Risk and Security Assessment Consultant

HRTX

Philippines

On-site

PHP 600,000 - 900,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HRTX is seeking a Risk and Security Assessment Consultant to conduct security and risk assessments in a fast-paced environment, delivering timely, practical recommendations to mitigate identified risks.

The role follows industry standards (ISO 27001/2, NIST, CIS, PCI DSS, SWIFT CSP, CSA CCM) and regulatory requirements, and includes maturity assessments, discovery workshops, client presentations, and security training across IT and business units.

Qualifications

  • Over 3 years of experience in Information Technology.
  • Holds 23 years of specific experience in security assessments, including Cloud Security Assessment, Third Party Security Risk Assessments, ISMS/NIST Assessment, SOC 2 Type 2 Assessment, RCSA, Configuration Review, Architecture Review, and Controls Review (must have).
  • Facilitated at least one IT Risk Assessment project.
  • Experience with Data Privacy frameworks such as PDPA, GDPR, and the Data Privacy Act of 2012.
  • Experience in Security Awareness and Training initiatives.
  • At least 1 year of consulting or advisory engagement experience (preferred).
  • Strong knowledge in IT Audit/Assessments and Maturity Assessments.
  • Strong knowledge of information security standards and guidelines, including ISO 27001/2, NIST, CIS, PCI DSS, and SWIFT CSP.
  • Understands local regulations such as BSP circulars.
  • Knowledgeable in cloud computing, storage, security, and virtualization best practices.
  • Effective communicator across organizational levels; skilled in technical writing and infographic reporting.
  • Strong time management and ability to multi-task with shifting priorities.
  • Delivers exemplary customer service to internal and external stakeholders.
  • Certifications such as ISC2 CISSP, ISMS LA/LI, ISACA CISA/CRISC, or PCI DSS/SWIFT/HITRUST related preferred.

Responsibilities

  • Conducts security and/or risk assessments in a fast-paced environment and provides timely, practical recommendations to mitigate identified risks.
  • Performs security and/or risk assessments aligned with ISO 27001/2, NIST, CIS, PCI DSS, SWIFT CSP, CSA CCM and regulatory requirements.
  • Carries out maturity assessments in cybersecurity and IT.
  • Engages in discovery workshops with consultants and key stakeholders across IT and other business units.
  • Participates in project presentations for client project teams and other stakeholders.
  • Facilitates security training and awareness programs.

Skills

Security assessments
IT risk assessments
Cloud security
Data privacy frameworks
IT audit & maturity assessments
Technical writing
Infographics reporting
Stakeholder communication
Project facilitation

Job description

About the job Risk and Security Assessment Consultant
  • Conducts security and/or risk assessments in a fast-paced environment and provides timely, practical recommendations to mitigate identified risks
  • Performs security and/or risk assessments in alignment with industry standards (ISO 27001/2, NIST, CIS, PCI DSS, SWIFT CSP, CSA CCM), regulatory requirements (BSP circulars and others), and best practices
  • Carries out maturity assessments in cybersecurity and information technology
  • Engages in discovery workshops with consultants and key stakeholders across IT and other business units
  • Participates in project presentations for client project teams and other key stakeholders
  • Facilitates security training and awareness programs

Qualification

  • Possesses over 3 years of experience in Information Technology
  • Holds 23 years of specific experience in security assessments, including Cloud Security Assessment, Third Party Security Risk Assessments, ISMS/NIST Assessment, SOC 2 Type 2 Assessment, RCSA, Configuration Review, Architecture Review, and Controls Review (must have)
  • Has facilitated at least one (1) IT Risk Assessment project
  • Experienced in Data Privacy frameworks such as PDPA, GDPR, and the Data Privacy Act of 2012
  • Experienced in conducting Security Awareness and Training initiatives
  • Has at least 1 year of consulting or advisory engagement experience (preferred)
  • Strong knowledge in IT Audit/Assessments and Maturity Assessments
  • Strong knowledge of information security standards and guidelines, including ISO 27001/2, NIST, CIS, PCI DSS, and SWIFT CSP
  • Understands local regulations such as BSP circulars
  • Knowledgeable in cloud computing, storage, security, and virtualization best practices
  • Effective communicator with the ability to interact across all organizational levels
  • Skilled in technical writing and infographic reporting
  • Strong time management skills, capable of multi-tasking and handling shifting priorities
  • Demonstrated ability to deliver exemplary customer service to both internal and external stakeholders
  • Preferably holds at least one of the following certifications: ISC2 CISSP, ISMS LA/LI, ISACA CISA or CRISC, or certifications relevant to PCI DSS, SWIFT, HITRUST, and other industry security standards/guidelinesA
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Risk & Security Assessment Consultant
IT Risk & Security Assessment Consultant

HRTX • Philippines

On-site
PHP 1,200,000 - 2,100,000
Cybersecurity Consultant (Risk & Security Assessment)
Cybersecurity Consultant (Risk & Security Assessment)

HRTX • Philippines

On-site
PHP 800,000 - 1,200,000
Associate Security Consultant
Associate Security Consultant

HRTX • Philippines

On-site
PHP 420,000 - 780,000
Security Risk & Maturity Assessment Consultant
Security Risk & Maturity Assessment Consultant

HRTX • Philippines

On-site
PHP 600,000 - 900,000
IT Security QA
IT Security QA

Questronix Corporation • Pasig

On-site
PHP 800,000 - 1,200,000
IT Security Risk Assessment Officer
IT Security Risk Assessment Officer

Metropolitan Bank & Trust Company • Metro Manila

On-site
PHP 900,000 - 1,200,000
Cybersecurity Analyst
Cybersecurity Analyst

ContactPoint360 • Cebu City

On-site
PHP 900,000 - 1,300,000
Cybersecurity/IT Risk Officer - Bank | Up to 80K Salary
Cybersecurity/IT Risk Officer - Bank | Up to 80K Salary

weSource Management Consultancy Firm • Makati

On-site
IT Security Consultant
IT Security Consultant

HRTX • Philippines

On-site
PHP 400,000 - 600,000
Cybersecurity & Compliance Consultant
Cybersecurity & Compliance Consultant

Sourcefit Philippines, Inc. • Philippines

On-site
PHP 360,000 - 600,000