Third-Party Security Risk Analyst - Japanese Bilingual

RecruitNest Consulting

Philippines

Hybrid

PHP 1,339,000 - 1,562,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RecruitNest Consulting is seeking a Vendor Information Security Senior Analyst to join the VISM/IT Governance team. You will assess and manage information security risks from third-party vendors globally, ensuring risks are properly assessed, documented, and addressed across regions.

The role requires strong vendor risk management experience, knowledge of ISO 27001 and NIST, and JLPT N1. This is a hybrid role in Quezon City with on-site responsibilities and direct-hire employment.

Qualifications

  • Bachelor's degree in relevant field.
  • 5+ years in information security, risk, governance, compliance or third-party risk management.
  • Experience with vendor risk assessments and security control reviews.
  • Knowledge of ISO 27001 and NIST.
  • CISA, CRISC, CISSP or equivalent preferred.
  • Japanese language proficiency: JLPT N1.
  • Experience in financial services or insurance is advantageous.

Responsibilities

  • Perform information security risk assessments for vendors including those supporting Japan and other regions.
  • Review vendor security documents (audit, penetration testing, vulnerability reports).
  • Conduct virtual assessments and site visits as needed.
  • Collaborate with Procurement, business stakeholders, contract owners, Security, Privacy, BCP, Legal and Compliance teams.
  • Identify, document, and track vendor risk and control gaps.
  • Maintain vendor risk records using Archer or ProcessUnity.
  • Support remediation tracking and risk communications to stakeholders.
  • Support internal and external audits (regulatory and client).
  • Review vendor contracts for security in partnership with Legal and Compliance.

Skills

Vendor risk assessment
Information security
Regulatory compliance
Stakeholder management
Japanese language

Education

Bachelor's degree in Computer Science, Business, Finance, or related field

Tools

Archer
ProcessUnity

Job description

Job Expectations
  • Position Type: Experienced - Senior/Lead
  • Employment Type: Full-Time, Permanent (Direct Hire)
  • Work Setup & Location: Hybrid (2-3x onsite per week) - Commonwealth Avenue, Quezon City
  • Work Schedule: Weekdays; Mid/Night Shift
  • Budget: Up to ₱90K Salary + ₱50K Monthly Language Premium
  • Industry: Insurance & Financial Services
About the Job

We are looking for a Vendor Information Security Senior Analyst to join our client's Vendor Information Security Management (VISM) / IT Governance team. In this role, you will assess and manage information security risks related to third‑party vendors, including vendors supporting Japan and other regions. You will work with global teams to ensure vendor risks are properly assessed, documented, and addressed.

Key Responsibilities
  • Perform information security risk assessments for new and existing vendors, including vendors supporting Japan and other regions.
  • Review vendor security documents such as audit reports, penetration testing reports, and vulnerability reports.
  • Conduct virtual vendor assessments and site visits when required.
  • Work closely with Procurement, business stakeholders, contract owners, Security, Privacy, Business Continuity, Legal, and Compliance teams.
  • Identify, document, and track security risks and control gaps related to vendor engagements.
  • Maintain accurate vendor risk records using tools such as Archer or ProcessUnity.
  • Support remediation tracking and communicate risk updates to stakeholders.
  • Support internal and external audits, including regulatory and client audits.
  • Conduct security reviews of vendor contracts in partnership with Legal and Compliance teams.
  • Ensure vendor security practices align with information security frameworks such as ISO 27001, NIST, and PCI DSS.
  • Stay updated on cybersecurity risks, industry trends, and regulatory requirements.
  • Contribute to improving vendor risk management processes, policies, and procedures.
  • Support other initiatives related to information security, IT governance, and business continuity.
Qualifications
  • Bachelor's Degree in Computer Science, Business, Finance, or a related field.
  • At least 5 years of experience in Information Security, IT Risk, Governance, Compliance, Cybersecurity, Technology Audit, or Third-Party Risk Management.
  • Experience in vendor risk assessments and security control reviews.
  • Knowledge of IT risk and security frameworks such as ISO 27001 and NIST.
  • Experience with vendor risk management tools such as Archer or ProcessUnity is an advantage.
  • Experience in the financial services or insurance industry is a strong advantage.
  • CISA, CRISC, CISSP, or equivalent certification is preferred.
  • Strong analytical, communication, and stakeholder management skills.
  • Ability to manage multiple priorities in a global environment.
  • Japanese language proficiency: JLPT N1 is required.
  • Strong written and verbal communication skills in Japanese, with the ability to work effectively with Japan-based stakeholders and vendors.

-

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vendor Security & Risk Analyst (Hybrid)
Senior Vendor Security & Risk Analyst (Hybrid)

RecruitNest Consulting • Philippines

Hybrid
PHP 1,339,000 - 1,562,000
Vendor Risk Analyst I - McKinley - 12-Month Contract
Vendor Risk Analyst I - McKinley - 12-Month Contract

TP • Philippines

On-site
PHP 360,000 - 600,000
Third-Party Risk Manager
Third-Party Risk Manager

NightOwl Consulting Philippines Inc. • Philippines

On-site
Above market salary
HMO on Day 1
Government benefits
+4
Third-Party Risk Manager
Third-Party Risk Manager

NightOwl Consulting • Quezon City

On-site
Above market salary
HMO on Day 1
Performance-based Incentives
Senior Information Security Engineering Consultant
Senior Information Security Engineering Consultant

UnitedHealth Group • Cebu City

On-site
PHP 900,000 - 1,400,000
Third Party Vendor Analyst
Third Party Vendor Analyst

GR8 Global Philippines • Philippines

Hybrid
PHP 600,000 - 900,000
Senior Info Security Risk Analyst - NCR And Cebu
Senior Info Security Risk Analyst - NCR And Cebu

UnitedHealth Group • Cebu City

On-site
PHP 550,000 - 850,000
Senior Manager – InfoSec Risk and Compliance
Senior Manager – InfoSec Risk and Compliance

Sutherland • Morong

On-site
PHP 2,000,000 - 3,600,000
Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)
Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)

Sutherland • Mabalacat

On-site
PHP 1,500,000 - 2,300,000
Information Security Analyst | Hybrid in Taguig
Information Security Analyst | Hybrid in Taguig

Gratitude Philippines • Taguig

Hybrid
PHP 600,000 - 900,000