- Location
- Baguio, Philippines
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Operations
- Experience
- 1+ years
- Closing date
- Today
- Source
- Workday
Description
Moog is a performance culture that empowers people to achieve great things. Our people enjoy solving interesting technical challenges in a culture where everyone trusts each other to do the right thing. For you, working with us can mean deeper job satisfaction, better rewards, and a great quality of life inside and outside of work.
Job Title:
Security Operations AnalystReporting To:
Head, IT SectionWork Schedule:
Hybrid – Baguio City, PHAs an IT Security Analyst, you will be responsible for supporting and monitoring Moog’s cybersecurity operations. The IT Security Analyst is a cybersecurity professional who monitors security alerts, investigates security incidents, conducts risk assessments, implements security controls, and contributes to the development of security policies & procedures. This position will be located at the Moog facility in Baguio, Philippines with a focus on the EASA Part-IS regulation.
Responsibilities:
- Act as the designated EASA Part-IS lead in Baguio.
- Operates and maintains the EASA Part-IS-compliant ISMS in Baguio
- Monitor and analyze security events, identify vulnerabilities, and develop strategies to address security incidents.
- Conduct vulnerability assessments, risk analysis, and security audits to identify weaknesses in systems and processes.
- Coordinates cyber security risks that could affect aviation safety in Baguio.
- Serves as the primary interface for EASA Part-IS in CAG Baguio with EASA regulators and auditors.
- Coordinates and aligns efforts with other EASA Part-IS leads in other regions to reduce duplication.
- Follow, prepare, design, and test security incident response procedures and playbooks.
- Document, prioritize, and formally report incidents, root cause analyses, and after-action reviews.
- Deploy, manage and maintain all security systems and their corresponding or associated software, including endpoint security software, intrusion detection systems, cryptography systems, and privileged account management software.
- Participant in and \ or lead the implementation of security controls, tools, and infrastructure to protect systems and data.
- Experience with cybersecurity frameworks such as Cyber Essential Plus, CMMC, NIST SP 800-53 & 171, ISO, etc.
- Must be onsite 75%.
- Travel to other Moog Asia Pacific locations will be required.
Qualifications:
- Bachelor’s degree in Information Security, Information Technology, Computer Science or related field preferred.
- More than 3 years’ experience in Security with more than five years working in an IT administration role.
- Experience should also include 1 to 3 years working with the following security tools and technologies:
- EDR / XDR platforms or Endpoint Security technologies
- SIEM platforms
- Email Security Platforms
- Privileged Account Management
- Vulnerability Management
- Experience should also include 1 to 3 years working with the following security tools and technologies:
- Strong understanding of enterprise security architecture design, security concepts, principles, and technologies.
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Ability to conduct research and log analysis into IT security issues and products as required.
- Demonstrated communication skills with both technical and non-technical audiences.
- Understanding of security policies, standards, and procedures.
- Incumbent must have flexible availability, as non-traditional work hours will be required, based on business need.
Preferred Qualifications:
- One or more of the following (or similar) relevant industry-recognized security certifications:
- CompTIA Security+ or Security X
- Certified Ethical Hacker
- GIAC Security Essentials Certification
- ISACA Certified Information Security Manager
- Microsoft Certified Systems Engineer: Security
- (ISC)2 CC, SCCP, CISSP, ISSAP, or ISSEP
- Experience with cybersecurity frameworks such as Cyber Essential Plus, CMMC, NIST SP 800-53 & 171, ISO, etc.
- Familiarity with scripting languages (e.g., Python)
- Working experience with MITRE ATT&CK and Cyber Kill Chain frameworks
- Proven analytical and problem-solving abilities
- 1– 3years of experience working with the following security tools and technologies:
- Vulnerability Management Platforms
- Cloud Platforms & Security (Azure, AWS, or GCP)
- Attack Surface Management Platforms
- Endpoint encryption