Determine the enterprise's cybersecurity risk posture for existing systems, products, and services across the PLDT Group, ensuring alignment with internal standards and full regulatory compliance.
Responsibilities
- Perform risk assessments for multiple critical projects and initiatives involving new assets, technologies, products, and services across the PLDT Group.
- Identify, assess, and mitigate security-related risks within Executive Management's defined risk tolerance levels.
- Conduct security risk assessments and validations in accordance with company standards, processes, and industry best practices.
- Gather and review project information, including scope, network architecture, data flow diagrams, evidence, and artifacts to support cybersecurity risk assessments.
- Analyze solution designs, data flow diagrams, and network architecture diagrams to identify vulnerabilities and recommend security controls.
- Create and monitor risk treatment plans, including risk findings, mitigation controls, residual risks, and implementation timelines.
- Track implementation of risk treatments and cybersecurity compliance requirements before production deployment or launch.
- Facilitate regular checkpoint meetings with project teams and document assessment results, compliance status, and reports.
- Assess requests that deviate from cybersecurity policies and standards, including non-standard internet access, application access, local administrator rights, and VPN access requests.
- Perform vulnerability scans on project-related applications, servers, and assets.
- Track and coordinate remediation of identified vulnerabilities and produce vulnerability management reports.
- Lead project risk assessment activities, facilitate meetings, ensure timely completion of deliverables, and maintain accurate project records and documentation.
Qualifications
Education
- Bachelor's Degree in Information Technology, Computer Science, Engineering, or any related course/discipline.
Work Experience
- 3 to 4 years of experience as an Analyst, Specialist, or related role within Information Technology or Cybersecurity.
Skills & Knowledge
- Experience in Information Security, Information Technology, Telecommunications Technology, Information Systems Audit, Operational Risk, Process and Policy Development, or Regulatory Compliance.
- Knowledge of cloud service models (IaaS, PaaS, SaaS) and associated security services.
- Familiarity with security technologies and solutions.
- Understanding of common cyber threats, including DDoS, brute-force attacks, SQL injection, and malware infections.
- Knowledge of risk assessment frameworks and methodologies, cybersecurity frameworks, cybersecurity tools, technology risk, laws and regulations impacting technology-driven businesses, on-premise and cloud infrastructure, project management, and requirements analysis.
Preferred Certifications
- CISA, CISM, CRISC, Security+, CISSP, CEH, or similar industry-recognized certifications.