Company Description
A7 Recruitment Corporation, a Filipino-owned company, provides innovative and cost-effective recruitment solutions in the Philippines. Originating from Vrtere Global Solutions, Inc., an IT staffing company in Manila, A7 Recruitment builds on a legacy of connecting qualified talent with organizational needs. Formerly operated by Kforce Global Solutions, Inc., the company offers top-tier talents and market insights to address recruitment challenges. A7 Recruitment is dedicated to bridging gaps and delivering the right solutions to help its partners succeed.
Role Description
- Develop tactical plans and programs for the establishment and maintenance of the Bank's third party information security risk management framework and ensure alignment with the enterprise risk framework
- Performs third party security, system security and information asset based risk assessment. Analyze and review of complex bank processes, application system and network security implementation and third party relationships to identify potential risk including the determination of risk mitigation strategies
- Analysis and review of complex application system and network security implementation on the current production environments to identify potential risk including the determination of risk mitigation strategies
- Recommend strategies to control risks from inadequate protection of confidentiality, integrity and availability of the information assets, processing facilities and connected services
Qualifications
- Bachelor's Degree
- Experienced in IT general controls and auditing, preferably strong background on system security risk assessments
- Can perform information security risk-based prioritization decisions, analyze business risk, and can articulate complex business/risk trade-off recommendations and decisions
- Experienced on project security technical review and risk assessment
- Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action
- Should also be abreast with security best practices and knowledge of common and emerging security threats
- Professional Certification may include CISA, CISM, CRISK, PCI-DSS, ISO-27001 LA or equivalent is an advantage