Security Analyst: Third Party & Trust Center

LexisNexis Risk Solutions

Manila

On-site

PHP 600,000 - 1,000,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

RELX seeks a qualified information security professional to manage third-party risk assessments, maintain the Trust Center, and coordinate governance with Legal, Procurement, Privacy, and Product teams. The role supports audits, customer due diligence, and continuous improvement in risk posture.

The ideal candidate has 2–3 years in information security compliance and is fluent in English, with certifications such as CISSP/CISA/CISM or similar preferred.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or a related field.
  • 2–3 years of experience in information security compliance, third-party/vendor risk management, or IT audit.
  • Experience handling inquiries from customer security questionnaires and maintaining a trust center.
  • Fluency in English required; preferred CISSP, CISA, CISM, Security+, or ISO27001 Lead Auditor/Implementer.

Responsibilities

  • Assess third-party risk and ensure compliance with contractual, security and regulatory obligations.
  • Maintain and publish Trust Center content; respond to security questionnaires and inquiries.
  • Engage with Legal, Procurement, Privacy and Product teams to drive process improvements and risk remediation.
  • Support audits and leadership reporting on third-party risk posture and Trust Center engagement.

Skills

Information security
Risk management
Compliance
Security controls
Data privacy
Communication

Education

Bachelor's degree in Information Security or Computer Science

Tools

OneTrust
SafeBase
AuditBoard

Job description

Key Responsibilities

Third-Party Risk Management Assess third parties and vendors globally for compliance with contractual agreements, security requirements, industry best practices, and regulatory obligations. Gather all relevant information for each engagement: type of engagement, data in scope, data flows, connectivity to internal networks, and intended data use; and evaluate impact to security objectives. Raise information requests where vendor or business responses are incomplete, and maintain accurate, comprehensive assessment records in an online GRC/TPRM platform (e.g., OneTrust). Proactively identify gaps or conflicts in existing processes and drive remediation of control deficiencies identified during assessments. Monitor assessment timelines, vendor record expiry dates, and reassessment cadences to keep the third-party risk register current. Assess potential business changes (new engagements, scope changes, offboarding) for impact to third-party compliance obligations.

Trust Center & Customer Assurance

Maintain the Elsevier's Trust Center, curating and publishing customer-facing security documentation: certifications, policies, whitepapers, product details, and FAQs; to accelerate customer due diligence. Respond to inbound customer and prospect security questionnaires (e.g., SIG, CAIQ, custom RFP/RFI security sections), partnering with sales, legal, product owner(s), and security to deliver accurate, timely responses. Support internal and external audit inquiries related to third-party risk, Trust Center content, and customer due diligence requests. Serve as a trusted point of contact for customers and prospects seeking assurance on Elsevier's security and compliance posture.

Governance & Stakeholder Engagement

Build strong relationships with business partners (Legal, Procurement, Privacy, and Product teams) and vendors; facilitate continuous improvement aligned with operational processes. Contribute to the maturation of processes governing third-party risk, data classification, and data handling requirements. Manage day-to-day communication with stakeholders and vendors, escalating concerns, queries, or issues to security leadership as appropriate, including suggested service and process improvements. Support metrics, KPIs, and executive-level reporting on third-party risk posture and Trust Center engagement to support risk-based decision making.

Ideal Candidate Profile

Elsevier is looking for a candidate with information security and risk experience in a commercial environment, including: Basic technical knowledge across security domains, including infrastructure security and its impact on security operations, vulnerabilities, reporting, analytics, and monitoring. Working knowledge of security and privacy standards and audit frameworks such as ISO 27001/27017, ISO 27701/27018, HIPAA, PCI DSS, and NIST 800-53. Experience with GRC/TPRM and trust center tooling (e.g., OneTrust, SafeBase, Optro (formerly AuditBoard) or similar platforms). Ability to interpret data flow diagrams and evaluate data privacy and data protection implications of third-party engagements. Excellent communication skills: able to explain complex or detailed compliance requirements clearly and concisely at all levels of the business and to external customers, and to keep leadership updated on progress and elevate issues promptly. A ‘can-do’ attitude and enthusiasm that inspires others; well organized and efficient, with the ability to multi-task and meet tight deadlines. Ability to work effectively and supportively within a global, cross-functional team. Willingness to receive training, mentoring, and ongoing support. Ability to quickly learn and apply enterprise AI tools and technologies to support technical workflows and business objectives.

Qualifications

Bachelor's degree in Information Security, Computer Science, or a related field. 2 – 3 years of experience in information security compliance, third-party/vendor risk management, or IT audit. Experience assessing vendors against security and privacy control frameworks and managing large control sets. Experience handling inquiries from customer security questionnaires and maintaining a trust center. Fluency in English required. Preferred certifications: CISSP, CISA, CISM, Security+, or ISO 27001 Lead Auditor/Implementer.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. USA Job Seekers: EEO Know Your Rights.

RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results, and be more productive. Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions. Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

REED ELSEVIER SHARED SERVICES (PHILIPPINES) INC. • Metro Manila

On-site
PHP 700,000 - 1,100,000
Administrative Svcs Generalist I
Administrative Svcs Generalist I

LexisNexis Risk Solutions • Manila

Hybrid
PHP 446,000 - 670,000
Accounts P/R Coordinator I
Accounts P/R Coordinator I

LexisNexis Risk Solutions • Manila, Hinoba-an

On-site
PHP 279,000 - 446,000
Third-Party Risk & Trust Center Analyst
Third-Party Risk & Trust Center Analyst

LexisNexis Risk Solutions • Manila

On-site
PHP 600,000 - 1,000,000
Account Support Analyst
Account Support Analyst

LexisNexis Risk Solutions • Manila, Hinoba-an

On-site
PHP 246,000 - 424,000
Accounts Payable Specialist
Accounts Payable Specialist

LexisNexis Risk Solutions • Iloilo City

On-site
PHP 223,000 - 357,000
Accounting Analyst II
Accounting Analyst II

LexisNexis Risk Solutions • Manila, Hinoba-an

On-site
PHP 350,000 - 600,000
null
Supervisor II, Data Analytics
Supervisor II, Data Analytics

LexisNexis Risk Solutions • Manila

On-site
PHP 900,000 - 1,500,000
Senior Systems Engineer I
Senior Systems Engineer I

Elsevier • Hinoba-an

On-site
PHP 1,800,000 - 3,000,000
Health insurance
Life insurance
Long-service awards
+2
Invoice Processing Analyst
Invoice Processing Analyst

LexisNexis Risk Solutions • Manila

On-site
PHP 279,000 - 391,000