Search by job, company or skills

Information Security Specialist

Information Security Specialist

MicroSourcing International
2-4 Years
Not Disclosed
  • Posted 11 days ago
  • Be among the first 10 applicants

Job Description

Role Summary:

The Information Security Specialist is responsible for strengthening MicroSourcing's cybersecurity baseline and operational resilience. Acting as a hybrid bridge between Governance, Risk & Compliance (GRC) and Hands-on Security Operations, this role ensures the organization adheres to strict international standards, regulatory mandates, and client security commitments.

Key Responsibilities

  • Audit & Compliance: Support internal/external audits (ISO/IEC 27001, SOC 2, PCI DSS) and manage audit evidence, walkthroughs, and remediation tracking.
  • Security Operations: Monitor tools (EDR/XDR, SIEM, vulnerability scanners), manage security alerts, perform system scans, and coordinate incident response.
  • Risk & Governance: Conduct security risk assessments, evaluate third-party/vendor risks, maintain risk registers, and support the Information Security Management System (ISMS).
  • Security Awareness: Help design and deliver company-wide security training, onboarding, and phishing simulations.
  • Stakeholder Management: Collaborate with IT, HR, Operations, external auditors, and clients to complete security questionnaires and drive continuous improvement.

What We're Looking For

Must-Haves:

  • Bachelor's degree in IT, Computer Science, Cybersecurity, or a related field.
  • 2–4 years of experience in Information Security, IT Audit, GRC, or Cybersecurity Operations.
  • Good working knowledge of ISO 27001, SOC 2, PCI DSS, and the NIST Cybersecurity Framework.
  • Practical understanding of risk management, security controls, and endpoint security.
  • Strong analytical, documentation, and communication skills.

Nice-to-Haves:

  • Experience in a BPO, IT Enabled Services (ITES), or Managed Services environment.
  • Familiarity with the Philippine Data Privacy Act (DPA).
  • Certifications such as CompTIA Security+, ISC2 CC, or ISO 27001 Internal/Lead Auditor.
  • Experience with GRC platforms (Vanta, OneTrust, Archer) or enterprise security tools.

About MicroSourcing

With over 9,000 professionals across 13 delivery centers, MicroSourcing is the pioneer and largest offshore provider of managed services in the Philippines.

Our commitment to 100% YOU

MicroSourcing firmly believes that our company's strength lies in our people's diversity and talent. We are proud to foster an inclusive culture that embraces individuals of all races, genders, ethnicities, abilities, and backgrounds. We provide space for everyone, embracing different perspectives, and making room for opportunities for each individual to thrive.

At MicroSourcing, equality is not merely a slogan – it's our commitment. Our way of life. Here, we don't just accept your unique authentic self - we celebrate it, valuing every individual's contribution to our collective success and growth. Join us in celebrating YOU and your 100%!

For more information, visit https://www.microsourcing.com/

More Info

Job Type:
Industry:
Employment Type:

Key Skills

XDR

SOC 2

vulnerability scanners

NIST Cybersecurity Framework

Vanta

OneTrust

GRC platforms

Similar Jobs

3-5 yrs
Philippines
Skills:
Iso 27001, Threat Intelligence, information security risk management, CIS Controls, nist, security governance, cybersecurity governance, governance risk compliance and reporting tools, ISMS operations, security control monitoring
3-5 yrs
Taguig, Philippines
Skills:
Vulnerability Assessments, Security awareness programs, Security Audits and Assessments, ISO27001 standards, ISMS implementation, Phishing simulations, Third-Party Security Risk Management, Data Privacy Act of 2012
4-5 yrs
Philippines
Skills:
technology risk , SaaS), Cloud service models (IaaS, Information Security, Information Technology, Paas, Requirements Analysis, Operational Risk, Telecommunications Technology, Regulatory Compliance, Process and Policy Development, Information Systems Audit, Cybersecurity tools, Project management, Laws and regulations impacting technology-driven businesses, Cybersecurity frameworks, Security technologies and solutions, On-premise and cloud infrastructure, Risk assessment frameworks and methodologies
2-4 yrs
Philippines
Skills:
Data Privacy, Identity Access Management, Information Security, Iso27001, CIS-CSC, Risk Management, NIST Cybersecurity Framework
3-5 yrs
Philippines
Skills:
Gdpr, Vulnerability Management, Incident Management, Threat Intelligence, Third-Party Risk Management, Security Governance, Microsoft 365 Security Suite, Email Security Support, Data Privacy Breach Response, nist, Router Administration, Security Operations