Senior Cybersecurity Analyst (Vulnerability)

Talkpush

Taguig

On-site

PHP 900,000 - 1,300,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Talkpush is seeking an Information Security Analyst to join the Exposure Management team in Manila. The role focuses on vulnerability management, attack surface management, cloud security, and providing network and endpoint security support.

You will report to the Cybersecurity Manager within the IS Threat Management Team. Responsibilities include conducting vulnerability assessments, coordinating remediation with stakeholders and vendors, and producing security metrics.

Qualifications

  • Minimum education and/or experience as described: BS in CS or equivalent and 3+ years in info security.
  • Experience with vulnerability management, risk and compliance assessments, and PCI/NIST/ISO familiarity.

Responsibilities

  • Perform scheduled security vulnerability assessments across global applications and infrastructure.
  • Coordinate remediation efforts and track vulnerabilities through triage and validation.
  • Document findings, remediation recommendations, and KPIs to illustrate effectiveness.

Skills

Vulnerability management
Endpoint security
Cloud security
Threat detection
Security operations
English communication

Education

BS in Computer Science or equivalent
Certifications: CISSP, CompTIA Security+, CEH, GIAC

Tools

Vulnerability assessment tools
Network security tools
Endpoint security tools

Job description

OVERVIEW AND REPORTING RELATIONSHIP

This analyst will be a member of the Exposure Management team and will report to the Cybersecurity Manager. This position will be responsible for various technical cybersecurity analyst functions, including vulnerability management, attack surface management, cloud security, as well as providing network and endpoint security support.

REPORTING STRUCTURE & WORK SETTING

Global Business Center - Manila position, within the IS Threat Management Team, under the Cybersecurity Manager, within the Tenet Corporate Cybersecurity organization.

RESPONSIBILITIES
Vulnerability Management
  • Perform scheduled security vulnerability assessments across global applications and infrastructure.
  • Manage, coordinate, and track vulnerabilities from discovery, triage, remediation, and validation.
  • Document, prioritize and formally report asset and vulnerability state, along with remediation recommendations and validation.
  • Coordinate, schedule, and manage the engagement process (with internal stakeholders and third-party vendors) for vulnerability remediation activities.
  • Formally document and establish well-defined processes, procedures, remediation and mitigation strategies, and lessons learned.
  • Manage vulnerability related tickets to ensure issues are remediated within designated timelines.
  • Provide vulnerability mitigation strategies and meaningful vulnerability metrics.
  • Support the maintenance and operations of vulnerability assessment infrastructure through refresh initiatives and annual planning.
  • Report on findings and respond to requests and known vulnerabilities as well as delivering ad-hoc vulnerability scans on request.
  • Coordinate emergency vulnerability patching, including remediation efforts.
  • Conduct research and provide feedback to leadership and Cybersecurity team members of the recommended actions for vulnerability scan findings.
  • Leverage vulnerability database sources to understand each weakness, its probability and remediation options, including vendor-supplied fixes and workarounds.
  • Provide support of maintenance and operations to the vulnerability assessment toolsets.
  • Provide support to internal processes to ensure compliance with the Payment Card Industry (PCI) standard.
  • Support internal and external auditors in their duties that focus on compliance and risk reduction.
  • Collaborate with security groups such as red teams, threat intelligence and risk management to form a holistic team dedicated to thwarting attackers and reducing attack surface.
  • Work closely with infrastructure teams to advise and support remediation efforts to close vulnerability exposure to new threats in the wild and verify the organization’s security posture against them.
  • Regularly research and learn new TTPs in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary.
  • Maintain an active database comprising third-party assets, their vulnerability state, remediation recommendations, overall security posture and potential threat to the business.
  • Define key performance indicators (KPIs) and metrics across business units to illustrate effectiveness with vulnerability management.
  • Understand breach and attack simulation solutions for known vulnerabilities and work with the team to validate controls effectiveness.
  • Liaise with the security engineering team to improve tool usage and workflow, as well as with the advanced threats and assessment team to mature monitoring and response capabilities.

REQUIRED KNOWLEDGE AND EXPERIENCE: Please describe the minimum education, technical training and/or experience required to perform this job (formal education, relevant work experience, ability to perform specific tasks, certification, skills, etc.).

