Be #InGoodHands with Metrobank!
Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach!
The Security Assurance and Assessment Officer are responsible for developing and maintaining the bank's third-party information security risk management framework, ensuring it aligns with the overall enterprise risk strategy.
This role conducts security risk assessments on third parties, systems, applications, and information assets. It reviews processes, systems, and network security controls to identify potential risks and recommend appropriate mitigation strategies.
The officer also evaluates the security of production environments and provides recommendations to protect the confidentiality, integrity, and availability of the bank's information, systems, and services.
Key Responsibilities
- Develop and implement plans for conducting information security, third-party, and system risk assessments.
- Identify critical assets, threats, and vulnerabilities, and evaluate the effectiveness of existing security controls.
- Assess and monitor the security performance of third-party vendors handling client data.
- Perform threat modeling and risk assessments for IT systems and assets.
- Evaluate the impact of process changes, system upgrades, and third-party engagements on security risks.
- Review and ensure adequate controls are in place to protect the confidentiality, integrity, and availability of information.
- Recommend and help develop information security policies and procedures based on assessment results.
- Coordinate with business units and stakeholders to gather information for risk assessments.
- Prepare and communicate risk assessment reports, including findings and recommended mitigation actions.
- Track and follow up on risk mitigation activities and maintain an updated risk register.
- Execute and monitor risk assessment plans and programs.
- Maintain proper documentation and records of assessments and security activities.
- Investigate security incidents related to information handling and data privacy.
- Stay updated on security trends, threats, and regulatory requirements, and apply them in daily work.
- Review, guide, and mentor junior risk assessors.
- Support continuous improvement of the bank's information security programs and strategies.
- Perform other security risk and compliance tasks as assigned.
Qualifications:
- Bachelor's degree in a relevant field
- Experience in IT general controls, auditing, and system security risk assessments
- Strong understanding of risk assessment and the ability to evaluate and prioritize security risks
- Able to analyze business risks and clearly explain recommendations and trade-offs
- Experience in project security reviews and risk assessments
- Strong analytical skills with the ability to identify risks and recommend appropriate actions
- Updated knowledge of security best practices and emerging threats
- Relevant certifications (e.g., CISA, CISM, CRISC, PCI-DSS, ISO 27001) are a plus