Talent Apply
Log in
All jobs
C

Cybersecurity GRC Analyst

Copeland
Quezon City, Manila, Philippines
Hybrid

About this role

Job title: Cybersecurity GRC Analyst

About the Role The Cybersecurity GRC Analyst will develop, implement, and maintain cybersecurity policies, standards, and procedures aligned with industry frameworks, conduct risk assessments and support audits, manage third-party risk, and oversee DLP policy strategy to protect sensitive data. This role requires collaboration with cross-functional teams to embed security controls into business processes and stay updated on threats and regulatory changes.

What You'll Do

  • Develop, implement, and maintain cybersecurity policies, standards, and procedures aligned with industry frameworks and regulatory requirements.
  • Conduct risk assessments, security control evaluations, and gap analyses to identify and mitigate risks.
  • Support internal and external audits, ensuring compliance with frameworks such as NIST CSF, ISO 27001, CIS Controls, SOC 2, and regulatory obligations.
  • Assist in management of third-party risk assessments and vendor security evaluations.
  • Track, monitor, and report on cybersecurity risks, controls, and compliance metrics.
  • Work with cross-functional teams to embed security controls in business processes and IT operations.
  • Develop and maintain risk registers, compliance documentation, and audit evidence repositories.
  • Provide cybersecurity awareness training and guidance to employees on security best practices and compliance requirements.
  • DLP Strategy & Oversight: Manage and help fine tune DLP Policies (preferably Zscaler) for Endpoint, Network and cloud to protect sensitive data (PII, PCI, IP).
  • Stay current with evolving cybersecurity threats, regulatory changes, and best practices to enhance the organization's security and compliance posture.

What We're Looking For

  • Bachelor's degree in computer science, Information Systems, or related degree plus three (3+) years of experience or equivalent combination of education and experience.
  • Strong knowledge of security and risk management frameworks like NIST CSF, CIS Critical Security Controls, ISO 27001, NIST 800-53, FAIR, and CIS.
  • Excellent oral and written communication skills; ability to communicate in technical and business terms; comfortable delivering presentations to senior management.
  • 3+ years of experience in cybersecurity, governance, risk, and compliance.
  • Experience conducting risk assessments, control evaluations, and compliance audits.
  • Strong knowledge of cybersecurity best practices, policies, and procedures.
  • Analytical, problem-solving, and communication skills; ability to work independently and collaboratively.
  • Professional certifications in IT and Cybersecurity a plus (e.g., Security+, GCRP, CGRC, etc.).

Nice to Have

  • 3-4 years of experience in Cybersecurity roles (incident response, security operations, application security, etc.)
  • Ability to multitask and manage multiple projects; flexibility to changing priorities.
  • Self-starter, initiative, critical thinker, self-directed with collaboration skills.
  • Experience designing and implementing cybersecurity reporting and metrics (KPI/KRI).
  • Fluent in English; additional languages are a plus.
  • Competencies: Tech Savvy, Optimizes Work Processes, Plans & Aligns, Business Insight, Communicates Effectively.

Compensation & Benefits

  • Flexible and competitive benefits plans; paid parental leave (maternal and paternal), vacation and holiday leave. We provide employees with flexible time off plans and support for work-life balance.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →