Назад
Company hidden
6 часов назад

Third Party Security Management Manager (Fintech)

Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Philippines
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Third Party Security Management Manager (Fintech): Leading and maturing a third-party security management program for financial solutions with an accent on risk assessment frameworks, governance, and security posture monitoring. Focus on managing security analysts, optimizing assessment processes, negotiating security clauses, and responding to third-party incidents.

Location: NCR - WGC, Philippines

Company

hirify.global operates GCash, a fintech company focused on innovative and convenient financial solutions for the Philippines.

What you will do

  • Lead the design and execution of initiatives that improve the maturity of the Third-Party Security Management program.
  • Lead, mentor, and develop a team of security analysts while ensuring high-quality assessments.
  • Define and maintain third-party security assessment frameworks, including risk tiers, methodologies, and reporting criteria.
  • Oversee third-party security control assessments, validation, ongoing monitoring, and risk-gap escalations.
  • Collaborate with Legal on security clauses and right-to-audit provisions in third-party contracts.
  • Lead third-party security incident response, mitigation, breach notification compliance, and reporting to senior leadership.

Requirements

  • Bachelor’s or Master’s degree in Cybersecurity, Information Technology, or a related field.
  • At least 7 years of experience in cybersecurity or information security, including 4 years managing or performing third-party security risk assessments.
  • Experience leading a security team and managing enterprise-scale third-party security risk programs.
  • Deep knowledge of NIST, ISO 27000 series, SOC 2, PCI DSS, and Cloud Security Alliance standards.
  • Experience with TPRM and GRC platforms such as OneTrust, Archer, ProcessUnity, or ServiceNow, plus ticketing systems such as JIRA.
  • Strong analytical, communication, risk negotiation, and data-driven process-automation skills.

Nice to have

  • CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor certification.
  • Project management skills.

Culture & Benefits

  • Career growth and development opportunities.
  • Work with a dynamic and collaborative team focused on fintech innovation.
  • Competitive and flexible compensation and benefits package.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →