Senior Security GRC Analyst

DFI Technology (Philippines)

Mandaluyong

On-site

PHP 1,200,000 - 1,900,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

DFI Retail Group seeks a Senior Security GRC Analyst to lead governance, risk, and compliance initiatives across enterprise environments. The role focuses on risk assessments, maintaining the security register, audit support, and alignment with ISO 27001 and NIST CSF, with vendor risk oversight.

You will collaborate with Information Security and IT teams to strengthen security posture, drive remediation, and ensure controls are in place for regulatory and contractual requirements across the

Qualifications

  • Bachelor’s degree in information technology, computer science, or equivalent experience.
  • 5+ years in security governance, risk, compliance, audit, or assurance roles.
  • Experience with risk assessments, risk registers and remediation tracking.
  • Working knowledge of ISO/IEC 27001 and NIST CSF; audits & evidence collection.

Responsibilities

  • Govern governance and policy management; draft, review and track approvals.
  • Maintain policy library with version control and review cadence.
  • Align artifacts with frameworks (NIST CSF, ISO 27001, PCI DSS, GDPR).
  • Conduct risk assessments for projects, systems and vendors; document risks and treatments.
  • Support audits; coordinate evidence collection and audit readiness.
  • Map controls to ISO/IEC 27001:2022 Annex A and NIST CSF 2.0.
  • Assist with vendor security risk assessments and evidence review.
  • Prepare dashboards and reports for leadership on risk, compliance, and audits.

Skills

Security governance
Risk management
Compliance
Audit
Policy drafting
Risk assessment
Vendor risk

Education

Bachelor's degree in IT or Computer Science

Tools

ISO 27001
NIST CSF
PCI DSS
GDPR

Job description

Is this your next challenge as a Senior Security GRC Analyst?

The challenge is to:

We are seeking a Senior Security GRC Analyst with at least 5 years' experience to strengthen our information security governance, risk management and compliance programs. In this role, you will lead risk assessments, maintain the security register, support audits and ensure alignment with frameworks such as NIST CSF, ISO 27001 and applicable regulations.

The successful candidate will work closely with Information Security team and IT teams to help protect organizational assets, strengthen security posture, and support cybersecurity initiatives across enterprise environments.

Key Responsibilities
  • Governance and Policy Management
  • Own the lifecycle of security policies, standards and procedures: draft, review, update and track approvals and exceptions
  • Maintain the policy library with version control, ownership, and review cadence
  • Align governance artifacts with frameworks (NIST CSF, ISO 27001, PCI DSS, GDPR as applicable)
  • Conduct risk assessments for projects, systems, and vendors using DFI's methodology
  • Document risks, treatments, and residual ratings; route for risk acceptance per authority tiers
  • Support project security risk assessment reviews and cybersecurity pre go-live security reviews with system/application owners
  • Track remediation and follow up with mitigation control/remediation action owners
  • Security Architecture & Data Flow Review
  • Review security architecture diagrams and data flow diagrams for new projects, system changes, and vendor integrations
  • Validate designs against DFI security standards, segmentation principles, and data classification requirements
  • Audit and Compliance Support
  • Coordinate annual security audits and certifications (ISO 27001,PCI DSS); manage evidence collection, stakeholder coordination and audit readiness.
  • Support control self-assessments and audit evidence preparation
  • Map controls/findings against ISO/IEC 27001:2022 Annex A and NIST CSF 2.0
  • Third-Party & Vendor Risk
  • Assist with vendor security risk assessments (documentation/evidence review)
  • Maintain security risk assessment records and chase outstanding vendor evidence
  • General Security GRC Support
  • Update Security GRC templates, trackers, and reporting materials
  • Support ad hoc governance, audit, and compliance tasks
  • Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit and awareness program status.

Do you have experience as a Security GRC Analyst?

Required Qualifications
  • Bachelor's degree in information technology, or Computer Science or equivalent experience
  • Experience: 5+ years in security governance, risk, compliance, audit, or security assurance roles.
  • Proven track record in risk assessments, risk register management, and remediation tracking
  • Working knowledge of ISO/IEC 27001 (Annex A, ISMS docs) and NIST CSF
  • Experience in supporting internal/external audits, evidence collection, and audit readiness activities
  • Strong ability to draft clear, actionable policies and procedures; translate regulatory requirements into control procedures
  • Ability to translate technical diagrams into risk/control language
Nice To Have Qualifications
  • Certifications: CISSP, CISA, CRISC, ISO 27001 Lead Auditor/Implementer or equivalent
  • Retail or regulated industry experience
  • Familiarity with automating evidence collection and control monitoring
  • Familiarity with PCI DSS, GDPR, or Hong Kong PDPA
  • Exposure to vulnerability management, IAM/PAM, cloud/network security

If you have the right skills and experience, this is an opportunity to build your career with Asia's leading retailer.

DFI Retail Group is an equal opportunity employer and responsible for ensuring that all personal information collected from each Candidate presented to DFI Retail Group is used for recruitment purposes only and the personal data will be kept and handled confidentially. We will retain the applications of candidates not selected for a period of no more than 24 months. The data collection process is in accordance with all applicable laws and compliant with the Code of Practice on Human Resource Management

To find out more about Our Businesses and Our People, please visit our website: https://www.DFIretailgroup.com

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst
Senior Security GRC Analyst

Hammerjack Pty Ltd • Philippines

On-site
PHP 3,769,000 - 5,653,000
Senior Security GRC Lead: Policy, Risk & Compliance
Senior Security GRC Lead: Policy, Risk & Compliance

DFI Technology (Philippines) • Mandaluyong

On-site
PHP 1,200,000 - 1,900,000
Senior Security GRC Analyst: Risk, Policy & Compliance
Senior Security GRC Analyst: Risk, Policy & Compliance

Hammerjack Pty Ltd • Philippines

On-site
PHP 3,769,000 - 5,653,000
Senior Manager, Security Operations And Assurance, Information Technology
Senior Manager, Security Operations And Assurance, Information Technology

City Developments Limited • Santo Niño 1st

On-site
PHP 1,800,000 - 2,400,000
Senior Specialist, GRC
Senior Specialist, GRC

LaVie • Manila

On-site
PHP 1,200,000 - 1,800,000
Cyber Security Specialist
Cyber Security Specialist

Sterling Global Call Center, Inc. • Pasig

On-site
PHP 900,000 - 1,300,000
Operations Monitoring Analyst
Operations Monitoring Analyst

Hammerjack Pty Ltd • Philippines

On-site
PHP 360,000 - 480,000
Sr. Specialist, GRC
Sr. Specialist, GRC

LaVie Resort and Casino Manila • Manila

On-site
PHP 550,000 - 900,000
Information Technology Procurement Manager
Information Technology Procurement Manager

DFI Technology (Philippines) • Mandaluyong

On-site
PHP 900,000 - 1,500,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Copeland India Private Ltd. • Quezon City

Hybrid
PHP 700,000 - 1,000,000
Flexible benefits plans
Paid parental leave
Vacation and holiday leave