Now hiring

SECURITY ASSURANCE AND ASSESSMENT OFFICER (Taguig, Philippines) @ MBTCHCM

Taguig, PhilippinesOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><span style="font-size:12.0pt"><strong>Be #InGoodHands with Metrobank!</strong></span></p> <p> </p> <p><span style="font-size:12.0pt">Here at Metrobank, we don&apos;t simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank&apos;s strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation&apos;s economic and social development. With Metrobank, a meaningful life is within your reach!</span></p> <p style="margin:0.0in 0.0in 9.75pt;text-align:justify;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="color:#3c3c3c;background-color:white;font-size:12.0pt"> </span></p> <p style="margin:0.0in 0.0in 9.75pt;text-align:justify;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt"><strong><span style="font-family:Arial, sans-serif;color:#3498db;background-color:white">Position Title: </span></strong><span style="font-family:Arial, sans-serif;color:black;background-color:white">Security Assurance and Assessment Officer</span></span></p> <p style="margin:0.0in 0.0in 9.75pt;text-align:justify;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="color:#3c3c3c;background-color:white;font-size:12.0pt"> </span></p> <p style="margin:0.0in 0.0in 8.25pt;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt"><strong><span style="font-family:Arial, sans-serif;color:#3498db;background-color:white">Job Summary:</span></strong></span></p> <p style="margin:0.0in 0.0in 9.75pt;text-align:justify;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Develop tactical plans and programs for the establishment and maintenance of the Bank’s zthird-party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset-based risk assessment. Analyze and review of complex bank processes, application system and network security implementation and third-party relationships to identify potential risk including the determination of risk mitigation strategies. Analysis and review of complex application system and network security implementation on the current production environments to identify potential risk including the determination of risk mitigation strategies. Recommend strategies to control risks from inadequate protection of confidentiality, integrity and availability of the information assets, processing facilities and connected services.</span></p> <p style="margin:0.0in 0.0in 9.75pt;text-align:justify;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"> </p> <p style="margin:0.0in 0.0in 9.75pt;text-align:justify;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt"><strong><span style="font-family:Arial, sans-serif;color:#3498db;background-color:white">Specific Duties &amp; Responsibilities:</span></strong></span></p> <ul> <li style="text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Prepares tactical plans and/or programs in the conduct of information, third party and system security risk assessments.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Identify the Bank’s critical assets, threats to these assets, vulnerabilities, and reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Coordinate and assess the security performance of third-party vendors that collect, process, transmit, and store client data</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Performs threat modelling-based system security risk assessment for all IT systems and other IT assets, as applicable</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Analyze and assess the impact of changes in process, technical changes and systems enhancements and third-party relationships.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information and information processing facilities to mitigate information security risk.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Formulates, recommends information security policies and procedures on physical, environmental and personnel security with respect to results of information security assessment activities. </span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Responsible for coordinating across all business units and stakeholders in gathering information in preparation to the conduct of information, third party and system security risk assessment.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Articulate security findings and risk remediation strategies through issuance of risk assessment report. Track and follow-up status of risk mitigation activities. </span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Ensures security risk register is maintained and kept updated including status of remediation activities.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Executes and monitors accomplishment of the risk assessment plans and programs.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Articulate security findings and risk remediation strategies through issuance of risk assessment report; writing comprehensive, concise and understandable to non-technical. Tracking and follow up on status of mitigation activities.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Maintain and track library of records and documentation.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Investigation of applicable reported incidents related to information handling and data privacy. </span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Keep abreast of and apply information, IT and third party security trends and regulatory and compliance changes affecting the security of landscape, security best practices, threat landscape (emerging and existing) and apply them in daily work.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Review the work of other Security Quality and Assurance Risk Assessors; guides and mentors them.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Proactively works with the Department Head in implementing programs for the continuous improvement of the bank’s information security plans and strategies.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;text-align:justify;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#3c3c3c;background-color:white">Perform other information security risk management and compliance related duties and responsibilities as directed by the Department Head.</span></li> </ul> <p style="text-align:justify;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif;margin:0.0in 0.0in 1.0E-4pt 0.0px"> </p> <p style="margin:0.0in 0.0in 9.75pt;text-align:justify;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt"><strong><span style="font-family:Arial, sans-serif;color:#3498db;background-color:white">Qualifications:</span></strong></span></p> <ul style="margin-bottom:1.0E-4pt;margin-top:0.0px"> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Knowledgeable on various compliance and regulatory requirements (i.e., BSP, DPA, PCI-DSS, etc.)</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Working knowledge of various information and IT security domains and controls related to third party risks, data security and risk management, data transmission integrity. This includes understanding various processes related to the service, product or solution provided by vendors to the Bank and its links to bank processes. </span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Has experience in information security governance, controls assurance, risk assessments and key risk indicators development</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Experience in IT general controls and auditing a plus. Strong background on network and application system security risk assessments.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Ability to plan, execute, and document assessment activities following established processes and procedures with minimal guidance</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Ability to lead and work well with the team, internal, and external clients. Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Analytical and risk identification skills to analyze a variety of information security –related risk situations and develop recommendations on the best course of action.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Good Project management skills: to lead and manage accomplishments of assigned tasks/risk assessment activities.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Possess excellent time management skills, thrive in a fast paced demanding environment</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Be a self-managed self-starter with good organizational skills to include good follow-up skills</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Be able to work under pressure on multiple assessments/projects simultaneously</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Strong attention to detail, analytical, and problem-solving skills. </span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Strong learning agility with the ability to learn new processes</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">College graduate or any degree on Information technology, Information Security, or related field of expertise.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Certification may include CISA, CISM, CRISC, PCI-DSS, etc.</span></li> <li style="margin:0.0in 0.0in 1.0E-4pt 0.0px;line-height:normal;background-color:white;font-size:12.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt;font-family:Arial, sans-serif;color:#222222;background-color:white">Knowledge in using MS office tools such as PowerPoint, word, excel and project.</span></li> </ul> <p style="margin:0.0in 0.0in 8.25pt;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="color:#3c3c3c;background-color:white;font-size:12.0pt"> </span></p> <p style="margin:0.0in 0.0in 8.25pt;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt"><strong><span style="font-family:Arial, sans-serif;color:#3498db;background-color:white">Other Details:</span></strong></span></p> <p style="margin:0.0in 0.0in 8.25pt;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt"><strong><span style="font-family:Arial, sans-serif;color:#3498db;background-color:white">Rank:</span></strong><span style="font-family:Arial, sans-serif;color:#3c3c3c;background-color:white"> Junior Officer</span></span></p> <p style="margin:0.0in 0.0in 8.25pt;line-height:normal;background-color:white;font-size:11.0pt;font-family:Calibri, sans-serif"><span style="font-size:12.0pt"><strong><span style="font-family:Arial, sans-serif;color:#3498db;background-color:white">Unit:</span></strong><span style="font-family:Arial, sans-serif;color:#3c3c3c;background-color:white"> Financial and Control Sector / Information Security Division / Security Quality Assurance and Assessment Department</span><span style="color:#3c3c3c;background-color:white"><br></span><strong><span style="font-family:Arial, sans-serif;color:#3498db;background-color:white">Location:</span></strong><span style="font-family:Arial, sans-serif;color:#222222;background-color:white"> Metrobank Center, Taguig</span></span></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores