Security Analyst

Reed Elsevier Philippines

Quezon City

Hybrid

PHP 720,000 - 1,080,000

Full time

36 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work setup
IT Equipment provided
HMO coverage starting Day 1 for you +
Retirement package with company match
Life and Accident Insurance starting 1
24 Annual PTOs (+6 after year 5)
Merit increases and incentives

Job summary

Reed Elsevier Philippines is seeking an experienced Third-Party & Trust Center Analyst to assess vendor security, privacy, and compliance across engagements and manage the centralized Trust Center documentation.

Reporting to the Manager of Cybersecurity, you will coordinate with Legal, Procurement, Privacy, Product, and Sales to respond to security questionnaires, support audits, and drive risk-based improvements in a global, cross-functional team.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or related field, or equivalent experience.
  • 2-3 years of experience in information security compliance, third-party/vendor risk management, or IT audit.
  • Basic technical knowledge across security domains, including infrastructure security and its impact on security operations, vulnerabilities, reporting, analytics, and monitoring.
  • Working knowledge of security and privacy standards and audit frameworks such as ISO 27001/27017, ISO 27701/27018, HIPAA, PCI DSS, and NIST 800-53.
  • Experience with GRC/TPRM and trust center tooling (OneTrust, SafeBase, Optro (AuditBoard) or similar platforms).
  • Ability to interpret data flow diagrams and evaluate data privacy and data protection implications of third-party engagements.
  • Excellent communication skills: able to explain complex or detailed compliance requirements clearly and concisely at all levels of the business and to external customers, and to keep leadership updated on progress and elevate issues promptly.
  • A 'can-do' attitude and enthusiasm that inspires others; well organized and efficient, with the ability to multi-task and meet tight deadlines.
  • Ability to work effectively and supportively within a global, cross-functional team.
  • Willingness to receive training, mentoring, and ongoing support.
  • Experience assessing vendors against security and privacy control frameworks and managing large control sets.
  • Experience handling inquiries from customer security questionnaires and maintaining a trust center.
  • Fluency in English required.
  • Preferred certifications: CISSP, CISA, CISM, Security+, or ISO 27001 Lead Auditor/Implementer.

Responsibilities

  • Assess third parties and vendors globally for compliance with contractual agreements, security requirements, industry best practices, and regulatory obligations.
  • Gather all relevant information for each engagement: type of engagement, data in scope, data flows, connectivity to internal networks, and intended data use; and evaluate impact to security objectives.
  • Raise information requests where vendor or business responses are incomplete, and maintain accurate, comprehensive assessment records in an online GRC/TPRM platform (e.g., OneTrust).
  • Proactively identify gaps or conflicts in existing processes and drive remediation of control deficiencies identified during assessments.
  • Monitor assessment timelines, vendor record expiry dates, and reassessment cadences to keep the third-party risk register current.
  • Assess potential business changes (new engagements, scope changes, offboarding) for impact to third-party compliance obligations.
  • Maintain the Elsevier's Trust Center, curating and publishing customer-facing security documentation: certifications, policies, whitepapers, product details, and FAQs; to accelerate customer due diligence.
  • Respond to inbound customer and prospect security questionnaires (e.g., SIG, CAIQ, custom RFP/RFI security sections), partnering with sales, legal, product owner(s), and security to deliver accurate, timely responses.
  • Support internal and external audit inquiries related to third-party risk, Trust Center content, and customer due diligence requests.
  • Serve as a trusted point of contact for customers and prospects seeking assurance on Elsevier's security and compliance posture.
  • Build strong relationships with business partners (Legal, Procurement, Privacy, and Product teams) and vendors; facilitate continuous improvement aligned with operational processes.
  • Contribute to the maturation of processes governing third-party risk, data classification, and data handling requirements.
  • Manage day-to-day communication with stakeholders and vendors, escalating concerns, queries, or issues to security leadership as appropriate, including suggested service and process improvements.
  • Support metrics, KPIs, and executive-level reporting on third-party risk posture and Trust Center engagement to support risk-based decision making.

Skills

Information security
Vendor risk management
Security compliance
ISO 27001/27017 knowledge
NIST 800-53 knowledge
English fluency
Communication skills

Education

Bachelor's degree in Information Security, Computer Science, or related field

Tools

OneTrust
SafeBase
Optro (AuditBoard)

Job description

Join us and enjoy benefits designed to help you thrive:

  • Flexible hybrid work setup (1-2 days/month onsite reporting)
  • IT Equipment provided
  • HMO coverage starting from Day 1 for you and FOUR FREE dependents
  • Attractive retirement package with company matching
  • Life and Accident Insurance starting Day 1
  • 24 Annual PTOs, additional 6 once you reach your 5th year with us
  • Competitive benefits with annual merit increase and incentives
  • Continuous improvement for our employees (workshops, certification programs, learning sessions, etc.)
Work Arrangement:
  • Set-Up: Hybrid (1-2/month onsite reporting)
  • Location: UP AyalaLand Technohub, Commonwealth, Quezon City
Job Description:

Reporting to the Manager of Cybersecurity, the Third-Party & Trust Center Analyst sits at the intersection of vendor risk management and customer-facing security assurance. This role is responsible for assessing the security, privacy, and compliance posture of third parties across the vendor lifecycle, while also owning and maintaining the company’s Trust Center: the centralized hub of security documentation, certifications, and due diligence materials used to build confidence and trust with customers and prospects. The role incorporates controls from a variety of security and privacy frameworks (e.g., ISO, NIST, HIPAA, PCI DSS) and is regularly updated to address emerging industry and regulatory risks.

