We are seeking a skilled Security Analyst reporting to our Group Head of Technology that will play a critical role in protecting our organisation's information systems and data. This position will be responsible for managing our security infrastructure, responding to threats, and ensuring our security posture remains robust and compliant with industry standards.
Key accountabilities
Security Platform Management
Administer and manage CrowdStrike security platform, including deployment, configuration, and optimization
Monitor security alerts and events through CrowdStrike console
Perform regular health checks and ensure platform updates are applied
Manage endpoint detection and response (EDR) activities
Configure and fine-tune detection rules and policies
Threat Detection & Response
Monitor, analyse, and respond to security incidents and alerts
Investigate suspicious activities and potential security breaches
Perform root cause analysis on security incidents
Document incident response procedures and maintain incident logs
Implement remediation measures and track resolution progress
Security Reporting & Communication
Prepare regular security status reports for management
Provide updates on security metrics, incidents, and trends
Generate monthly and quarterly security dashboards
Present findings and recommendations to stakeholders
Respond to internal and external due diligence queries regarding security controls and practices
Threat Intelligence & Awareness
Stay current with emerging security threats, vulnerabilities, and attack vectors
Monitor threat intelligence feeds and security advisories
Assess the relevance and impact of new threats to the organisation
Share threat intelligence insights with the team
Recommend proactive security measures based on threat landscape
Security Testing & Compliance
Coordinate and manage annual penetration testing exercises
Work with external security assessors and penetration testers
Review penetration test findings and develop remediation plans
Track and verify remediation of identified vulnerabilities
Ensure compliance with Essential Eight framework requirements
Document security controls and maintain compliance evidence
Vulnerability Management
Conduct regular vulnerability scans and assessments
Prioritise vulnerabilities based on risk and business impact
Track remediation efforts and coordinate with IT teams
Maintain vulnerability management database and reporting
Verify patch compliance across systems and endpoints
Access Control & Identity Management
Ensure principle of least privilege is maintained
Monitor privileged account usage and activities
Security Monitoring & Log Analysis
Review security logs from various systems and applications
Correlate events across multiple security tools
Identify anomalous behaviour and potential security issues
Maintain and tune security monitoring rules and alerts
Archive logs in compliance with retention policies
Security Tools Administration
Manage antivirus, anti-malware, and endpoint protection solutions
Administer firewalls, intrusion detection/prevention systems
Maintain data loss prevention (DLP) tools
Configure and manage web filtering and email security gateways
Ensure security tools are properly integrated and functioning
Change Management & Configuration Review
Review changes to critical systems for security implications
Participate in change advisory board meetings
Assess security impact of proposed system changes
Verify security configurations align with hardening standards
Maintain secure baseline configurations
Vendor & Third-Party Risk Management
Assess security posture of vendors and third-party providers
Review vendor security documentation and certifications
Monitor compliance with contractual security requirements
Participate in vendor security assessments
Support procurement process with security evaluations
Backup & Disaster Recovery
Verify security of backup systems and processes
Test backup restoration procedures periodically
Review disaster recovery and business continuity plans from a security perspective
Ensure encrypted backups are maintained and accessible
Participate in disaster recovery exercises
Documentation & Continuous Improvement
Maintain security policies, procedures, and documentation
Create and update security runbooks and playbooks
Contribute to security awareness and training initiatives
Develop security metrics and KPIs
Identify opportunities for security process improvements
Participate in security projects and initiatives
Conduct security tabletop exercises
Essential
4+ years working in information security or cybersecurity operations
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field
Familiarity with fund management, non-bank lending industry and regulatory landscape.
Hands-on experience with security monitoring and incident response
Desirable
Relevant security certifications (Security+, CySA+, CEH, GCIH, or similar)
CrowdStrike Certified Falcon Administrator or similar certification
Experience with compliance frameworks (ISO 27001, NIST, CIS Controls)
Familiarity with scripting languages (PowerShell, Python)
Knowledge of Australian government security frameworks (ACSC, ISM)
Ability to explain technical security concepts to non-technical stakeholders
Proven experience with CrowdStrike or similar EDR/XDR platforms
Strong understanding of security principles, threats, and vulnerabilities
Knowledge of Windows and Linux operating systems
Familiarity with network protocols, firewalls, and security technologies
Experience with security information and event management (SIEM) tools
Knowledge of penetration testing methodologies and vulnerability management
Personal
A team player who demonstrates enthusiasm, resilience and ethical behaviour
Ability to think outside the box while maintaining an unbiased, risk and analytically driven assessment of alternate options when decisioning applications.
An ability to liaise well with others of all levels and source information and delegate efficiently
Honest and open both in actions and words with a drive to achieve results without sacrificing culture
Excellent written and verbal communication skills
Strong attention to detail, a mature positive attitude and strong work ethic
Work Setup:
Shift: Dayshift Setup: Onsite Location: Pasig
By Applying, you give consent to collect, store, and/or process personal and/or sensitive information for the purpose of recruitment and employment may it be internal to Cobden & Carter International and/or to its clients.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the Philippines.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the Philippines, connecting you to thousands of jobs fast!
Find the best jobs in the Philippines, apply in 1 click and get a job today!