Overview
Role: Senior Consultant I - Security & Privacy
Work Arrangement: Hybrid
Location: Philippines - Angeles (Pampanga) / Cebu
Schedule: Morning Shift
Job Description: Security & Privacy (S&P) consultants are responsible for extensive client contact, staff training, management & development; liaising with third parties. You will be skilled and experienced at managing the full project lifecycle for IT general controls audits, cyber security and information security services.
Responsibilities
- Perform IT / Cyber / Business Continuity / technology risk assessments, technical security related reviews, assess the effectiveness of processes/controls and risks related to third party organizations.
- Execute and complete IT, cyber security and resiliency audits and special project reviews related to applications, IT infrastructure and other relevant IT domains.
- Conduct independent risk-based IT, cyber security and resiliency assessments to evaluate internal controls and the reliability of client business and IT systems.
- Lead or coordinate audit engagements with engagement team members, including planning, execution and scheduling staff.
- Undertake or arrange special consulting or other reviews as required (e.g., system software reviews, new system development evaluations, post-implementation reviews, contingency planning, access reviews, installation reviews).
- Assist in planning client deliverables (e.g., strategic internal audit plan, scope documents).
- Execute fieldwork and document findings (maintain the audit file).
- Provide IT general controls and application controls audit support to external audit.
- Define objectives, scope and extent of each audit and ensure timely, professional completion.
- Support business development activities of the firm and coordinate with other divisions.
- Address technical issues and assist in preparing technical position papers.
- Develop team members and coordinate audit team activities including training and methodology compliance.
- Identify opportunities to improve operational efficiencies and effectiveness.
- Maintain documentation to auditing standards; identify findings and draft client reports; discuss findings with management as required.
- Liaise and present audit results to information system staff and client management; stay current with technological enhancements in auditing and IT.
Qualifications
Education & Essential Requirements
- Successful Criminal Record Screening Clearance.
- Relevant tertiary degree and/or qualification is essential.
Demonstrated Experience & Attributes
- Minimum 5 years of Professional Services experience in Cyber / IT technical delivery, Business Continuity, IT audit, internal controls, or risk management.
- Experience performing security risk assessments, testing or auditing cybersecurity or information security standards or governance frameworks (e.g., COBIT, NIST CSF, ASD Top 35 and Essential Eight, PCI DSS, CIS Controls, ISO/IEC 27001, GDPR, etc.).
- Experience leading Business Continuity (BCP) and IT Disaster Recovery (IT DRP) engagements; ability to assess recovery plans for critical applications and systems; incident management; and reviewing against ISO 22301, BS 25999.
- Ability to translate technical findings for non-technical client staff; strong IT general controls and application controls knowledge.
- Strong knowledge of IT processes, project management, applications, databases, operating systems and network infrastructure.
- Excellent written and verbal communication skills; ability to tailor messaging for technical and non-technical audiences.
- Strong analytical skills and attention to detail; ability to work autonomously and in a team.
- Ability to add value by delivering high-quality client service.
Desirable
- Knowledge of data analytics / computer-assisted audit techniques using IDEA, ACL, SQL or other analytics tools.
Non-negotiable Skills & Requirements
- Minimum 5 years of Professional Services experience in Cyber / IT technical delivery, Business Continuity, IT audit, internal controls, or risk management.
- Experience performing security risk assessments, testing or auditing cybersecurity or information security standards or governance frameworks (e.g., COBIT, NIST CSF, ASD Top 35 and Essential Eight, PCI DSS, CIS Controls, ISO/IEC 27001, GDPR).
- Experience leading engagements on Business Continuity (BCP) and IT Disaster Recovery (IT DRP), including recovery plan assessment and incident management.
- Ability to translate technical findings and articulate recommendations for non-technical client staff.
- Demonstrated knowledge of IT general controls and application controls.
- Demonstrated knowledge of IT processes, project management, applications, databases, operating systems and network infrastructure.
Benefits
- Comprehensive health and life insurance eligibility and related coverage.
- Flexible leave credits for vacation, emergency, and sick leave.
- WFH/hybrid perks, career advancement opportunities, and annual performance reviews with salary increases.
- Company-provided PC/Laptop and reliable internet; technical support options.
- Employee engagement programs, mentoring, and opportunities for international career growth.
- Employee referral incentives and wellness resources.
- Cloudstaff benefits program and career-building opportunities across locations.