Hiring.Camp

Security Analyst

Cobdenandcarter

·

Today

Location
Pasig
Type
Full-time
Department
Security
Education
Bachelor
Closing date
Today
Source
CareersPage

Description

Job Summary:

We are seeking a skilled Security Analyst reporting to our Group Head of Technology that will play a critical role in protecting our organisation's information systems and data. This position will be responsible for managing our security infrastructure, responding to threats, and ensuring our security posture remains robust and compliant with industry standards.

Key accountabilities

Security Platform Management

  • Administer and manage CrowdStrike security platform, including deployment, configuration, and optimization
  • Monitor security alerts and events through CrowdStrike console
  • Perform regular health checks and ensure platform updates are applied
  • Manage endpoint detection and response (EDR) activities
  • Configure and fine-tune detection rules and policies

Threat Detection & Response

  • Monitor, analyse, and respond to security incidents and alerts
  • Investigate suspicious activities and potential security breaches
  • Perform root cause analysis on security incidents
  • Document incident response procedures and maintain incident logs
  • Implement remediation measures and track resolution progress

Security Reporting & Communication

  • Prepare regular security status reports for management
  • Provide updates on security metrics, incidents, and trends
  • Generate monthly and quarterly security dashboards
  • Present findings and recommendations to stakeholders
  • Respond to internal and external due diligence queries regarding security controls and practices

Threat Intelligence & Awareness

  • Stay current with emerging security threats, vulnerabilities, and attack vectors
  • Monitor threat intelligence feeds and security advisories
  • Assess the relevance and impact of new threats to the organisation
  • Share threat intelligence insights with the team
  • Recommend proactive security measures based on threat landscape

Security Testing & Compliance

  • Coordinate and manage annual penetration testing exercises
  • Work with external security assessors and penetration testers
  • Review penetration test findings and develop remediation plans
  • Track and verify remediation of identified vulnerabilities
  • Conduct annual Essential Eight security maturity assessments
  • Ensure compliance with Essential Eight framework requirements
  • Document security controls and maintain compliance evidence

Vulnerability Management

  • Conduct regular vulnerability scans and assessments
  • Prioritise vulnerabilities based on risk and business impact
  • Track remediation efforts and coordinate with IT teams
  • Maintain vulnerability management database and reporting
  • Verify patch compliance across systems and endpoints

Access Control & Identity Management

  • Ensure principle of least privilege is maintained
  • Monitor privileged account usage and activities

Security Monitoring & Log Analysis

  • Review security logs from various systems and applications
  • Correlate events across multiple security tools
  • Identify anomalous behaviour and potential security issues
  • Maintain and tune security monitoring rules and alerts
  • Archive logs in compliance with retention policies

Security Tools Administration

  • Manage antivirus, anti-malware, and endpoint protection solutions
  • Administer firewalls, intrusion detection/prevention systems
  • Maintain data loss prevention (DLP) tools
  • Configure and manage web filtering and email security gateways
  • Ensure security tools are properly integrated and functioning

Change Management & Configuration Review

  • Review changes to critical systems for security implications
  • Participate in change advisory board meetings
  • Assess security impact of proposed system changes
  • Verify security configurations align with hardening standards
  • Maintain secure baseline configurations

Vendor & Third-Party Risk Management

  • Assess security posture of vendors and third-party providers
  • Review vendor security documentation and certifications
  • Monitor compliance with contractual security requirements
  • Participate in vendor security assessments
  • Support procurement process with security evaluations

Backup & Disaster Recovery

  • Verify security of backup systems and processes
  • Test backup restoration procedures periodically
  • Review disaster recovery and business continuity plans from a security perspective
  • Ensure encrypted backups are maintained and accessible
  • Participate in disaster recovery exercises

Documentation & Continuous Improvement

  • Maintain security policies, procedures, and documentation
  • Create and update security runbooks and playbooks
  • Contribute to security awareness and training initiatives
  • Develop security metrics and KPIs
  • Identify opportunities for security process improvements
  • Participate in security projects and initiatives
  • Conduct security tabletop exercises

Essential

  • 4+ years working in information security or cybersecurity operations
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field
  • Familiarity with fund management, non-bank lending industry and regulatory landscape.
  • Hands-on experience with security monitoring and incident response