QUALIFICATIONS
  • Information Systems (IS) security professional with a broad range of knowledge in vulnerability and endpoint security systems/processes.
  • Intermediate or advanced understanding in information security administration, vulnerability assessment and management, or security operations.
  • Intermediate or advanced understanding of advanced threat detection in an enterprise environment.
  • Intermediate or advanced understanding of malware families, their types, and threats they pose.
  • Strong technical background in vulnerability assessment tools, as well as network and endpoint security best practices.
  • Demonstrated ability in identification of vulnerabilities/threats to data, systems and networks.
  • Comprehension of end-to-end vulnerability management workflow to include industry standards such as CVE, CPE, MITRE Attack Framework, and CVSS.
  • Preferred experience with vulnerability management in both on-premise and cloud provider platforms.
  • Experience in conducting organization-wide vulnerability scanning and remediation processes.
  • Knowledge of compliance standards such as Payment Card Industry (PCI), National Institute of Standards (NIST), and/or International Standards Organization (ISO).
  • Fluency in speaking and communicating in English.
EDUCATION AND WORK EXPERIENCE
  • Minimum three years of experience
  • BS in Computer Science or equivalent field.
  • Preferred education and/or experience: Relevant industry recognized certifications (CISSP, CompTIA Security+,
  • CEH, GIAC, Security+, etc.)
SPECIALIZED KNOWLEDGE, SKILLS & ABILITIES:
  • Effectively communicate security goals effectively with other departments.
  • Ability to work within an environment of frequently changing priorities.
  • Knowledge of industry trending threats, security tools, and best practices.
  • Proven ability in the performance of information security risk assessments.
  • Experience in performing risk and compliance assessments of new and existing solutions.
  • Ability to provide guidance and recommended remediation or alternative solutions for both internal and external supported environments.
  • Ability to provide guidance in the identification, documentation and rating of threats/vulnerabilities, and remediation steps recommended to reduce risks to data, systems and networks.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst (End point Security)
Senior Cybersecurity Analyst (End point Security)

Talkpush • Taguig

On-site
PHP 600,000 - 900,000
Senior Cybersecurity Analyst (Vulnerability)
Senior Cybersecurity Analyst (Vulnerability)

Tenet Healthcare • Taguig

On-site
PHP 600,000 - 900,000
Senior Cybersecurity Analyst (Vulnerability)
Senior Cybersecurity Analyst (Vulnerability)

Tenet Global Business Center, Inc. • Taguig

On-site
PHP 700,000 - 1,200,000
Night differential 15%
PTO 20 days/year
Annual appraisal
+4
SENIOR CYBERSECURITY ANALYST (END POINT SECURITY)
SENIOR CYBERSECURITY ANALYST (END POINT SECURITY)

Tenet Global Business Center, Inc. • Taguig

On-site
PHP 800,000 - 1,000,000
Senior Cybersecurity Engineer (Vulnerability Management)
Senior Cybersecurity Engineer (Vulnerability Management)

APW Tech • Metro Manila

Hybrid
PHP 1,500,000 - 2,100,000
Hybrid Work Setup (3 Days Onsite per W
Day Shift | 8:00 AM – 5:00 PM
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Santo Niño 1st

On-site
PHP 1,200,000 - 1,800,000
Vulnerability Remediation Lead (Cyber/InfoSec) | Up to 280K Salary
Vulnerability Remediation Lead (Cyber/InfoSec) | Up to 280K Salary

weSource Management Consultancy Firm • Taguig

On-site
PHP 2,455,200 - 3,124,800
Security Analyst
Security Analyst

Artech Technology Inc. • Quezon City

On-site
PHP 3,527,337 - 5,291,005
Vulnerability Remediation Lead | Up to 280K Salary
Vulnerability Remediation Lead | Up to 280K Salary

weSource Management Consultancy Firm • Taguig

On-site
PHP 252,000 - 308,000
Hiring! Lead IT Security Analyst
Hiring! Lead IT Security Analyst

Ascendion • Mandaluyong

Hybrid
PHP 1,800,000 - 3,000,000