Sr Cybersecurity Analyst - GRC

Dexcom Inc.

Philippines

On-site

PHP 900,000 - 1,300,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Full benefits program
Career development opportunities
Global growth opportunities
Tuition reimbursement

Job summary

Dexcom Inc. is seeking a Senior Cybersecurity Analyst to join the GRC Information Security team in the Philippines.

You will coordinate audit readiness, evidence collection, control owner preparation, and remediation tracking for internal and external audits, while supporting security certification and compliance activities. The role emphasizes risk assessments, control gap analysis, and reporting; you will optimize the OneTrust GRC platform, manage user access and workflows, and collaborate

Qualifications

  • Bachelor’s degree or equivalent practical experience in information security, information systems, computer science, business or related field.
  • 5+ years of experience in cybersecurity, information security, IT risk management, compliance or audit.
  • Experience configuring or supporting a GRC platform such as OneTrust, Archer, ServiceNow GRC, AuditBoard or LogicGate.
  • Working knowledge of ISO 27001, NIST CSF, NIST 800-53, PCI DSS, SOC 2, HIPAA or similar standards.
  • Experience supporting audit readiness, evidence collection, control testing and remediation activities.

Responsibilities

  • Coordinate audit readiness, evidence collection, control owner preparation, audit workflow tracking, findings management, and remediation follow-up for internal and external audits.
  • Support security certification, compliance, and assessment activities by partnering with control owners, cybersecurity teams, business stakeholders, and auditors.
  • Conduct and support risk assessments using defined risk criteria, scoring methodologies, risk tolerance levels, and treatment tracking processes.
  • Track control gaps, audit findings, risks, remediation plans, and risk treatment activities through closure.
  • Support mapping of applicable regulatory, framework, and internal policy requirements to controls, assessments, evidence requests, and reporting within the GRC platform.
  • Perform control mapping, gap analysis, and compliance assessments against applicable frameworks, standards, regulations, and internal policy requirements.
  • Support control testing, evidence collection, and continuous monitoring activities to assess control effectiveness and identify remediation needs.
  • Generate and maintain reports, dashboards, metrics, and status updates that communicate audit status, remediation progress, control health, risk trends, and compliance indicators.
  • Validate GRC data quality and work with stakeholders to improve completeness, accuracy, and consistency of records, assessments, evidence, and reporting.

Skills

GRC knowledge
Analytical ability
Cross-functional collaboration
Communication skills
Audit readiness

Education

Bachelor’s degree in information security or related field

Tools

OneTrust GRC
Archer
ServiceNow GRC
AuditBoard
LogicGate

Job description

Meet the team:

The Governance, Risk & Compliance (GRC) team partners with business, technology, privacy, legal, and security stakeholders to strengthen the organization's cybersecurity and compliance posture. We help identify and manage cyber risk, support regulatory and industry compliance programs, drive audit readiness, and promote a culture of security across the enterprise. Dexcom is seeking a Senior Cybersecurity Analyst to join the GRC Information Security team and support information security compliance, certification, audit, and risk management activities. The Senior Cybersecurity Analyst will coordinate with control owners, business stakeholders, auditors, and cybersecurity teams to prepare for audits, track findings, support risk treatment plans, and improve the consistency and effectiveness of GRC processes. This position will also contribute to security control assessment, testing, documentation, metrics, and continuous improvement efforts. And this role will manage and optimize the OneTrust GRC platform to support risk assessments, compliance workflows, evidence collection, control gap tracking, remediation activities, and reporting.

