SECURITY ASSURANCE AND ASSESSMENT OFFICER

Metrobank

Taguig

On-site

PHP 600,000 - 800,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Opportunities for professional development
Community contribution initiatives

Job summary

Metrobank is seeking a Security Assurance and Assessment Officer to develop and maintain the Bank's information security risk management framework. This role involves assessing third-party security, analyzing risks to critical assets, and coordinating risk mitigation strategies.

The ideal candidate will have a degree in Information Technology or a related field, with knowledge of regulatory requirements like BSP and experience in security assessments. Metrobank offers an opportunity to contribute positively to the community while developing your career.

Qualifications

  • Knowledge of compliance and regulatory requirements like BSP and PCI-DSS.
  • Ability to plan and execute risk assessments with minimal guidance.
  • Strong attention to detail and analytical problem-solving skills.

Responsibilities

  • Develop tactical plans for the Bank’s information security risk management.
  • Coordinate and assess the performance of third-party vendors.
  • Monitor and track the accomplishment of risk assessment plans.

Skills

Information security governance
Risk assessments
Analytical skills
Communication skills
Project management

Education

Bachelor's degree in Information Technology or related field
CISA, CISM, CRISC, PCI-DSS certifications

Tools

MS Office (PowerPoint, Word, Excel, Project)

Job description

Be #InGoodHands with Metrobank!

Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well‑rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach!

Position Title

Security Assurance and Assessment Officer

Job Summary

Develop tactical plans and programs for the establishment and maintenance of the Bank’s third‑party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third‑party security, system security and information asset‑based risk assessment. Analyze and review complex bank processes, application system and network security implementation and third‑party relationships to identify potential risk including the determination of risk mitigation strategies. Recommend strategies to control risks from inadequate protection of confidentiality, integrity and availability of the information assets, processing facilities and connected services.

Specific Duties & Responsibilities
  • Prepares tactical plans and/or programs in the conduct of information, third party and system security risk assessments.
  • Identify the Bank’s critical assets, threats to these assets, vulnerabilities, and reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information.
  • Coordinate and assess the security performance of third‑party vendors that collect, process, transmit, and store client data.
  • Performs threat modelling‑based system security risk assessment for all IT systems and other IT assets, as applicable.
  • Analyze and assess the impact of changes in process, technical changes and systems enhancements and third‑party relationships.
  • Reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information and information processing facilities to mitigate information security risk.
  • Formulates, recommends information security policies and procedures on physical, environmental and personnel security with respect to results of information security assessment activities.
  • Responsible for coordinating across all business units and stakeholders in gathering information in preparation to the conduct of information, third party and system security risk assessment.
  • Articulate security findings and risk remediation strategies through issuance of risk assessment report. Track and follow‑up status of risk mitigation activities.
  • Ensures security risk register is maintained and kept updated including status of remediation activities.
  • Executes and monitors accomplishment of the risk assessment plans and programs.
  • Articulate security findings and risk remediation strategies through issuance of risk assessment report; writing comprehensive, concise and understandable to non‑technical. Tracking and follow up on status of mitigation activities.
  • Maintain and track library of records and documentation.
  • Investigation of applicable reported incidents related to information handling and data privacy.
  • Keep abreast of and apply information, IT and third‑party security trends and regulatory and compliance changes affecting the security of landscape, security best practices, threat landscape (emerging and existing) and apply them in daily work.
  • Review the work of other Security Quality and Assurance Risk Assessors; guides and mentors them.
  • Proactively works with the Department Head in implementing programs for the continuous improvement of the bank’s information security plans and strategies.
  • Perform other information security risk management and compliance related duties and responsibilities as directed by the Department Head.
Qualifications
  • Knowledgeable on various compliance and regulatory requirements (i.e., BSP, DPA, PCI‑DSS, etc.).
  • Working knowledge of various information and IT security domains and controls related to third‑party risks, data security and risk management, data transmission integrity. This includes understanding various processes related to the service, product or solution provided by vendors to the Bank and its links to bank processes.
  • Has experience in information security governance, controls assurance, risk assessments and key risk indicators development.
  • Experience in IT general controls and auditing a plus. Strong background on network and application system security risk assessments.
  • Ability to plan, execute, and document assessment activities following established processes and procedures with minimal guidance.
  • Ability to lead and work well with the team, internal, and external clients. Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.
  • Analytical and risk identification skills to analyze a variety of information security–related risk situations and develop recommendations on the best course of action.
  • Good Project management skills: to lead and manage accomplishments of assigned tasks/risk assessment activities.
  • Possess excellent time management skills, thrive in a fast paced demanding environment.
  • Be a self‑managed self‑starter with good organizational skills to include good follow‑up skills.
  • Be able to work under pressure on multiple assessments/projects simultaneously.
  • Strong attention to detail, analytical, and problem‑solving skills.
  • Strong learning agility with the ability to learn new processes.
  • Good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.
  • Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action.
  • College graduate or any degree on Information technology, Information Security, or related field of expertise.
  • Certification may include CISA, CISM, CRISC, PCI‑DSS, etc.
  • Knowledge in using MS office tools such as PowerPoint, Word, Excel and Project.
Other Details
  • Rank: Junior Officer
  • Unit: Financial and Control Sector / Information Security Division / Security Quality Assurance and Assessment Department
  • Location: Metrobank Center, Taguig
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Risk Assessment Officer
IT Security Risk Assessment Officer

Metrobank • Philippines

On-site
PHP 650,000 - 900,000
HEAD, SECURITY ARCHITECTURE AND INNOVATIONS DEPARTMENT
HEAD, SECURITY ARCHITECTURE AND INNOVATIONS DEPARTMENT

Metrobank • Taguig

On-site
Junior InfoSec Risk & Assurance Officer
Junior InfoSec Risk & Assurance Officer

Metrobank • Taguig

On-site
PHP 600,000 - 800,000
Opportunities for professional development
Community contribution initiatives
NETWORK SECURITY ENGINEER
NETWORK SECURITY ENGINEER

Metrobank • Taguig

On-site
NETWORK SECURITY ENGINEER
NETWORK SECURITY ENGINEER

Metrobank • Hinoba-an

On-site
PHP 600,000 - 900,000
Head, Security Architecture and Innovation
Head, Security Architecture and Innovation

Metrobank • Metro Manila

On-site
PHP 1,200,000 - 2,000,000
Network Security Engineer
Network Security Engineer

Metrobank • Metro Manila

On-site
PHP 700,000 - 1,000,000
AUDIT OFFICER, SECURITY AND INFRASTRUCTURE AUDIT DEPARTMENT
AUDIT OFFICER, SECURITY AND INFRASTRUCTURE AUDIT DEPARTMENT

Metrobank • Taguig

On-site
PHP 600,000 - 800,000
AUDIT OFFICER, SECURITY AND INFRASTRUCTURE AUDIT DEPARTMENT
AUDIT OFFICER, SECURITY AND INFRASTRUCTURE AUDIT DEPARTMENT

Metrobank • Taguig

On-site
PHP 500,000 - 700,000
OFFENSIVE SECURITY OFFICER
OFFENSIVE SECURITY OFFICER

Metrobank • Hinoba-an

On-site
PHP 600,000 - 1,000,000