Senior IT Risk Analyst

Fresenius Medical Care

Metro Manila

On-site

PHP 700,000 - 1,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fresenius Medical Care is seeking a Senior IT Risk Analyst to drive IT risk assessments, document control gaps, and support enterprise risk management processes. The role reports to the Director of IT Risk Management and collaborates across ITS and Internal Audit to strengthen cyber risk posture.

The candidate should have 5–8 years in audits or risk management, with IT process understanding and relevant certifications.

Qualifications

  • Bachelor’s degree in MIS, CS, or related field required.
  • 5–8 years in audits/risk management with IT focus.
  • Certifications such as CISA/CISSP/CRISC are preferred.

Responsibilities

  • Conduct IT risk assessments to identify inherent and residual risks.
  • Evaluate risks and controls and challenge IT customers on risk acceptance.
  • Coordinate risk response plans with risk owners and stakeholders.
  • Oversee portfolio of IT risks and communicate with governance.
  • Stay updated on IT security best practices and guidance.
  • Collaborate with ITS, Internal Audit, and Corporate Risk Management to ensure consistent risk messaging.
  • Develop procedures to support operational risk processes.
  • Promote security best practices across all BU’s and departments.

Skills

IT risk assessments
Analytical skills
Communication skills
Problem solving
Team collaboration

Education

Bachelor’s Degree in MIS/CS/business-related field

Tools

CISA
CISSP
CRISC

Job description

The Senior IT Risk Analyst provides technical expertise and supports Information Technology Solutions (ITS) in identifying, assessing, documenting, and resolving IT risks. This role serves as a key core team member in drafting IT risk analyses for all IT related processes. The role reports to the Director, IT Risk Management and performs the ITS Risk Management and Fresenius Medical Care Enterprise Risk Management processes. The individual will help drive critical cyber security risk management initiatives across the enterprise.

PRINCIPAL DUTIES AND RESPONSIBILITIES:
  • Conduct IT risk assessments, using subject matter expertise, to identify both inherent and residual risk ratings.
  • Apply sound judgment in evaluating risks and controls; effectively challenge IT customers on the identification and acceptance of risks and the adequacy of controls and mitigating factors.
  • Partner with risk owners and stakeholders to obtain appropriate risk response plans and monitor risk response plans
  • Assist with oversight and communication of the portfolio of IT related risks with limited oversight.
  • Understand and stay current on best practices and guidance on achieving security.
  • Partner with other groups within ITS, Global Internal Audit, and Corporate Risk Management to ensure risks are appropriately communicated and remain consistent with the ever-changing enterprise/industry risk environment.
  • Develop and maintain procedures to support the execution of operational risk processes.
  • Evangelize security best practices in dealings across all BU’s and departments.
  • Maintain strong knowledge of risk management practices and IT best practices.
  • Build and maintain strong relationships with personnel across all Business Units.
  • Review and comply with the Code of Business Conduct and all applicable company policies and procedures, local, state and federal laws and regulations.
  • Assist with various projects as assigned by a direct supervisor.
  • Other duties as assigned.
EDUCATION:
  • Bachelor’s Degree in Management Information Systems, Computer Science, or business/science related field required
EXPERIENCE AND REQUIRED SKILLS
  • 5-8 years of experience working with internal/external audits or risk management - methods and techniques for the assessment and management of risk.
  • Ability to operate as a pro-active and result-driven problem solver with excellent analytical and interpersonal skills.
  • Ability to understand IT processes, management objectives risk appetite and tolerances and impact of objectives, risk appetite and tolerances and impact of changes to risk profiles.
  • CISA, CISSP, CRISC, or other relevant certification(s) desired.
  • Strong client services orientation and communication skills coupled with a high sense of urgency to keep appropriate partners informed, including solutions to overcome obstacles to deliver to expectation.
  • Strong understanding of risk management, integration with enterprise risk management, and the integration with business strategy.
  • Solid understanding of IT Audit best practices. Former Big 4 IT auditor or Financial Services IT risk management experience preferred.
  • Experience in IT governance, risk, and controls, including governance frameworks.
  • Demonstrated technical writing, communication, and presentation skills.
  • Ability to work effectively in a team environment.
  • Creativity in addressing technical challenges.
  • Proven record to deliver results.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Risk Architect - Cybersecurity & Compliance
Senior IT Risk Architect - Cybersecurity & Compliance

Fresenius Medical Care • Metro Manila

On-site
PHP 700,000 - 1,100,000
Information Security Risk Consultant - IT Audit
Information Security Risk Consultant - IT Audit

Optum Philippines • Makati

On-site
PHP 600,000 - 1,200,000
Associate Specialist, GRC
Associate Specialist, GRC

Concentrix • Morong

On-site
PHP 500,000 - 1,200,000
Associate Specialist, Governance, Risk and Compliance
Associate Specialist, Governance, Risk and Compliance

Concentrix • Angeles

On-site
PHP 600,000 - 900,000
Assistant Vice President-Internal Audit
Assistant Vice President-Internal Audit

Maxicare Healthcare Corporation • Makati

On-site
PHP 1,800,000 - 3,000,000
Associate Specialist, Governance, Risk and Compliance
Associate Specialist, Governance, Risk and Compliance

Concentrix Philippines • Angeles

On-site
PHP 600,000 - 1,200,000
IT Risk & Control Specialist
IT Risk & Control Specialist

Palawan Group of Companies • Mandaluyong

On-site
PHP 600,000 - 900,000
Risk Analyst - IT
Risk Analyst - IT

Wonese Philippines • Quezon City

On-site
PHP 800,000 - 1,200,000
Senior IT Risk Analyst
Senior IT Risk Analyst

Global Payments Inc. • Philippines

On-site
PHP 1,200,000 - 1,800,000
Senior Information Security Engineering Consultant
Senior Information Security Engineering Consultant

UnitedHealth Group • Cebu City

On-site
PHP 900,000 - 1,400,000