Desirable

  • Relevant security certifications (Security+, CySA+, CEH, GCIH, or similar)
  • CrowdStrike Certified Falcon Administrator or similar certification
  • Experience with compliance frameworks (ISO 27001, NIST, CIS Controls)
  • Familiarity with scripting languages (PowerShell, Python)
  • Knowledge of Australian government security frameworks (ACSC, ISM)
  • Ability to explain technical security concepts to non-technical stakeholders
  • Proven experience with CrowdStrike or similar EDR/XDR platforms
  • Strong understanding of security principles, threats, and vulnerabilities
  • Knowledge of Windows and Linux operating systems
  • Familiarity with network protocols, firewalls, and security technologies
  • Experience with security information and event management (SIEM) tools
  • Knowledge of penetration testing methodologies and vulnerability management

Personal

  • A team player who demonstrates enthusiasm, resilience and ethical behaviour
  • Ability to think outside the box while maintaining an unbiased, risk and analytically driven assessment of alternate options when decisioning applications.
  • An ability to liaise well with others of all levels and source information and delegate efficiently
  • Honest and open both in actions and words with a drive to achieve results without sacrificing culture
  • Excellent written and verbal communication skills
  • Strong attention to detail, a mature positive attitude and strong work ethic

Work Setup:

Shift: Dayshift
Setup: Onsite
Location: Pasig

By Applying, you give consent to collect, store, and/or process personal and/or sensitive information for the purpose of recruitment and employment may it be internal to Cobden & Carter International and/or to its clients.

Skills

PythonLinuxCybersecurityPenetration TestingSIEMRisk ManagementComplianceLoss PreventionProcurementChange ManagementISO 27001

Similar Jobs

30

Security Analyst

Arrow · US-CO-Denver, Colorado (Panorama Arrow Building), United States of America · Remote, Hybrid, Onsite

Today

Security Analyst

Nokia · Portugal, PT · Hybrid

Yesterday

Data Security Analyst

Guidehouse is · GH Office: Atlanta, GA (5170 Peachtree), United States of America +1 · Remote

2 days ago

Security Analyst

Acrisure · 100 Ottawa Ave Sw - GRAND RAPIDS, MI, United States of America +1 · Onsite

6 days ago

Security Analyst

Acquireai · Pasig City, Philippines

6 days ago

Security Analyst

Privacy Policy · Hyderabad, Telangana, India

1 week ago

Security Analyst

Riministreet · Hyderabad, India

1 week ago

Data Security Analyst

Clarivate · R244-Kansas City, United States of America · Hybrid

1 week ago

Data Security Analyst

Career opportunities · R244-Kansas City, United States of America · Hybrid

1 week ago

Security Analyst

Center For Health Information And Analysis · Boston, MA

1 week ago

Security Analyst

ASOS · London, England, United Kingdom · Hybrid

1 week ago

Security Analyst

Nokia · India · Hybrid

1 week ago

Security Analyst

Discord · San Francisco Bay Area +1

1 week ago

Security Analyst

Copeland · Pune, India · Hybrid

1 week ago

Security Analyst

SkyBox Labs · Burnaby, British Columbia · Onsite

2 weeks ago

Security Analyst

Careers - AbsenceSoft · Denver, CO

2 weeks ago

Security Analyst

BC Pensions · Victoria, BC, Canada

2 weeks ago

Security Analyst

Computer World Services · Morrisville, NC · Hybrid

3 weeks ago

Security Analyst

Infios · Remote Brazil · Remote

3 weeks ago

Security Analyst

Pencor Services · Palmerton, Pennsylvania

3 weeks ago

Security Analyst

Rytbank · KL - Headquarter, Malaysia

4 weeks ago

Security Analyst

Goodwinprocter · Los Angeles, United States of America +1

4 weeks ago

Security Analyst

Trendmicro · Tokyo, Japan

4 weeks ago

Security Analyst

Ensigninfosecurity · Malaysia (Selangor)

1 month ago

Security Analyst

CEFCU We · Airport Main Office, United States of America

1 month ago

Security Analyst

Fortegra · Jacksonville, FL

1 month ago

Security Analyst

Integral Federal · McLean, VA, US

1 month ago

Security Analyst

Proton · Paris +1

1 month ago

Security Analyst

Sekologistics · HQ - Schaumburg, United States of America · Hybrid, Onsite

1 month ago

Security Analyst

Neptune Technology Group · Tallassee, AL +1

1 month ago