Search Jobs

Search by job, company or skills

Security Analyst

Security Analyst

Asia Select Inc.
4-6 Years
  • Posted 12 days ago
  • Be among the first 10 applicants

Job Description

Job Description

KEY RESPONSIBILITIES

You will:

  • Administer and manage CrowdStrike security platform, including deployment, configuration, and optimisation
  • Monitor security alerts and events through CrowdStrike console
  • Perform regular health checks and ensure platform updates are applied
  • Manage endpoint detection and response (EDR) activities
  • Configure and fine-tune detection rules and policies
  • Monitor, analyse, and respond to security incidents and alerts
  • Investigate suspicious activities and potential security breaches
  • Perform root cause analysis on security incidents
  • Document incident response procedures and maintain incident logs
  • Implement remediation measures and track resolution progress
  • Prepare regular security status reports for management
  • Provide updates on security metrics, incidents, and trends
  • Generate monthly and quarterly security dashboards
  • Present findings and recommendations to stakeholders
  • Respond to internal and external due diligence queries regarding security controls and practices
  • Stay current with emerging security threats, vulnerabilities, and attack vectors
  • Monitor threat intelligence feeds and security advisories
  • Assess the relevance and impact of new threats to the organisation
  • Share threat intelligence insights with the team
  • Recommend proactive security measures based on threat landscape
  • Coordinate and manage annual penetration testing exercises
  • Work with external security assessors and penetration testers
  • Review penetration test findings and develop remediation plans
  • Track and verify remediation of identified vulnerabilities
  • Conduct annual Essential Eight security maturity assessments
  • Ensure compliance with Essential Eight framework requirements
  • Document security controls and maintain compliance evidence
  • Conduct regular vulnerability scans and assessments
  • Prioritize vulnerabilities based on risk and business impact
  • Track remediation efforts and coordinate with IT teams
  • Maintain vulnerability management database and reporting
  • Verify patch compliance across systems and endpoints
  • Ensure principle of least privilege is maintained
  • Monitor privileged account usage and activities
  • Review security logs from various systems and applications
  • Correlate events across multiple security tools
  • Identify anomalous behaviour and potential security issues
  • Maintain and tune security monitoring rules and alerts
  • Archive logs in compliance with retention policies
  • Manage antivirus, anti-malware, and endpoint protection solutions
  • Administer firewalls, intrusion detection/prevention systems
  • Maintain data loss prevention (DLP) tools
  • Configure and manage web filtering and email security gateways
  • Ensure security tools are properly integrated and functioning
  • Review changes to critical systems for security implications
  • Participate in change advisory board meetings
  • Assess security impact of proposed system changes
  • Verify security configurations align with hardening standards
  • Maintain secure baseline configurations
  • Assess security posture of vendors and third-party providers
  • Review vendor security documentation and certifications
  • Monitor compliance with contractual security requirements
  • Participate in vendor security assessments
  • Support procurement process with security evaluations
  • Verify security of backup systems and processes
  • Test backup restoration procedures periodically
  • Review disaster recovery and business continuity plans from a security perspective
  • Ensure encrypted backups are maintained and accessible
  • Participate in disaster recovery exercises
  • Maintain security policies, procedures, and documentation
  • Create and update security runbooks and playbooks
  • Contribute to security awareness and training initiatives
  • Develop security metrics and KPIs
  • Identify opportunities for security process improvements
  • Participate in security projects and initiatives
  • Conduct security tabletop exercises

QUALIFICATIONS:

  • 4+ years working in information security or cybersecurity operations
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field
  • Familiarity with fund management, non-bank lending industry and regulatory landscape.
  • Hands-on experience with security monitoring and incident response
  • Relevant security certifications (Security+, CySA+, CEH, GCIH, or similar)

Work Schedule: Early Morning Shift (AU - 6am-3pm)

Work Set-up: Full-onsite, Ortigas, Pasig

More Info

Job Type:
Employment Type:

Key Skills

CrowdStrike security platform

security metrics and KPIs

email security gateways

About Company

Similar Jobs

2-4 yrs
Philippines, Quezon City
Skills:
endpoint detection and response (EDR), cloud security, network security, Microsoft Office, vulnerability assessment, Firewalls, Identity And Access Management, Incident Response, Siem, endpoint protection, security reporting tools, penetration testing coordination, antivirus systems, root-cause analysis methodologies, data loss prevention tools
2-4 yrs
Philippines, Central Visayas
Skills:
Microsoft 365, Microsoft Entra ID, Vulnerability management and security assessment tools, Privileged access controls, Cloud security monitoring and reporting, conditional access, Firewall and network traffic analysis
2-4 yrs
Philippines
Skills:
Vulnerability Management, Incident Response, Information Security, Iam, Network security, Encryption, AI tools, Endpoint protection, Security Monitoring, Security Operations
3-5 yrs
Philippines
Skills:
Incident Response, Cybersecurity, Information Security, Vendor Risk Management, Regulatory Compliance, Security Audits and Compliance, Risk Assessment and Management, Security Architecture, Documentation and Reporting
5-8 yrs
Muntinlupa City, Philippines
Skills:
Automation Scripting, Endpoint Security, Vulnerability Management, PowerShell, Identity Management, Microsoft 365, cybersecurity operations, Microsoft cloud technologies, NIST 800, Active Directory, security policy administration, enterprise infrastructure, SIEM technologies, security monitoring solutions, CMMC