4 дня назад
Senior GRC Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior GRC Analyst (Cybersecurity): Managing governance, risk, and compliance activities to support ongoing ISO27001 certification and broader security assurance with an accent on risk assessments, internal audits, third-party assessments, and regulatory analysis. Focus on maintaining risk and information asset registers, managing a GRC platform, coordinating external audits, and translating product compliance obligations into requirements for Engineering, Product, Legal, and Operations.
Location: Manila, Philippines; hybrid workplace
Company
develops AV networking media products that manage audio and video channels over a single network.
What you will do
- Conduct information security risk assessments and third-party security assessments against ISMS policies, guidelines, and controls.
- Design and perform internal audits, document findings, and report results to management.
- Manage and maintain a GRC platform for tracking and reporting compliance activities.
- Coordinate with ISO27001 auditors to support successful audits and ongoing certification.
- Own the risk assessment process, including the risk register, information asset register, and incident register.
- Monitor product compliance regulations and standards, assess their impact, and translate obligations into requirements for Engineering, Product, Legal, and Operations.
Requirements
- Bachelor’s degree or industry certifications in cybersecurity, risk management, governance, or a related field.
- 5+ years of direct information security experience focused on governance, risk, and compliance.
- 3+ years of experience preparing for ISO27001 audits and preparing responses with auditors.
- Thorough understanding of ISO27001:2022 and associated guidelines.
- Experience with GRC platforms such as ISMS.online, Vanta, SecureFrame, or similar tools.
- Ability to work independently and collaborate with developers, engineers, business, operations, and external stakeholders.
Nice to have
- CISA, CISSP, or CRISC certification.
Culture & Benefits
- Hybrid work arrangement in Manila.
- Values centered on Excellence, Courage, Integrity, Innovation, and Teamwork.
- Flexible and change-oriented approach with a focus on continuous improvement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Third Party Risk Analyst (Cybersecurity)
3 дня назад
Senior Manager – InfoSec Risk and Compliance (Cybersecurity)
2 дня назад
Cybersecurity GRC Analyst
6 дней назад
Regional Information Security Manager (Cybersecurity)
12 часов назад
PCI Compliance Analyst (Fintech)
2 дня назад