M

Security Assurance And Assessment Officer

icon briefcase Job Type : Full Time

Number of Applicants

 : 

000+

Click to reveal the number of candidates who applied for this job.
icon loader
Apply Now
icon loader Apply Now

Let AI Supercharge Your Job Hunt!

JobCopilot scans 500,000+ company career sites daily to find jobs for you

Never miss an opportunity Save hours by auto-filling applications forms Land more interviews with tailored applications
happy man
thunder iconActivate JobCopilot

Job Description - Security Assurance And Assessment Officer


This role is open for both iAspire candidates and external talents. We encourage you to refer candidates to this role.


 


Position Title: Security Assurance and Assessment Officer


 


Job Summary:


Develop tactical plans and programs for the establishment and maintenance of the Bank’s zthird-party information security risk management framework and ensure alignment with the enterprise risk framework. Performs third party security, system security and information asset-based risk assessment. Analyze and review of complex bank processes, application system and network security implementation and third-party relationships to identify potential risk including the determination of risk mitigation strategies. Analysis and review of complex application system and network security implementation on the current production environments to identify potential risk including the determination of risk mitigation strategies. Recommend strategies to control risks from inadequate protection of confidentiality, integrity and availability of the information assets, processing facilities and connected services.


 


Specific Duties & Responsibilities:



  • Prepares tactical plans and/or programs in the conduct of information, third party and system security risk assessments.

  • Identify the Bank’s critical assets, threats to these assets, vulnerabilities, and reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information.

  • Coordinate and assess the security performance of third-party vendors that collect, process, transmit, and store client data

  • Performs threat modelling-based system security risk assessment for all IT systems and other IT assets, as applicable

  • Analyze and assess the impact of changes in process, technical changes and systems enhancements and third-party relationships.

  • Reviews adequacy of existing security controls to safeguard the confidentiality, integrity and availability of information and information processing facilities to mitigate information security risk.

  • Formulates, recommends information security policies and procedures on physical, environmental and personnel security with respect to results of information security assessment activities.

  • Responsible for coordinating across all business units and stakeholders in gathering information in preparation to the conduct of information, third party and system security risk assessment.

  • Articulate security findings and risk remediation strategies through issuance of risk assessment report. Track and follow-up status of risk mitigation activities.

  • Ensures security risk register is maintained and kept updated including status of remediation activities.

  • Executes and monitors accomplishment of the risk assessment plans and programs.

  • Articulate security findings and risk remediation strategies through issuance of risk assessment report; writing comprehensive, concise and understandable to non-technical.  Tracking and follow up on status of mitigation activities.

  • Maintain and track library of records and documentation.

  • Investigation of applicable reported incidents related to information handling and data privacy.

  • Keep abreast of and apply information, IT and third party security trends and regulatory and compliance changes affecting the security of landscape, security best practices, threat landscape (emerging and existing) and apply them in daily work.

  • Review the work of other Security Quality and Assurance Risk Assessors; guides and mentors them.

  • Proactively works with the Department Head in implementing programs for the continuous improvement of the bank’s information security plans and strategies.

  • Perform other information security risk management and compliance related duties and responsibilities as directed by the Department Head.


 


Qualifications:



  • Knowledgeable on various compliance and regulatory requirements (i.e., BSP, DPA, PCI-DSS, etc.)

  • Working knowledge of various information and IT security domains and controls related to third party risks, data security and risk management, data transmission integrity.  This includes understanding various processes related to the service, product or solution provided by vendors to the Bank and its links to bank processes.

  • Has experience in information security governance, controls assurance, risk assessments and key risk indicators development

  • Experience in IT general controls and auditing a plus. Strong background on network and application system security risk assessments.

  • Ability to plan, execute, and document assessment activities following established processes and procedures with minimal guidance

  • Ability to lead and work well with the team, internal, and external clients. Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.

  • Analytical and risk identification skills to analyze a variety of information security –related risk situations and develop recommendations on the best course of action.

  • Good Project management skills: to lead and manage accomplishments of assigned tasks/risk assessment activities.

  • Possess excellent time management skills, thrive in a fast paced demanding environment

  • Be a self-managed self-starter with good organizational skills to include good follow-up skills

  • Be able to work under pressure on multiple assessments/projects simultaneously

  • Strong attention to detail, analytical, and problem-solving skills.

  • Strong learning agility with the ability to learn new processes

  • Good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.

  • Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action

  • College graduate or any degree on Information technology, Information Security, or related field of expertise.

  • Certification may include CISA, CISM, CRISC, PCI-DSS, etc.

  • Knowledge in using MS office tools such as PowerPoint, word, excel and project.


 


Other Details:


Rank: Junior Officer


Unit: Financial and Control Sector / Information Security Division / Security Quality Assurance and Assessment Department
Location: Metrobank Center, Taguig


Original job Security Assurance And Assessment Officer posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Apply Now
Share Job
Share Job

About the Company

Meaningful Banking From Metrobank

Don't let the name fool you -- Metrobank is a global operation. The Metropolitan Bank and Trust Company provides a full range of banking services to individual and commercial clients through around 800 offices in the Philippines, Asia, Europe, and the US. Its services include deposits, savings, loan...

Read more about the company

Auto-Apply to Security Assurance And Assessment Officer Jobs with your AI JobCopilot

thunder icon Auto-Apply with AI

Similar Security Assurance And Assessment Officer Jobs in the Philippines

GrabJobs is the no1 job portal in the Philippines, connecting you to thousands of jobs fast! Find the best jobs in the Philippines, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.