Information Security Analyst
- Satellite Office
- Pasig City, Philippines
- PHP 800,000 – PHP 1,200,000
Position Purpose
Preventing, mitigating, and responding to major information and cyber security events, security incidents, and security breaches. This includes researching, recommending, implementing, and operating technologies, controls, and processes that will effectively protect and defend the information systems in use across our portfolio of brands. Ensuring minimal system downtime and reducing the impact of attacks and operational outages through enhanced cybersecurity defence strategies and processes.
This is a global role that will require work with all regions in which our brands operate. Successful applicant will oversee security events across more than 2,000 IT assets; help to secure our more than 400 applications and IT systems; and educate and interface with 5,000 employees across our global enterprise.
This role requires continuous upskilling in information and cyber security defence strategies, techniques, and technologies to align with industry, threat, and attacker trends, as well as the demands of the role. Successful applicant will generate and implement recommendations for measurably improving security across the brands.
Role Accountabilities
Accountability: Security Engineering and Architecting
· Participate in complex, global IT projects across Applications, Infrastructure, Security, and wider business initiatives to provide security engineering, solution implementation, and to ensure that best-practice security controls are implemented and tested. Examples include consulting on security considerations when the business is implementing a new ERP system, designing SIEM use cases and onboarding event sources, participating in secure network / zero trust redesigns, uplifting our filtering technology stack, enhancing our patching and vulnerability management tooling and process, and more.
· Research and assess new threats, security patches, and alerts, and recommend or implement remedial actions.
· Research, evaluate, design, test, recommend, plan, and help to implement new and existing information security technologies, including creating the business case for security investments.
· Review and implement security policies, principles, and standards and recommend updates as appropriate.
· Other security architecture and engineering objectives as required.
Accountability: Incident Detection and Response
· As a key member of the Computer Security Incident Response Team (CSIRT), successful applicant will respond to Major Incidents. This includes ransomware events, data exfiltration, security detections and incidents, and privacy breaches using the business’s Incident Response Plan, including the occasional out-of-hours response for high priority or urgent incidents.
· Stay up to date on the latest threat intelligence and countermeasures, including attacker methodologies and emerging security technologies.
· Engage in proactive threat-hunting and reactive response using the various technologies leveraged by the business, including our EDR/XDR, SSE, SIEM, vulnerability management toolset, email and web filters, and other technologies.
· Provide incident investigation and reporting, and security awareness training for those involved in incidents.
· Assist the relevant IT stakeholders in the resolution of reported security incidents.
· Monitor event-based or scheduled alerts, reports, and logs for potential threats and aberrative events.
Accountability: Strategy & Interfacing with Senior Management
· Interface with Senior Management, as well as Rip Curl, Kathmandu, and Oboz IT & Systems Departments to develop and implement the business’s risk-based security program and projects, security awareness training, and technological uplifts to address identified risks and business security requirements.
· Create regular high-level reports and deliverables based on security metrics.
· Manage the process of gathering, analysing, and assessing the current and future threat landscape, as well as providing the CISO with a realistic overview of risks and threats in the enterprise environment.
· Provide positive, educational, interesting, and entertaining risk-based information security expertise and training across the business to ensure that information security is embedded and understood at all levels of the organization.
Accountability: Sustainability
· Explore opportunities to improve our environmental impact through sustainable IT practices and procedures.
Accountability: Vulnerability and Cyber Risk Assessments
· Conduct cyber security assessments of internal systems, applications, and IT infrastructure as part of the overall risk management practice of the organization, including improving our ongoing vulnerability management tool suite and process.
· Defining, testing, and refining threat detection use cases for our security tools; responsible for maintaining a common set of cybersecurity tools.
· Ensure that a complete, accurate inventory of all systems, infrastructure, and applications exists.
· Ensure that appropriate logging is incorporated into our security information and event management (SIEM) or log management tools.
· Work with various stakeholders to identify information asset owners to classify data and systems as part of a control framework.
· Perform control and vulnerability assessments to measure the effectiveness of existing controls and recommend remedial action.
· Timely reporting of information security risk, vulnerabilities, and other security exposures including misuse of information assets to the ISO, or others where appropriate.
· Conduct regular security audits of 3rd party vendor services, especially those with which the organization shares intellectual property, PII, regulated or other protected data to ensure that those organizations have an appropriate level of security controls in place.
· Execute risk assessment activities; analyse the results of audits and penetration tests (both internal and external) and other available security logs to produce recommendations of acceptable risk and risk mitigation strategies.
