Senior Security GRC Analyst
dfi technology (philippines)- Posted 8 hours ago
- Be among the first 10 applicants
Job Description
Is this your next challenge as a Senior Security GRC Analyst
The challenge is to:
We are seeking a Senior Security GRC Analyst with at least 5 years experience to strengthen our information security governance, risk management and compliance programs. In this role, you will lead risk assessments, maintain the security register, support audits and ensure alignment with frameworks such as NIST CSF, ISO 27001 and applicable regulations.
The successful candidate will work closely with Information Security team and IT teams to help protect organizational assets, strengthen security posture, and support cybersecurity initiatives across enterprise environments.
Key Responsibilities
- Governance and Policy Management
- Own the lifecycle of security policies, standards and procedures: draft, review, update and track approvals and exceptions
- Maintain the policy library with version control, ownership, and review cadence
- Align governance artifacts with frameworks (NIST CSF, ISO 27001, PCI DSS, GDPR as applicable)
- Risk Management
- Conduct risk assessments for projects, systems, and vendors using DFI's methodology
- Document risks, treatments, and residual ratings; route for risk acceptance per authority tiers
- Support project security risk assessment reviews and cybersecurity pre go-live security reviews with system/application owners
- Track remediation and follow up with mitigation control/remediation action owners
- Security Architecture & Data Flow Review
- Review security architecture diagrams and data flow diagrams for new projects, system changes, and vendor integrations
- Validate designs against DFI security standards, segmentation principles, and data classification requirements
- Audit and Compliance Support
- Coordinate annual security audits and certifications (ISO 27001,PCI DSS); manage evidence collection, stakeholder coordination and audit readiness.
- Maintain ISMS documentation — policies, procedures, SOA, evidence
- Support control self-assessments and audit evidence preparation
- Map controls/findings against ISO/IEC 27001:2022 Annex A and NIST CSF 2.0
- Third-Party & Vendor Risk
- Assist with vendor security risk assessments (documentation/evidence review)
- Maintain security risk assessment records and chase outstanding vendor evidence
- General Security GRC Support
- Update Security GRC templates, trackers, and reporting materials
- Support ad hoc governance, audit, and compliance tasks
- Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit and awareness program status.
Do you have experience as a Security GRC Analyst
Required Qualifications
- Bachelor's degree in information technology, or Computer Science or equivalent experience
- Experience: 5+ years in security governance, risk, compliance, audit, or security assurance roles.
- Proven track record in risk assessments, risk register management, and remediation tracking
- Working knowledge of ISO/IEC 27001 (Annex A, ISMS docs) and NIST CSF
- Experience in supporting internal/external audits, evidence collection, and audit readiness activities
- Strong ability to draft clear, actionable policies and procedures; translate regulatory requirements into control procedures
- Ability to translate technical diagrams into risk/control language
- Strong written communication skills
Nice To Have Qualifications
- Certifications: CISSP, CISA, CRISC, ISO 27001 Lead Auditor/Implementer or equivalent
- Retail or regulated industry experience
- Familiarity with automating evidence collection and control monitoring
- Familiarity with PCI DSS, GDPR, or Hong Kong PDPA
- Exposure to vulnerability management, IAM/PAM, cloud/network security
- Experience supporting ISO 27001 certification/surveillance audits
If you have the right skills and experience, this is an opportunity to build your career with Asia's leading retailer.
DFI Retail Group is an equal opportunity employer and responsible for ensuring that all personal information collected from each Candidate presented to DFI Retail Group is used for recruitment purposes only and the personal data will be kept and handled confidentially. We will retain the applications of candidates not selected for a period of no more than 24 months. The data collection process is in accordance with all applicable laws and compliant with the Code of Practice on Human Resource Management
To find out more about Our Businesses and Our People, please visit our website: https://www.DFIretailgroup.com
More Info
Key Skills
risk assessments
audit readiness
NIST CSF
vendor security risk assessments
ISMS documentation
ISO IEC 27001 Annex A
remediation tracking
risk register management
