
Information Security Analyst
Posted 22 hours ago

Posted 22 hours ago
This is a fully remote position, open to applicants in Philippines.
• Prevent, mitigate, and address significant information and cybersecurity events, incidents, and breaches.
• Research, recommend, implement, and manage security technologies, controls, and processes.
• Safeguard information systems across a global portfolio of brands and over 2,000 IT assets.
• Secure more than 400 applications and IT systems.
• Educate and engage with approximately 5,000 employees worldwide.
• Participate in global IT projects involving applications, infrastructure, security, and business initiatives.
• Provide consultation on security for ERP implementations, SIEM use cases, secure network and zero-trust redesigns, filtering technologies, patching, and vulnerability management.
• Investigate threats, security patches, and alerts, and implement necessary remedial actions.
• Design, test, evaluate, and deploy information security technologies and business cases.
• Review and uphold security policies, principles, and standards.
• Respond to significant incidents as a member of the CSIRT, including ransomware, data exfiltration, detections, and privacy breaches.
• Offer occasional out-of-hours response for high-priority or urgent incidents.
• Conduct proactive threat hunting and reactive incident response utilizing EDR/XDR, SSE, SIEM, vulnerability management, email and web filters, and other tools.
• Investigate and document incidents and provide security awareness training.
• Monitor alerts, reports, and logs for potential threats and anomalous activities.
• Collaborate with senior management and IT departments to develop and execute risk-based security programs and projects.
• Create high-level security metrics reports and deliverables.
• Assess current and future threat landscapes and brief the CISO on enterprise risks and threats.
• Provide organization-wide information security expertise and training.
• Conduct cybersecurity, control, vulnerability, and risk assessments.
• Maintain inventories of systems, infrastructure, and applications, ensuring appropriate SIEM logging.
• Classify data and systems with stakeholders and evaluate third-party vendor security.
• Analyze audits, penetration tests, and security logs to propose risk mitigation strategies.
• Manage relationships with internal and external auditors and penetration testers, along with tracking remediation.
• Support ongoing PCI compliance and identify regulatory changes.
• Implement and uphold global security policies, procedures, processes, and SLAs.
• Monitor and report on compliance with security policies.
• Explore sustainable IT practices and perform other aligned duties.
• A degree in IT, Computer Science, or a related field is highly preferred but not mandatory.
• Knowledge of network and system infrastructures acquired in a business environment.
• Understanding of, experience in, and/or eagerness to learn modern software development practices and lifecycle, infrastructure projects, vendor management, and IT service/help desk functions.
• Background in help desk, network administration, systems administration, DFIR analysis, or testing is strongly preferred.
• Ability to discuss IT-related projects and tools that have been deployed or managed, including associated security components.
• Experience participating in digital forensic investigations, incident response, and/or root cause analyses is strongly preferred.
• A minimum of one technical certification is strongly preferred, such as CEH, CISSP, OSCP, GCIH, CCSP, CCNP, NSE-4, PCNSE, GCFE, GCFA, CCSA, or equivalent.
• Understanding of information risk concepts and principles, or a desire to learn them.
• Familiarity with cloud technologies, particularly AWS and Azure.
• Strong documentation skills, including the ability to create workflows, diagrams, and internal security documentation.
• Technical understanding and practical experience with authentication mechanisms, password management tools, EMM/MDM platforms, patch and vulnerability management, firewalls, network capture tools, security models, and other security technologies is strongly preferred.
• Experience or knowledge in risk, business impact, control, and vulnerability assessments.
• Experience developing and documenting strategic, tactical, and project security plans.
• Familiarity with information security management frameworks such as CIS, ISO2700x, and NIST CSF.
• Strong understanding of business applications, including ERP and financial systems.
• High-level technical knowledge of operating systems and security technologies including SIEM, log aggregation, network security appliances, email filters, IAM, EDR, cryptography, SSE, vulnerability scanners, anti-malware solutions, security awareness training platforms, automated policy compliance tools, and desktop security tools.
• Experience in developing, documenting, and maintaining security policies, processes, procedures, and standards, or a strong desire to learn.
• Knowledge of network infrastructure, including routers, switches, firewalls, network protocols, and concepts, or a strong desire to learn.
• Ability to work with minimal supervision while staying updated on security trends, emerging threats, and controls.
• Excellent written and verbal communication skills.
• Strong analytical and problem-solving abilities.
• Capacity to manage multiple projects with overlapping deadlines.
• Learning opportunities, mentoring, and support.
• Team-building experiences and company-wide celebrations.
• Wellness programs.
• World-class offices situated in premium business hubs.
• Opportunities to collaborate with global brands and international clients.
• Continuous learning and development.
• Engaging employee programs.
• Modern, comfortable office environments.
• Flexible and collaborative working atmosphere.
ImageTrend
Stefanini LATAM
Cox Enterprises
NuHarbor Security
Get handpicked remote jobs straight to your inbox weekly.