risk, IT audit, information security or similar analytical roles.
  • Hands-on experience with IT control testing, risk assessments, or security evaluations.
  • Good understanding of ITGC, security principles, and areas like access, change, and vulnerability management.
  • Knowledge of ISO 27001, COBIT, or NIST; relevant certifications (e.g., CISA, CISSP) are a plus.

Responsibilities

  • Support the planning and execution of IT, operations, security, and technology-related audits and assurance reviews.
  • Assess the design and operating effectiveness of controls (i.e., IT, Financial, Security, Compliance, etc.).
  • Document testing results, observations, and supporting evidence in accordance with internal control methodology.
  • Assist in identifying control deficiencies, root causes, risk implications, and opportunities for improvement.
  • Support the planning and execution of audits to critical third parties on security, operational resilience, data privacy and AI compliance topics.

Skills

Analytical thinking
Critical thinking
Problem solving
Attention to detail
Communication skills
Organizational skills
Project management
Integrity
Objectivity
Stakeholder collaboration

Education

Bachelor’s degree in IT, Risk Management, Cybersecurity or related discipline

Job description

Risk and Internal Control Analyst support the planning, execution, and reporting of IT, operational, compliance and security audit and assurance activities. The role evaluates the effectiveness of IT and operational controls, security processes, and risk management practices, identifies potential gaps and risks, and works with stakeholders to develop practical remediation actions.

The role will work closely with IT, Information Security, Risk, Compliance, and other business stakeholders to assess adherence to internal policies, control requirements, and applicable regulatory or industry standards.

Key Responsibilities:
Controls Evaluation and Assurance Activities
  • Support the planning and execution of IT, operations, security, and technology-related audits and assurance reviews.
  • Assess the design and operating effectiveness of controls (i.e., IT, Financial, Security, Compliance, etc.).
  • Perform testing of controls related to areas such as access management, change management, IT operations, backup and recovery, incident management, vulnerability management, and data protection.
  • Review IT processes, policies, procedures, system configurations, and supporting documentation to identify control weaknesses and potential risks.
  • Document testing results, observations, and supporting evidence in accordance with established internal control methodology.
  • Assist in identifying control deficiencies, root causes, risk implications, and opportunities for improvement.
  • Support the planning and execution of audits to critical third parties on security, operational resilience, data privacy and AI compliance topics.
  • Prepare clear and concise findings and recommendations for management.
  • Support the tracking and validation of remediation activities and management action plans, ensuring timely and effective closure.
Risk Assessment and Monitoring
  • Perform risk assessments for new and existing systems, applications, vendors and technology processes.
  • Support the development and maintenance of the risk register, ensuring risks are well-described, assessed and updated.
  • Monitor key risk indicators (KRIs) and provide insights on emerging risks or trends.
  • Prepare dashboards and reports highlighting risk insights for senior management.
Governance, Policies and Compliance
  • Assist in drafting, updating and reviewing IT policies, standards and procedures to align with regulatory, industry best practices and internal group policies.
  • Support compliance with applicable regulatory requirements and internal governance standards.
  • Contribute to periodic governance reporting and technology risk presentations.
  • Contribute to improving IT and security control frameworks, internal control methodologies, and assurance processes.
  • Identify opportunities to enhance the efficiency and effectiveness of control testing and monitoring.
  • Stay informed about emerging cybersecurity threats, technology risks, regulatory developments, and industry practices relevant to IT audit and security.
QUALIFICATIONS:
Education and Experience
  • Bachelor’s degree in IT, Accountancy, Risk Management, Cybersecurity or related discipline.
  • 2–5 years of experience in IT risk, IT audit, information security or similar analytical roles.
  • Hands-on experience with IT control testing, risk assessments, or security evaluations.
  • Good understanding of ITGC, security principles, and key areas like access, change, and vulnerability management.
  • Knowledge of frameworks such as ISO 27001, COBIT, or NIST; relevant certifications (e.g., CISA, CISSP) are a plus.
Skills and Competencies
  • Strong analytical, critical-thinking, and problem-solving abilities, with expertise in identifying control weaknesses and assessing their impact.
  • Excellent attention to detail, with a solid understanding of technology, cybersecurity risks, and audit evidence.
  • Effective communication skills—both written and verbal—and the ability to challenge processes constructively.
  • Strong organizational and project management capabilities, capable of handling multiple activities and deadlines independently.
  • High integrity, objectivity, and a proactive mindset focused on continuous improvement and stakeholder collaboration
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT, Security and Internal Control Audit Analyst
IT, Security and Internal Control Audit Analyst

Vertere Global Solutions, Inc. • Makati

On-site
PHP 600,000 - 820,000
Technology Controls Senior Analyst
Technology Controls Senior Analyst

Vault Outsourcing OPC • Muntinlupa

On-site
PHP 600,000 - 900,000
IT Audit - Assistant Manager
IT Audit - Assistant Manager

Nexus Recruitment Group • Makati

On-site
PHP 900,000 - 1,300,000
Risk and Compliance Analyst
Risk and Compliance Analyst

Kinect Incorporated • Manila

On-site
PHP 334,800 - 558,000
Consultant - Risk & Security Assessments (Lead Level)
Consultant - Risk & Security Assessments (Lead Level)

Nexus Recruitment Group • Makati

On-site
PHP 600,000 - 1,000,000
Technology Risk & Compliance Officer - BGC - Manila
Technology Risk & Compliance Officer - BGC - Manila

Dotco Pte. Ltd. • Taguig

On-site
PHP 1,200,000 - 1,900,000
IT Governance, Risk & Compliance (GRC) Analyst
IT Governance, Risk & Compliance (GRC) Analyst

Satellite Office • Taguig

On-site
PHP 420,000 - 660,000
Information Security Auditor / Security Compliance Specialist/ Security Analyst
Information Security Auditor / Security Compliance Specialist/ Security Analyst

Vertere Global Solutions, Inc. • Muntinlupa

On-site
PHP 800,000 - 1,100,000
IT Audit - Senior Manager
IT Audit - Senior Manager

Nexus Recruitment Group • Makati

On-site
PHP 2,000,000 - 3,200,000
Risk Analyst - IT
Risk Analyst - IT

Wonese Philippines • Quezon City

On-site
PHP 800,000 - 1,200,000