Sr. Security Analyst

Concentrix

Manila

On-site

PHP 2,460,024 - 4,305,043

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Concentrix is seeking a skilled Information Security Specialist in Manila to lead security assessments, implement controls, and ensure compliance with industry standards. You will be tasked with monitoring security incidents and training staff on best practices.

The ideal candidate will have a bachelor's degree in Computer Science or a related field, relevant certifications, and proven experience in information security. This role ensures adherence to security policies and enhances the organization's overall security posture.

Qualifications

  • Bachelor's degree in Computer Science or related field, with relevant certifications such as CISSP, CISA, or CISM.
  • Proven experience in information security or compliance.
  • Strong knowledge of security frameworks, such as NIST, CIS, or ISO 27001.
  • Excellent analytical and problem-solving skills with attention to detail.

Responsibilities

  • Conduct regular security assessments and vulnerability scans.
  • Implement and maintain security controls against unauthorized access.
  • Monitor security events, analyze logs, and respond to breaches.
  • Develop, test, and enforce security policies and procedures.

Skills

Information security
Compliance
Risk assessment
Analytical skills
Problem-solving
Communication
Collaboration

Education

Bachelor's degree in Computer Science or related field
Relevant certifications (CISSP, CISA, CISM)

Tools

Tenable Nessus
Burp Suite
CrowdStrike
Firewalls
VPN concentrators

Job description

Responsibilities
  • Conduct regular security assessments and vulnerability scans to identify potential risks and weaknesses in our information systems.
  • Implement and maintain security controls to protect against unauthorized access, data breaches, and other security threats.
  • Monitor security events and incidents, analyze security logs, and respond to security breaches promptly.
  • Assist in the development, testing, and enforcement of security policies, procedures, and guidelines.
  • Collaborate with IT teams to ensure secure configurations of systems, applications, and network devices.
  • Stay up-to-date with the latest security technologies, trends, and best practices to continually improve our security posture.
Compliance and Regulation
  • Ensure compliance with relevant industry standards, laws, regulations, and contractual obligations (e.g., GDPR, CPRA, ISO 27001, PCI DSS).
  • Conduct compliance assessments and audits to validate adherence to security standards and requirements.
  • Prepare reports and documentation for internal and external stakeholders to demonstrate compliance.
  • Collaborate with legal and regulatory affairs teams to interpret and implement applicable data protection and privacy laws.
  • Provide guidance to internal teams on compliance-related matters and assist in remediation efforts when needed.
Risk Assessment and Mitigation
  • Identify, assess, and prioritize information security risks based on the potential impact and likelihood of occurrence.
  • Develop risk mitigation strategies and recommendations to enhance overall security posture.
  • Work with business units to ensure that security measures align with business objectives and are properly integrated into their processes.
Training and Awareness
  • Conduct security awareness training sessions for employees to promote a security-conscious culture.
  • Educate staff on security policies, best practices, and procedures to reduce human-related security risks.
Testing, Incident Response, and Forensics
  • Conduct application and environment tests for new and emerging security threats and vulnerabilities.
  • Participate in incident response activities and support investigations into security incidents.
  • Assist in collecting evidence, conducting forensic analysis, and preparing incident reports.
Qualifications and Requirements
  • Bachelor's degree in Computer Science, Information Technology, or a related field. Relevant certifications such as CISSP, CISA, or CISM are a plus.
  • Proven experience in information security, compliance, or a related field.
  • Strong knowledge of security frameworks, such as NIST, CIS, or ISO 27001.
  • Familiarity with regulatory requirements and privacy laws (e.g., GDPR, CPRA, etc.).
  • Understanding of risk assessment methodologies and risk management practices.
  • Experience with security tools and technologies, such as firewalls, IDS/IPS, SIEM, etc.
  • Excellent analytical and problem-solving skills with attention to detail.
  • Effective communication and collaboration skills to work with cross-functional teams.
  • Ability to stay abreast of industry trends and emerging security threats.
  • Proven skills in application and environment security, exploit, and vulnerability testing
Relevant Technologies and Skills
  • Experience in Privacy Management and regulation. GDPR, CPRA, CCPA, etc.
  • Experience with AWS, OCI, and Azure Cloud.
  • Expertise using tools such as Tenable Nessus, Burp Suite, SUMO Cloud, CrowdStrike.
  • Experience with Firewalls, Load Balancers, WAFs, VPN concentrators.
  • Experience with hardening standards for servers, desktops, laptops, networking devices.
  • Experience with Pen Tests and Vulnerability Scans.
  • Understanding of malware, network threats, attack vectors, incident response.
  • Information security issues in an open, highly distributed networked environment.
  • The secure use and system administration of desktop and server operating systems.
  • Internet protocols and data formats such as HTTP, TLS, SSL, HTML, and XML.
  • Database technologies such as Elasticsearch, SQL, or Oracle.
  • Identification and authentication technologies.
  • Knowledge of cloud, container-based and virtualization architectures.
  • Encryption techniques, algorithms, and approaches.
  • Higher education or government agency information security experience
  • Experience handling and protecting information at a variety of sensitivity levels
  • Understanding of laws and standards such as FISMA, GLBA, FERPA, PCI DSS, ISO, and NIST
  • Information security certifications such as CISSP, CSFA, CEH, GWAPT, GPEN, etc, a plus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Artech Technology Inc. • Quezon City

On-site
PHP 3,527,000 - 5,292,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
Senior Security Officer
Senior Security Officer

Open iT, Inc. • Lucena

On-site
PHP 700,000 - 900,000
Staff Security Engineer
Staff Security Engineer

Koine Ventures Inc. • Manila

On-site
PHP 1,200,000 - 1,800,000
IT Security Analyst
IT Security Analyst

Wisefund Finance Corporation Ortigas • Metro Manila

On-site
PHP 600,000 - 900,000
Data Security Analyst (Work from Home)
Data Security Analyst (Work from Home)

Quantrics Enterprises Inc. • Manila

On-site
PHP 600,000 - 1,100,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
Security Officer
Security Officer

Open iT, Inc. • Lucena

On-site
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
IT Security Specialist
IT Security Specialist

IBEX Global Solutions (Philippines) Inc. • Mandaluyong

On-site
PHP 450,000 - 750,000