Skip to content

Open nowPosted 3 days ago

Security Analyst

Workable (global search)108,016 open roles

Where
Pasig, Metro Manila, Philippines
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity AnalystWorkable (global search) · Pasig, Metro Manila, Philippines
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 3 days ago

Workable (global search) median: 7 days open

The posting

Work Setup: ONSITE (Pasig)

Work Schedule: AU DAYSHIFT

We are seeking a skilled Security Analyst reporting to our Group Head of Technology that will play a critical role in protecting our organization’s information systems and data. This position will be responsible for managing our security infrastructure, responding to threats, and ensuring our security posture remains robust and compliant with industry standards.

Why you want this role

  • Hands-On Security Impact - You'll directly protect the organization by managing cutting-edge security platforms like CrowdStrike, responding to real threats, and making decisions that immediately strengthen our security posture.
  • Comprehensive Skill Development - Gain broad exposure across the entire security lifecycle—from threat intelligence and incident response to penetration testing coordination and compliance frameworks—building expertise that accelerates your cybersecurity career.
  • Trusted Security Advisor - Take ownership as the go-to security expert for your region, presenting to stakeholders, responding to due diligence queries, and shaping security strategy rather than just following orders.

What we are looking for

  • Proactive Self-Starter - takes initiative in identifying and responding to security threats, stays ahead of emerging risks, and doesn't wait to be told what to do when security issues arise.
  • Clear Communicator – ability to translate complex technical security concepts into understandable language for non-technical stakeholders
  • Detail-Oriented Problem Solver - An analytical thinker who can methodically investigate security incidents, spot anomalies in logs and alerts, and track multiple compliance requirements

About the role Key accountabilities

Security Platform Management

  • Administer and manage CrowdStrike security platform, including deployment, configuration, and optimization
  • Monitor security alerts and events through CrowdStrike console
  • Perform regular health checks and ensure platform updates are applied
  • Manage endpoint detection and response (EDR) activities
  • Configure and fine-tune detection rules and policies

Threat Detection & Response

  • Monitor, analyses, and respond to security incidents and alerts
  • Investigate suspicious activities and potential security breaches
  • Perform root cause analysis on security incidents
  • Document incident response procedures and maintain incident logs
  • Implement remediation measures and track resolution progress

Security Reporting & Communication

  • Prepare regular security status reports for management
  • Provide updates on security metrics, incidents, and trends
  • Generate monthly and quarterly security dashboards
  • Present findings and recommendations to stakeholders
  • Respond to internal and external due diligence queries regarding security controls and practices

Threat Intelligence & Awareness

  • Stay current with emerging security threats, vulnerabilities, and attack vectors
  • Monitor threat intelligence feeds and security advisories
  • Assess the relevance and impact of new threats to the organization
  • Share threat intelligence insights with the team
  • Recommend proactive security measures based on threat landscape

Security Testing & Compliance

  • Coordinate and manage annual penetration testing exercises
  • Work with external security assessors and penetration testers
  • Review penetration test findings and develop remediation plans
  • Track and verify remediation of identified vulnerabilities
  • Conduct annual Essential Eight security maturity assessments
  • Ensure compliance with Essential Eight framework requirements
  • Document security controls and maintain compliance evidence

Vulnerability Management

  • Conduct regular vulnerability scans and assessments
  • Prioritize vulnerabilities based on risk and business impact
  • Track remediation efforts and coordinate with IT teams
  • Maintain vulnerability management database and reporting
  • Verify patch compliance across systems and endpoints

Access Control & Identity Management

  • Ensure principle of least privilege is maintained
  • Monitor privileged account usage and activities

Security Monitoring & Log Analysis

  • Review security logs from various systems and applications
  • Correlate events across multiple security tools
  • Identify anomalous behavior and potential security issues
  • Maintain and tune security monitoring rules and alerts
  • Archive logs in compliance with retention policies

Security Tools Administration

  • Manage antivirus, anti-malware, and endpoint protection solutions
  • Administer firewalls, intrusion detection/prevention systems
  • Maintain data loss prevention (DLP) tools
  • Configure and manage web filtering and email security gateways
  • Ensure security tools are properly integrated and functioning

Change Management & Configuration Review

  • Review changes to critical systems for security implications
  • Participate in change advisory board meetings
  • Assess security impact of proposed system changes Verify security configurations align with hardening standards
  • Maintain secure baseline configurations

Vendor & Third-Party Risk Management

  • Assess security posture of vendors and third-party providers
  • Review vendor security documentation and certifications
  • Monitor compliance with contractual security requirements
  • Participate in vendor security assessments
  • Support procurement process with security evaluations

Backup & Disaster Recovery

  • Verify security of backup systems and processes
  • Test backup restoration procedures periodically
  • Review disaster recovery and business continuity plans from a security perspective
  • Ensure encrypted backups are maintained and accessible
  • Participate in disaster recovery exercises

Documentation & Continuous Improvement

  • Maintain security policies, procedures, and documentation
  • Create and update security runbooks and playbooks
  • Contribute to security awareness and training initiatives
  • Develop security metrics and KPIs
  • Identify opportunities for security process improvements
  • Participate in security projects and initiatives
  • Conduct security tabletop exercises

Skills, qualifications and experience

  • 4+ years working in information security or cybersecurity operations
  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field
  • Familiarity with fund management, non-bank lending industry and regulatory landscape.
  • Hands-on experience with security monitoring and incident response

Desirable:

  • Relevant security certifications (Security+, CySA+, CEH, GCIH, or similar)
  • CrowdStrike Certified Falcon Administrator or similar certification
  • Experience with compliance frameworks (ISO 27001, NIST, CIS Controls)
  • Familiarity with scripting languages (PowerShell, Python)
  • Knowledge of Australian government security frameworks (ACSC, ISM)
  • Ability to explain technical security concepts to non-technical stakeholders
  • Proven experience with CrowdStrike or similar EDR/XDR platforms
  • Strong understanding of security principles, threats, and vulnerabilities
  • Knowledge of Windows and Linux operating systems
  • Familiarity with network protocols, firewalls, and security technologies
  • Experience with security information and event management (SIEM) tools
  • Knowledge of penetration testing methodologies and vulnerability management
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.