Where you come in:
  • You will coordinate audit readiness, evidence collection, control owner preparation, audit workflow tracking, findings management, and remediation follow-up for internal and external audits.
  • You will support security certification, compliance, and assessment activities by partnering with control owners, cybersecurity teams, business stakeholders, and auditors.
  • You will conduct and support risk assessments using defined risk criteria, scoring methodologies, risk tolerance levels, and treatment tracking processes.
  • You will track control gaps, audit findings, risks, remediation plans, and risk treatment activities through closure.
  • You will support mapping of applicable regulatory, framework, and internal policy requirements to controls, assessments, evidence requests, and reporting within the GRC platform.
  • You will perform control mapping, gap analysis, and compliance assessments against applicable frameworks, standards, regulations, and internal policy requirements.
  • You will support control testing, evidence collection, and continuous monitoring activities to assess control effectiveness and identify remediation needs.
  • You will generate and maintain reports, dashboards, metrics, and status updates that communicate audit status, remediation progress, control health, risk trends, and compliance indicators.
  • You will validate GRC data quality and work with stakeholders to improve completeness, accuracy, and consistency of records, assessments, evidence, and reporting.
  • You will configure, maintain, and support the OneTrust GRC platform to enable security risk assessments, compliance, audit, remediation, and reporting workflows.
  • You will manage user access, permissions, templates, workflows, assessments, and reporting configurations in alignment with defined GRC and cybersecurity requirements.
  • You will evaluate OneTrust features, releases, and configuration options and recommend practical improvements to usability, workflow efficiency, reporting, and stakeholder experience.
  • You will identify opportunities to improve GRC processes, workflows, templates, documentation, reporting, and automation.
  • You will support stakeholder enablement by developing guidance, job aids, and communications for OneTrust users, control owners, and GRC stakeholders.
  • You will monitor changes in regulations, industry standards, and best practices and help translate applicable changes into GRC processes, assessments, and reporting.
What makes you successful:
  • You possess a bachelor’s degree in information security, Information Systems, Computer Science, Business, or a related field, or equivalent practical experience.
  • You bring 5+ years of experience in cybersecurity, information security, IT risk management, compliance, audit, or a related information technology function, or an equivalent combination of education and experience.
  • Your experience configuring, administering, or supporting a GRC platform such as OneTrust, Archer, ServiceNow GRC, AuditBoard, LogicGate, or a similar tool.
  • Your working knowledge of cybersecurity, risk, and compliance frameworks such as ISO 27001, NIST CSF, NIST 800-53, PCI DSS, SOC 2, HIPAA, or similar standards.
  • Your experience supporting audit readiness, evidence collection, control testing, compliance assessments, issue tracking, and remediation activities.
  • Your ability to support risk assessments, control gap analysis, risk treatment plans, and remediation tracking across business and technology stakeholders.
  • Your ability to effectively work in cross-functional teams and collaborate with stakeholders from various departments.
  • Your strong analytical skills, including the ability to analyze GRC data, identify trends, validate data quality, and develop useful metrics or reports.
  • Your ability to plan, organize, and execute work related to GRC services.
  • Your strong written and verbal communication skills, with the ability to translate cybersecurity risk, compliance, and audit concepts into clear business language.
  • Your ability to partner with control owners, business stakeholders, auditors, and cybersecurity teams to resolve issues and drive audit, risk, and compliance activities to completion.
Nice to have qualifications
  • OneTrust GRC experience or certification.
  • Experience supporting cybersecurity, privacy, audit, or compliance activities in a regulated environment, such as medical device, healthcare, life sciences, financial services, or technology.
  • Professional certification such as CISSP, CISA, CISM, CRISC, Security+, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
  • Experience developing GRC dashboards, metrics, workflow automation, or reporting processes.
What you’ll get:
  • A front row seat to life changing CGM technology. Learn about our brave #dexcomwarriors community.
  • A full and comprehensive benefits program.
  • Growth opportunities on a global scale.
  • Access to career development through in-house learning programs and/or qualified tuition reimbursement.
  • An exciting and innovative, industry-leading organization committed to our employees, customers, and the communities we serve.
Travel Required:
  • 0-5%
Experience and Education Requirements:
  • Typically requires a Bachelor’s degree in a technical discipline, and a minimum of 5-8 years related experience or Master’s degree and 2-5 years equivalent industry experience or a PhD and 0-2 years experience.
AI in Hiring Notice:

We may use AI supported tools to help make our hiring process more efficient, consistent, and accessible for candidates around the world. All hiring decisions are made by people.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Cybersecurity Analyst - GRC
Sr Cybersecurity Analyst - GRC

Dexcom Philippines • Manila

Hybrid
PHP 900,000 - 1,300,000
Full benefits program
Hybrid work model
Career development opportunities
+1
Sr Cybersecurity Analyst - GRC Manila, Philippines + 1 more Posted 20 hours ago
Sr Cybersecurity Analyst - GRC Manila, Philippines + 1 more Posted 20 hours ago

Dexcom Inc. • Manila

On-site
PHP 1,200,000 - 1,800,000
Comprehensive benefits
Career development
Global opportunities
Lead Enterprise Cybersecurity Engineer (Security Engineering)
Lead Enterprise Cybersecurity Engineer (Security Engineering)

Dexcom Inc. • Philippines

Hybrid
PHP 1,800,000 - 2,400,000
Comprehensive benefits program
Global growth opportunities
Career development programs
Sr Cybersecurity Analyst
Sr Cybersecurity Analyst

Dexcom Inc. • Philippines

Hybrid
PHP 1,200,000 - 2,400,000
Sr. Cybersecurity Engineer (Security Assessment)
Sr. Cybersecurity Engineer (Security Assessment)

Dexcom Philippines • Philippines

On-site
PHP 1,200,000 - 1,800,000
Benefits package
Growth opportunities
Career development
+2
Sr. Cybersecurity Engineer (Security Assessment)
Sr. Cybersecurity Engineer (Security Assessment)

Dexcom Philippines • Cebu City

On-site
PHP 1,000,000 - 1,500,000
Comprehensive benefits
Global growth opportunities
Tuition reimbursement
+1
Sr Cybersecurity Engineer Security Assessment
Sr Cybersecurity Engineer Security Assessment

Dexcom Philippines • Philippines

On-site
PHP 1,200,000 - 2,400,000
Intelligence Analyst
Intelligence Analyst

Dexcom • Manila

On-site
PHP 900,000 - 1,400,000
Intelligence Analyst - Geopolitical
Intelligence Analyst - Geopolitical

Dexcom Inc. • Taguig

On-site
PHP 420,000 - 700,000
Benefits program
Global growth opportunities
In-house learning / tuition assistance
+1
Intelligence Analyst
Intelligence Analyst

Dexcom Inc. • Manila

On-site
PHP 600,000 - 900,000