Key Responsibilities:
Third-Party Risk Management
  • Assess third parties and vendors globally for compliance with contractual agreements, security requirements, industry best practices, and regulatory obligations.
  • Gather all relevant information for each engagement: type of engagement, data in scope, data flows, connectivity to internal networks, and intended data use; and evaluate impact to security objectives.
  • Raise information requests where vendor or business responses are incomplete, and maintain accurate, comprehensive assessment records in an online GRC/TPRM platform (e.g., OneTrust).
  • Proactively identify gaps or conflicts in existing processes and drive remediation of control deficiencies identified during assessments.
  • Monitor assessment timelines, vendor record expiry dates, and reassessment cadences to keep the third-party risk register current.
  • Assess potential business changes (new engagements, scope changes, offboarding) for impact to third-party compliance obligations.
Trust Center & Customer Assurance
  • Maintain the Elsevier's Trust Center, curating and publishing customer-facing security documentation: certifications, policies, whitepapers, product details, and FAQs; to accelerate customer due diligence.
  • Respond to inbound customer and prospect security questionnaires (e.g., SIG, CAIQ, custom RFP/RFI security sections), partnering with sales, legal, product owner(s), and security to deliver accurate, timely responses.
  • Support internal and external audit inquiries related to third-party risk, Trust Center content, and customer due diligence requests.
  • Serve as a trusted point of contact for customers and prospects seeking assurance on Elsevier's security and compliance posture.
Governance & Stakeholder Engagement
  • Build strong relationships with business partners (Legal, Procurement, Privacy, and Product teams) and vendors; facilitate continuous improvement aligned with operational processes.
  • Contribute to the maturation of processes governing third-party risk, data classification, and data handling requirements.
  • Manage day-to-day communication with stakeholders and vendors, escalating concerns, queries, or issues to security leadership as appropriate, including suggested service and process improvements.
  • Support metrics, KPIs, and executive-level reporting on third-party risk posture and Trust Center engagement to support risk-based decision making.
Qualifications:
  • Bachelor's degree in Information Security, Computer Science, or a related field, or equivalent experience.
  • 2-3 years of experience in information security compliance, third-party/vendor risk management, or IT audit.
  • Basic technical knowledge across security domains, including infrastructure security and its impact on security operations, vulnerabilities, reporting, analytics, and monitoring.
  • Working knowledge of security and privacy standards and audit frameworks such as ISO 27001/27017, ISO 27701/27018, HIPAA, PCI DSS, and NIST 800-53.
  • Experience with GRC/TPRM and trust center tooling (e.g., OneTrust, SafeBase, Optro (formerly AuditBoard) or similar platforms).
  • Ability to interpret data flow diagrams and evaluate data privacy and data protection implications of third-party engagements.
  • Excellent communication skills: able to explain complex or detailed compliance requirements clearly and concisely at all levels of the business and to external customers, and to keep leadership updated on progress and elevate issues promptly.
  • A 'can-do' attitude and enthusiasm that inspires others; well organized and efficient, with the ability to multi-task and meet tight deadlines.
  • Ability to work effectively and supportively within a global, cross-functional team.
  • Willingness to receive training, mentoring, and ongoing support.
  • Experience assessing vendors against security and privacy control frameworks and managing large control sets.
  • Experience handling inquiries from customer security questionnaires and maintaining a trust center.
  • Fluency in English required.
  • Preferred certifications: CISSP, CISA, CISM, Security+, or ISO 27001 Lead Auditor/Implementer.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Hammerjack Pty Ltd • Philippines

Hybrid
PHP 700,000 - 900,000
HMO coverage starting Day 1 for you &
Retirement plan with company matching
Life & accident insurance starting Day
+2
Security Analyst
Security Analyst

REED ELSEVIER SHARED SERVICES (PHILIPPINES) INC. • Metro Manila

On-site
PHP 700,000 - 1,100,000
Security Analyst: Third Party & Trust Center
Security Analyst: Third Party & Trust Center

Hammerjack Pty Ltd • Philippines

On-site
PHP 900,000 - 1,200,000
Country-specific benefits
Security Analyst: Third Party & Trust Center
Security Analyst: Third Party & Trust Center

RELX • Quezon City

On-site
PHP 900,000 - 1,300,000
Competitive benefits
Vendor Risk & Trust Center Analyst (Hybrid)
Vendor Risk & Trust Center Analyst (Hybrid)

Hammerjack Pty Ltd • Philippines

Hybrid
PHP 700,000 - 900,000
HMO coverage starting Day 1 for you &
Retirement plan with company matching
Life & accident insurance starting Day
+2
Hybrid: Trust Center & Third-Party Risk Analyst
Hybrid: Trust Center & Third-Party Risk Analyst

Reed Elsevier Philippines • Quezon City

Hybrid
PHP 720,000 - 1,080,000
Hybrid work setup
IT Equipment provided
HMO coverage starting Day 1 for you +
+4
IT Security Analyst
IT Security Analyst

John Clements Consultants, Inc. • Metro Manila

On-site
PHP 1,000,000 - 1,800,000
IT Security QA
IT Security QA

Questronix Corporation • Pasig

On-site
PHP 800,000 - 1,200,000
Third-Party Risk & Trust Center Security Analyst
Third-Party Risk & Trust Center Security Analyst

Hammerjack Pty Ltd • Philippines

On-site
PHP 900,000 - 1,200,000
Country-specific benefits
Vendor Risk Analyst - Third Party
Vendor Risk Analyst - Third Party

Manpower (Philippines) • Metro Manila

On-site
PHP 600,000 - 900,000