2 дня назад
Cybersecurity GRC Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity GRC Analyst (Cybersecurity Governance, Risk and Compliance): Developing and maintaining cybersecurity policies, risk registers, control assessments, audit evidence, and compliance reporting with an accent on NIST, ISO 27001, CIS Controls, SOC 2, and third-party risk. Focus on evaluating security controls, managing DLP policies, supporting audits, and translating cybersecurity risks into clear guidance for business stakeholders.
Location: Quezon City, Manila, Philippines; hybrid work arrangement with on-site work three times per week. Mid-shift schedule: 4:00 PM–1:00 AM.
Company
is a global climate technologies company developing HVACR, cold chain, controls, software, and monitoring solutions focused on sustainability and energy efficiency.
What you will do
- Develop, implement, and maintain cybersecurity policies, standards, and procedures aligned with industry frameworks and regulatory requirements.
- Conduct risk assessments, security control evaluations, gap analyses, and compliance audits.
- Support internal and external audits involving NIST CSF, ISO 27001, CIS Controls, SOC 2, and regulatory obligations.
- Manage third-party risk assessments, vendor security evaluations, risk registers, compliance documentation, and audit evidence repositories.
- Track and report cybersecurity risks, controls, KPI/KRI metrics, and compliance status to technical and business stakeholders.
- Manage and fine-tune DLP policies for endpoint, network, and cloud environments, while providing security awareness training and guidance.
Requirements
- Bachelor’s degree in computer science, information systems, or a related field, plus 3 or more years of experience, or an equivalent combination of education and experience.
- At least 3 years of experience in cybersecurity, governance, risk, and compliance, including risk assessments, control evaluations, and compliance audits.
- Strong knowledge of NIST CSF, CIS Critical Security Controls, ISO 27001, NIST 800-53, FAIR, and cybersecurity policies and procedures.
- Excellent analytical, problem-solving, oral, written, and presentation skills, with the ability to communicate technical and business concepts to senior management.
- Ability to work independently and collaboratively, manage multiple projects, adapt to changing priorities, and operate effectively in a dynamic environment.
- Fluent English is required.
Nice to have
- Professional IT or cybersecurity certifications such as Security+, GCRP, or CGRC.
- Three to four years of experience in incident response, security operations, application security, or related cybersecurity roles.
- Experience designing and implementing cybersecurity reporting and KPI/KRI metrics.
- Additional language skills.
Culture & Benefits
- Work within a sustainability-focused climate technologies organization.
- Inclusive and collaborative environment with employee resource groups supporting culture and community building.
- Flexible benefits plans for employees and families.
- Paid parental leave, vacation leave, holiday leave, and flexible time-off plans.
- End-to-end employee development from onboarding through senior leadership.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →