Third Party Risk Management - IT Security Specialist

John Clements Consultants, Inc.

Mandaluyong

On-site

PHP 800,000 - 1,200,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

John Clements Consultants, Inc. is seeking an IT Security Specialist - Third-Party Risk Management to monitor security policies across the global IT landscape, including vendors and service providers, and to act as the first contact for security incidents and tickets.

You must have 3+ years in third-party risk management in an international environment and 5+ years in IT security, with strong knowledge of threats, networking, and security controls such as MFA, encryption, and access management.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or a related field.
  • MUST HAVE experience in Third-Party Risk Management with at least 3 years in an international environment
  • MUST HAVE IT Security experience for at least 5 yrs.
  • Strong understanding of security threats, risks, networking, TCP/IP, security incident response, and security technologies such as access control, encryption, and multi-factor authentication.
  • Hands-on experience with Microsoft 365 Security Suite, Privileged Access Management (PAM), Vulnerability Management, network and security monitoring tools, and preferably firewall and router administration.
  • Experience with security and privacy frameworks such as NIST, MITRE ATT&CK, and GDPR.
  • Ability to analyze security reports, recommend appropriate security controls and mitigations, and effectively investigate and respond to security incidents.
  • Self-driven and able to work independently, with strong communication, analytical, critical thinking, problem-solving, interpersonal, and teamwork skills.

Responsibilities

  • Third-Party Risk Management – Identify, assess, and mitigate cybersecurity risks associated with external vendors, service providers, applications, and services, including security compliance evaluations.
  • Incident Management & Security Operations – Detect, investigate, and resolve security incidents within defined SLAs by analyzing alerts, correlating security data, determining root causes, assessing impact, and escalating out-of-scope incidents to the appropriate teams or vendors.
  • Identity & Email Security Support – Respond to user inquiries on suspicious emails, identify phishing/spam threats, provide authentication support, and investigate high-risk sign-ins or compromised accounts.
  • Data Privacy & Breach Response – Respond to personal data breach incidents, assist in containment and remediation, recommend preventive measures, and prepare incident reports.
  • Security Governance & Continuous Improvement – Review and optimize firewall policies and rule bases, update security policies, maintain SOC documentation, recommend process improvements, and provide regular security reporting.
  • Threat Intelligence & Security Monitoring – Stay up to date on cybersecurity trends, vulnerabilities, and emerging threats by leveraging threat intelligence, data feeds, and security tools to strengthen the organization's security posture.

Skills

Third-Party Risk Management
IT Security
Networking
TCP/IP
Security Incident Response
MFA
Access Control
Encryption
PAM
Vulnerability Management
Security Monitoring Tools
NIST
MITRE ATT&CK
GDPR

Education

Bachelor's degree in Computer Science, Information Technology, or a related field

Tools

Microsoft 365 Security Suite
Privileged Access Management (PAM)
Vulnerability Management
Network/Security Monitoring Tools
Firewall/Router Administration

Job description

About the role

The IT Security Specialist - Third-Party Risk Management is responsible for monitoring, applying, and maintaining security policies and guidelines for the global IT landscape, including Vessels, Depots, Terminals and Seafarms and acts as first point of contact for all security related incidents and tickets. This includes ownership and management of security risks, incidents and problem tickets assigned to third-party support and/or solution providers and risks assessments of third parties. The role requires strong interaction with the IT Security Officer, regional Service Delivery teams, security vendors and managed (security) service provider.

Key responsibilities
  • Third-Party Risk Management – Identify, assess, and mitigate cybersecurity risks associated with external vendors, service providers, applications, and services, including security compliance evaluations.
  • Incident Management & Security Operations – Detect, investigate, and resolve security incidents within defined SLAs by analyzing alerts, correlating security data, determining root causes, assessing impact, and escalating out-of-scope incidents to the appropriate teams or vendors.
  • Identity & Email Security Support – Respond to user inquiries on suspicious emails, identify phishing/spam threats, provide authentication support, and investigate high-risk sign-ins or compromised accounts.
  • Data Privacy & Breach Response – Respond to personal data breach incidents, assist in containment and remediation, recommend preventive measures, and prepare incident reports.
  • Security Governance & Continuous Improvement – Review and optimize firewall policies and rule bases, update security policies, maintain SOC documentation, recommend process improvements, and provide regular security reporting.
  • Threat Intelligence & Security Monitoring – Stay up to date on cybersecurity trends, vulnerabilities, and emerging threats by leveraging threat intelligence, data feeds, and security tools to strengthen the organization's security posture.
About you
  • Bachelor's degree in Computer Science, Information Technology, or a related field.
  • MUST HAVE experience in Third-Party Risk Management with at least 3 years in an international environment
  • MUST HAVE IT Security experience for at least 5 yrs.
  • Strong understanding of security threats, risks, networking, TCP/IP, security incident response, and security technologies such as access control, encryption, and multi-factor authentication.
  • Hands-on experience with Microsoft 365 Security Suite, Privileged Access Management (PAM), Vulnerability Management, network and security monitoring tools, and preferably firewall and router administration.
  • Experience with security and privacy frameworks such as NIST, MITRE ATT&CK, and GDPR.
  • Ability to analyze security reports, recommend appropriate security controls and mitigations, and effectively investigate and respond to security incidents.
  • Self-driven and able to work independently, with strong communication, analytical, critical thinking, problem-solving, interpersonal, and teamwork skills.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security - Third Party Risk Management Specialist
IT Security - Third Party Risk Management Specialist

Socium - Teams Done Differently • Mandaluyong

Hybrid
PHP 900,000 - 1,300,000
Hybrid work arrangement
Career growth opportunities
Competitive compensation package
+1
IT Security Risk Assessment Officer
IT Security Risk Assessment Officer

Metropolitan Bank & Trust Company • Metro Manila

On-site
PHP 900,000 - 1,200,000
IT Vendor Security Analyst
IT Vendor Security Analyst

HRTX • Santa Rosa

On-site
PHP 1,200,000 - 1,800,000
Global IT Security & Third-Party Risk Specialist
Global IT Security & Third-Party Risk Specialist

Stolt Sea Farm SA • Mandaluyong

Hybrid
PHP 900,000 - 1,200,000
Career growth
Competitive compensation
Hybrid work model
Information Security Analyst
Information Security Analyst

Satellite Office • Pasig

Hybrid
PHP 1,000,000 - 2,000,000
Operational IT Security Specialist
Operational IT Security Specialist

Stolt Sea Farm SA • Mandaluyong

Hybrid
PHP 900,000 - 1,200,000
Career growth
Competitive compensation
Hybrid work model
Third Party Vendor Analyst
Third Party Vendor Analyst

GR8 Global Philippines • Philippines

Hybrid
PHP 600,000 - 900,000
Senior Security Consultant
Senior Security Consultant

Hunter's Hub Inc. • Taguig

On-site
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
IT Information Security Manager
IT Information Security Manager

Manila Water Philippine Ventures • Philippines

On-site
PHP 1,200,000 - 1,800,000