IT.Security - Risk Analyst
HybridMakati City, Metro Manila, Philippines
Job Summary
Oversee Citco's Information Security Management System by performing risk and controls maturity assessments, conducting ISO 27001/2 audits, and executing service provider due diligence reviews. Liaise with internal stakeholders, auditors, and cross-functional teams to maintain compliance with security frameworks, document assessment results, and present findings to Senior Management. Collaborate with Audit, Operations, and Risk Management to remediate issues, manage security databases, and establish the organization's risk management program. Maintain expertise on security trends through research and training, while assisting with metrics programs and training other staff. Work independently with strong project management skills, manage multiple concurrent tasks, and demonstrate flexibility for international travel as needed.
Required Qualifications
- Bachelor's/College Degree in Computer Science/Information Technology or equivalent
- five or more years working in governance, risk and compliance; leading audit and risk assessment projects; and performing risk analysis and compliance remediation
- three or more years of experience in developing solutions using ISO 27001/2 and COBIT guidelines
- CISA certifications
- good foundation on IT security and IT-related topics
- Reliable and prepared to undertake international travel, if needed
- Work independently with or without direction and or supervision
- Proactive with good project management and organizational skills
- Strong negotiation and influencing skills
- Confident personality with ability to communicate clearly and succinctly
- Accept responsibility and personal accountability
- Demonstrate flexibility and adaptability in approach to work
- Demonstrate use of professional judgment on the job
- Demonstrate effective teamwork and working relationships with others, both from Citco and external clients
- Demonstrate a self-directed approach to learning new technologies in the field; pursue professional development
- Ability to effectively manage multiple concurrent projects/tasks with high attention to detail
Desired Qualifications
- Understanding of Basel II, SAS70, and SOC I & II requirements and other best practices a plus
- Other security certifications such as ISO 27001 Lead Auditor certification, CRISC, CISSP, CISM and other audit-, risk- and security-related certifications a plus
- Working knowledge of Protiviti, Prevalent platform, Team Central, JIRA and Confluence a plus
- Working knowledge on third party risk assessments a plus
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.