Job Description
KEY RESPONSIBILITIES
You will:
- Administer and manage CrowdStrike security platform, including deployment, configuration, and optimisation
- Monitor security alerts and events through CrowdStrike console
- Perform regular health checks and ensure platform updates are applied
- Manage endpoint detection and response (EDR) activities
- Configure and fine-tune detection rules and policies
- Monitor, analyse, and respond to security incidents and alerts
- Investigate suspicious activities and potential security breaches
- Perform root cause analysis on security incidents
- Document incident response procedures and maintain incident logs
- Implement remediation measures and track resolution progress
- Prepare regular security status reports for management
- Provide updates on security metrics, incidents, and trends
- Generate monthly and quarterly security dashboards
- Present findings and recommendations to stakeholders
- Respond to internal and external due diligence queries regarding security controls and practices
- Stay current with emerging security threats, vulnerabilities, and attack vectors
- Monitor threat intelligence feeds and security advisories
- Assess the relevance and impact of new threats to the organisation
- Share threat intelligence insights with the team
- Recommend proactive security measures based on threat landscape
- Coordinate and manage annual penetration testing exercises
- Work with external security assessors and penetration testers
- Review penetration test findings and develop remediation plans
- Track and verify remediation of identified vulnerabilities
- Conduct annual Essential Eight security maturity assessments
- Ensure compliance with Essential Eight framework requirements
- Document security controls and maintain compliance evidence
- Conduct regular vulnerability scans and assessments
- Prioritize vulnerabilities based on risk and business impact
- Track remediation efforts and coordinate with IT teams
- Maintain vulnerability management database and reporting
- Verify patch compliance across systems and endpoints
- Ensure principle of least privilege is maintained
- Monitor privileged account usage and activities
- Review security logs from various systems and applications
- Correlate events across multiple security tools
- Identify anomalous behaviour and potential security issues
- Maintain and tune security monitoring rules and alerts
- Archive logs in compliance with retention policies
- Manage antivirus, anti-malware, and endpoint protection solutions
- Administer firewalls, intrusion detection/prevention systems
- Maintain data loss prevention (DLP) tools
- Configure and manage web filtering and email security gateways
- Ensure security tools are properly integrated and functioning
- Review changes to critical systems for security implications
- Participate in change advisory board meetings
- Assess security impact of proposed system changes
- Verify security configurations align with hardening standards
- Maintain secure baseline configurations
- Assess security posture of vendors and third-party providers
- Review vendor security documentation and certifications
- Monitor compliance with contractual security requirements
- Participate in vendor security assessments
- Support procurement process with security evaluations
- Verify security of backup systems and processes
- Test backup restoration procedures periodically
- Review disaster recovery and business continuity plans from a security perspective
- Ensure encrypted backups are maintained and accessible
- Participate in disaster recovery exercises
- Maintain security policies, procedures, and documentation
- Create and update security runbooks and playbooks
- Contribute to security awareness and training initiatives
- Develop security metrics and KPIs
- Identify opportunities for security process improvements
- Participate in security projects and initiatives
- Conduct security tabletop exercises
QUALIFICATIONS:
- 4+ years working in information security or cybersecurity operations
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field
- Familiarity with fund management, non-bank lending industry and regulatory landscape.
- Hands-on experience with security monitoring and incident response
- Relevant security certifications (Security+, CySA+, CEH, GCIH, or similar)
Work Schedule: Early Morning Shift (AU - 6am-3pm)
Work Set-up: Full-onsite, Ortigas, Pasig