Accountability: Compliance & Audit Support
· Manage relationships with internal and external audit and penetration testing groups (e.g. pen test vendors, PCI Assessors, IT Auditors, etc). Receive audit findings and manage the collection of responses and remediation plans with owners.
· Provide oversight of audit finding remediation, including generating requirements for full remediation, providing feedback and suggestions on managerial responses to findings, and tracking progress and providing status and updates for reporting purposes.
· Enable our brands maintain and achieve ongoing PCI compliance by ensuring we’re aligned with the latest standards and performing all necessary compliance-related activities throughout the year.
· Identify regulatory changes that may affect information security policy, standards, and procedures, and recommend appropriate changes.
Accountability: Security Policy & Process
· Continue to implement and maintain our global family of companies’ security policies and procedures to ensure secure operating efficiency and regulatory compliance.
· Provide advice and information on policies and procedures that require revision or replacement.
· Develop security processes and procedures, and support service-level agreements (SLAs) to ensure that security controls are managed and maintained.
· Monitor and report on compliance with security policies, as well as the enforcement of policies within the IT function.
Accountability: Other duties aligned with the role as required
· A flexible and collaborative attitude, and willingness to assist the wider team with ad hoc tasks as needed.
Essential Qualities
· Problem-solving tenacity and investigative mindset.
· Excellent written and verbal communication skills.
· Ability to manage multiple ongoing projects with overlapping deadlines.
· Strong analytical skills to analyse security requirements and relate them to appropriate security controls.
· A desire to improve and openness to constructive feedback.
· Positive attitude about securityand user education; ability to productively relate, interact, and build healthy relationships with a broad cross-section of staff (of varying technical levels, including security and tech newbies!) to helpfully consult on, explain, and enforce security measures.
· Capability and desire to work with minimal supervision, and to stay current on security trends, emerging threats, and new controls. A default attitude of “I can learn this!”
· Desire to share knowledge gained with the rest of the team in a positive, helpful way, helping all members (even those senior to applicant) learn and understand more than they did yesterday.
Qualification & Experience Requirements
What is the typical background required to competently perform the responsibilities of the job?
· A degree in IT, Computer Science, or a related field is strongly preferred but not required.
· Knowledge of network and system infrastructures gained in a business environment. Understanding of, experience in, and/or a strong drive and desire to learn more about modern software development practices and lifecycle, infrastructure projects, vendor management, and IT service/help desk functions.
· Background working in a help desk, network admin, sysadmin, DFIR analyst, or testing role strongly preferred.
· Ability to speak to any IT-related projects (including personal projects) and tools that you deployed or managed, and any related security components.
· Participation in digital forensic investigations, incident response, and/or root cause analyses strongly preferred.
· Technical certifications (strongly preferred to have at least one or more): CEH, CISSP, OSCP, GCIH, CCSP, CCNP, NSE-4, PCNSE, GCFE, GCFA, CCSA or equivalent.
· Understanding or a desire to learn information risk concepts and principles, as a means of relating business needs to security controls.
· Understanding and general familiarity with cloud technologies, especially AWS and Azure.
· Strong documentation skills; able to create workflows, diagrams, and internal instructive security documentation for other staff.
· Technical understanding and practical experience with authentication mechanisms, password management tools, EMM/MDM platforms, patch and vulnerability management processes, firewalls, network capture tools, security models, and other security technologies strongly preferred.
· Experience (or knowledge of requirements) in performing risk, business impact, control, and vulnerability assessments.
· Experience in developing and documenting security plans, including strategic, tactical, and project plans.
· Experience with common information security management frameworks, such as those by CIS, and the ISO2700x and NIST CSF.
· Strong understanding of business applications, including ERP and financial systems.
· High-level technical knowledge of mainstream operating systems and a wide range of security technologies, such as SIEM and log aggregation platforms, network security appliances, email filters, identity, and access management (IAM) systems, EDR, cryptography, SSE, vulnerability scanners, anti-malware solutions, security awareness training platforms, automated policy compliance tools, and desktop security tools.
· Experience in developing, documenting, and maintaining security policies, processes, procedures and standards, or a strong desire and drive to learn same.
· Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts, or a strong desire and drive to learn same.
Skills
- Security Incident Response
- Threat Detection
- SIEM
- Security Architecture
- Vulnerability Management
- Risk assessment
- Security Awareness Training








