IT Security – Third Party Risk Management Specialist
We’re currently looking for an IT Security – Third Party Risk Management Specialist to join a global organization in the storage and transportation industry.
In this role, you will support the organization's global IT security landscape by managing third-party cybersecurity risks, responding to security incidents, supporting security operations, and helping strengthen security governance and controls.
Work Setup
- Work arrangement: Hybrid (3 days onsite; 2 days work from home)
- Schedule: Rotating morning and mid shifts per quarter
- Office location: Ortigas, Mandaluyong
- Employment type: Full-time / Regular position, Direct Hiring
What You Will Be Doing
As an IT Security – Third Party Risk Management Specialist, you will be responsible for monitoring, implementing, and maintaining security policies and guidelines across the organization's global IT environment.
You will serve as a key point of contact for security-related incidents, tickets, risks, and third-party assessments. The role involves close collaboration with internal IT Security teams, regional Service Delivery teams, security vendors, and managed security service providers.
Key Responsibilities
Third-Party Risk Management
- Identify, assess, and mitigate cybersecurity risks associated with third-party vendors, service providers, applications, and services.
- Conduct and support security and compliance evaluations of external third parties.
- Manage and monitor third-party security risks and remediation activities.
Incident Management & Security Operations
- Detect, investigate, and respond to security incidents within defined SLAs.
- Analyze security alerts and correlate security data to identify potential threats.
- Determine root causes, assess business impact, and coordinate incident resolution.
- Escalate incidents that require support from internal teams or external vendors.
Identity & Email Security
- Respond to user inquiries involving suspicious emails and potential phishing or spam threats.
- Provide support for authentication and access-related security concerns.
- Investigate high-risk sign-ins, suspicious activities, and potentially compromised accounts.
Data Privacy & Breach Response
- Support the investigation and response to personal data breach incidents.
- Assist with containment, remediation, and preventive measures.
- Prepare and maintain incident reports and supporting documentation.
Security Governance & Continuous Improvement
- Review and support the optimization of firewall policies and rulebases.
- Assist in updating and maintaining security policies, procedures, and SOC documentation.
- Identify opportunities to improve security processes and operational efficiency.
- Prepare regular security reports and provide recommendations for risk mitigation.
Threat Intelligence & Security Monitoring
- Monitor emerging cybersecurity threats, vulnerabilities, and industry trends.
- Utilize threat intelligence, data feeds, and security tools to strengthen the organization's security posture.
- Support proactive identification and mitigation of potential security risks.
Qualifications
Required
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- At least 3 years of experience in Third-Party Risk Management (TPRM) within an international environment.
- Strong understanding of:
- Cybersecurity threats and risks
- Networking and TCP/IP
- Security incident response
- Access control
- Encryption
- Multi-factor authentication
- Experience assessing cybersecurity risks associated with third-party vendors and service providers.
- Ability to analyze security reports and recommend appropriate security controls and risk mitigations.
- Strong analytical, critical thinking, problem-solving, communication, and interpersonal skills.
- Ability to work independently while collaborating effectively with internal and external stakeholders.
Preferred Skills and Experience
- Hands-on experience with the Microsoft 365 Security Suite.
- Experience with Privileged Access Management (PAM).
- Experience in Vulnerability Management.
- Familiarity with network and security monitoring tools.
- Experience with firewall and router administration.
- Knowledge of security and privacy frameworks, including:
- NIST
- MITRE ATT&CK
- GDPR
- Experience investigating and responding to cybersecurity incidents.
What We Offer
- The opportunity to be part of a global organization.
- Excellent opportunities for career growth and professional development.
- A competitive compensation package with attractive perks and comprehensive benefits.
- A flexible hybrid work arrangement that supports work-life balance.