10 дней назад
Information Security Risk Manager
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Risk Manager (Fintech/ISO 27001): Owning information security risk management, control assurance, and ISMS governance for a regulated banking, consumer finance, and technology group with an accent on risk assessment, control effectiveness, and governance reporting. Focus on maintaining risk registers and ISO 27001 evidence, validating controls across IAM, cloud, endpoint security, and secure development, and driving remediation of deficiencies and exceptions.
Location: Remote from Serbia, the European Union, Georgia, Kazakhstan, or Poland; core collaboration hours are 12:00–18:00 Manila time (UTC+8).
Company
Technology-driven financial company building banking and lending products across Southeast Asia, starting in the Philippines.
What you will do
- Own information security risk assessment, treatment, acceptance, monitoring, and reporting.
- Assess control design and operating effectiveness across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
- Maintain the security control framework and test controls using evidence, data, sampling, and technical validation.
- Maintain the ISO 27001 ISMS, including policies, standards, Statement of Applicability, risk records, evidence, exceptions, and security registers.
- Define KRIs and control metrics and provide decision-ready reporting to governance forums and the Group CISO.
- Track deficiencies, findings, exceptions, and remediation actions with control owners.
Requirements
- Practical experience in information security risk management, including inherent and residual risk, treatment, acceptance, control effectiveness, and risk appetite.
- Technical depth to critically assess security controls across IAM, cloud, endpoint security, monitoring, vulnerability management, data protection, and secure development.
- Hands-on experience reviewing or testing controls and distinguishing documented controls from effective controls.
- Working knowledge of ISO 27001 and the ability to turn complex risk and control information into concise management reporting.
- Experience with GRC platforms, structured risk and control registers, and evidence management.
Culture & Benefits
- Fully remote work with company-provided tools and equipment.
- Medical insurance support for the employee and family through co-funding or reimbursement, depending on location and policy limits.
- 22 vacation days, Philippine public holidays, and 15 sick days.
- Access to an internal mental health support specialist.
- Opportunities for expert meetups, conferences, speaking engagements, and industry publications.
- Company-sponsored trips to Manila and team experience opportunities in Southeast Asia.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Information Security & Compliance Manager (GRC)
12 дней назад
BS Information Security Specialist (GRC Analyst)
12 дней назад
GRC Specialist (Cybersecurity Compliance)
12 дней назад
GRC Specialist (Cybersecurity)
13 дней назад
Risk Manager (Cybersecurity)
11 дней назад