en

Services

We understand that no two organisations are the same. Find out more about how we've customised our talent solutions to help clients across South East Asia meet their needs.

Read more
Jobs

View all the latest job opportunities in the Philippines. Write a new chapter in your career with Robert Walters today.

See all jobs
Candidates

Together, we’ll map out career-defining, life-changing pathways to achieve your career ambitions. Browse our range of services, advice, and resources.

Learn more
Services

We understand that no two organisations are the same. Find out more about how we've customised our talent solutions to help clients across South East Asia meet their needs.

Read more
About Robert Walters Philippines

Since our establishment in 2016, our belief remains the same: Building strong relationships with people is vital in a successful partnership.

Learn more

Work for us

Our people are the difference. Hear stories from our people to learn more about a career at Robert Walters

Learn more

Tech Security Engineer (GRC)

Save job

Our client is seeking a highly skilled Tech Security Engineer with a focus on Governance, Risk and Compliance (GRC).

This role is integral to the organisation's cybersecurity framework, ensuring its effective implementation and maintenance. The successful candidate will be responsible for documenting and updating security policies, reporting on compliance and risk metrics, conducting information security risk assessments, leading security awareness programs, and monitoring security compliance with regulatory and organisational requirements.

  • Key role in managing cybersecurity risk controls.
  • Supporting the development of security policies to safeguard the organisation’s assets.
  • Continuously improving security measures to protect digital assets and information systems.

What you'll do:

As a Tech Security Engineer (GRC), you will play a pivotal role in shaping the cybersecurity landscape of the organisation. Your day-to-day responsibilities will include implementing the organisation's cybersecurity governance framework, developing robust security policies aligned with industry best practices, conducting comprehensive risk assessments, evaluating third-party vendors' security risks, conducting internal system assessments, delivering impactful security awareness training programmes, maintaining up-to-date documentation of all processes and controls, and providing regular reports to senior management.

  • Implement and maintain the organization's cybersecurity governance framework.
  • Develop and update security policies, procedures, and standards to align with industry best practices and regulatory requirements.
  • Perform security risk assessments to identify potential threats and vulnerabilities across internal and external environments.
  • Evaluate third-party vendors’ security risk postures by assessing their security controls and compliance with contractual security obligations.
  • Conduct risk-based security assessments for internal systems, applications, and infrastructure.
  • Develop and deliver security awareness training for employees, third-party vendors, and stakeholders.
  • Develop and maintain security assessment checklists, frameworks, and methodologies.
  • Generate regular reports on governance, risk, and compliance metrics for senior management.

What you bring:

The ideal Tech Security Engineer (GRC) candidate will bring a wealth of experience in cybersecurity governance, risk management and compliance. You should hold a bachelor's or master's degree in a relevant field and have professional security certifications such as ISO27001 Lead Implementer or Lead Auditor, ISO31000 Risk Manager, CISSP, CISM, CRISC or CISA. Your strong knowledge of security frameworks and standards, proficiency in GRC management tools, and experience with audit processes will be key to your success in this role.

  • Bachelor's or master's degree in computer science, Information Technology, Cybersecurity or a related field.
  • Professional Security certifications such as ISO27001 Lead Implementer or Lead Auditor, ISO31000 Risk Manager, CISSP, CISM, CRISC or CISA is highly desirable.
  • At least 4+ years’ experience in cybersecurity governance, risk management and compliance.
  • Understanding of cybersecurity principles, practices, and risk management methodologies.
  • Strong knowledge in security frameworks and standards such as ISO 27001, NIST, CIS, OWASP, GDPR, and PCI-DSS.
  • Proficiency in tools used for GRC management and compliance tracking.
  • Experience with audit processes and regulatory compliance requirements.

What sets this company apart:

Our client is a leading global organisation that values the importance of cybersecurity. They offer an inclusive work environment where every employee is valued for their unique contributions. They are committed to providing their employees with opportunities for growth and development, and they recognise the importance of work-life balance. Their commitment to excellence extends beyond their products and services to their dedication to creating a positive impact on society.

What's next:

Ready to take the next step in your career? Apply now!

Apply today by clicking on the link provided. We look forward to receiving your application!

Due to the high volume of applications we are experiencing, our team will only be in touch with you if your application is shortlisted.

Contract Type: FULL_TIME

Specialism: Tech & Transformation

Focus: Cyber Security

Industry: Banking

Salary: Negotiable

Workplace Type: Hybrid

Experience Level: Associate

Location: Taguig

Job Reference: YR6IVJ-3267BEBA

Date posted: 23 April 2025

Consultant: Cyrene Villanueva