
Information Security Analyst
- Manila City, Metro Manila
- Permanent
- Full-time
They will be heavily involved with creating our disaster recovery plan, including preventive measures such as regularly copying and transferring data to an offsite location. It also involves plans to restore proper IT functioning after a disaster. The Information Security Analyst will continually test the steps in their recovery plans.
Information Security Analysts are required stay up to date on IT security and on the latest method attackers are using to infiltrate computer systems. Analysts need to research new security technology to decide what will most effectively protect their organization. In addition to reviewing and auditing the Information Technology Infrastructure for the maintenance of security and compliance.What You'll Do:
- Hands on installation, support, configuration and maintenance of Bill Gosling’s network and security equipment (hardware and software).
- Create and assist with the maintenance of Business Management System and Business Continuity Management Manual including: Request for Change, Incident, Problem and Risk Identification process per Bill Gosling’s ISO 9001/27001 processes related to networking and security infrastructure. Ensure information is accurate and complete and provide clarification as requested. Execute changes upon approval.
- Manage the securitization of LAN, WAN, routers/switches, internal/external connectivity, Firewalls, VPN, VOIP, wireless and related network/security technologies as required.
- Creation and maintenance of internal and external information security documentation such as client/vendor/internal audits.
- Participation in Disaster Recovery / Business Continuity / Cyber Response planning and testing.
- Contribute to operational and support best practices and standard process development through secure practices.
- Ensure network and security infrastructure and related procedures support business requirements.
- Collaborate with, support, and provide coverage for other roles within the IT department as needed.
- Perform other duties as assigned by management and/or supervisor.
- Deal with clients in a professional and appropriate manner, in accordance with Bill Gosling Outsourcing’s “Promise of Performance” and “The Gosling Theory” and all Company Policies
- On-call and after-hours work required
- Ability to travel to/from branch offices if required
- Highly available and reliable in times of emergency changes and/or support
- Contact person for Network / Information Security related matters
- Participation in weekly Change Advisory Board (CAB), Control Self-Assessment (CSA) Board and Information Security and Risk meetings
- Logging of RFCs, Incidents, Problems and Risks per Bill Gosling’s ISO 27001 and PCI DSS standard processes.
- Function as an internal consulting resource on network, information security issues and/or coordinate information security efforts with the internal Control Self-Assessment (CSA) team or other business functions
- Conduct/complete information security risk assessment programs including internal, vendor and client assessments
- Provide, coordinate and/or assist with network and information security awareness, Incident response and change management, Business continuity & disaster recovery programs and serve as the information security contact for all internal/external users/clients/vendors/contractors
- Ensure the secure operation of the organization’s computer systems, servers, and network connections.
- Audit network and user activity in addition to assisting with the maintenance of the Branch Test/Task Schedule.
- Perform internal/external vulnerability scanning, reporting and remediation
- Determine network and security needs, develop, and implement solutions.
- Identification of non-conforming processes, security or services
- Report access privileges inappropriate to job duties to the MC and/or VP for correction
- Internal consulting related to understanding of ISO 9001/27001(Security) standard
- Understanding of PCIDSS and requirements related to certification at Bill Gosling Outsourcing
- Champion company core values and other company programs
- Other duties as assigned