Job Description
The Information Security Analyst is responsible for protecting the organization's information assets, systems, and networks from security threats, vulnerabilities, and unauthorized access. This role monitors, analyzes, and responds to security incidents, implements and maintains security controls, and supports compliance with information security policies and standards. The position requires strong technical knowledge of cybersecurity practices, analytical skills, and the ability to work closely with the IT team and other departments to safeguard company data and infrastructure.
Key Responsibilities
Category 1: Security Monitoring & Incident Response
- Monitor security systems, networks, and endpoints for suspicious activity, intrusions, and policy violations
- Investigate, analyze, and respond to security alerts, incidents, and breaches in a timely manner
- Conduct root-cause analysis of security incidents and recommend corrective and preventive actions
- Maintain and monitor security tools such as SIEM, firewalls, endpoint detection and response (EDR), and antivirus systems
- Support the use of employee monitoring and insider-threat detection tools (e.g., Teramind) to identify anomalous user behavior, where applicable
Category 2: Risk Management, Compliance & Vulnerability Management
- Conduct regular vulnerability assessments, security audits, and penetration testing coordination
- Identify security gaps and risks across systems, applications, and infrastructure, and recommend remediation plans
- Support compliance with information security standards and frameworks (e.g., ISO 27001, NIST, Data Privacy Act)
- Develop, update, and enforce information security policies, procedures, and guidelines
- Assist in business continuity and disaster recovery planning related to information security
Category 3: Stakeholder Support & Security Awareness
- Collaborate with the IT Manager and IT team to implement and maintain security controls across systems and networks
- Conduct information security awareness training and phishing simulation programs for employees
- Support access management processes, including user provisioning, deprovisioning, and access reviews
- Prepare security reports, dashboards, and metrics for management and key stakeholders
- Stay current on emerging threats, vulnerabilities, and industry best practices, and recommend improvements accordingly
QUALIFICATION & REQUIREMENTS
- Bachelor's degree in Information Technology, Computer Science, Information Security, or a related field
- Relevant certifications such as CompTIA Security+, CEH, CISSP, or CISM are preferred
- ITIL or IT service management certification is an advantage
Experience:
- Minimum of 2–4 years of experience in information security, IT security operations, or a related role
- Experience in security monitoring, incident response, and vulnerability management
- Experience supporting compliance with information security frameworks and data privacy regulations
- Background in network security, systems administration, or IT infrastructure is an advantage
- Experience working with cross-functional IT and business teams
SKILLS & COMPETENCIES
Technical Skills:
- Strong knowledge of information security principles, frameworks, and best practices (ISO 27001, NIST, CIS Controls)
- Experience with SIEM, firewalls, endpoint protection, and intrusion detection/prevention systems
- Familiarity with employee monitoring and data loss prevention tools such as Teramind is a plus, though not required
- Vulnerability assessment and penetration testing coordination
- Understanding of network security, cloud security, and identity and access management
- Proficiency in Microsoft Office and security reporting tools
- Knowledge of data privacy regulations (e.g., Philippine Data Privacy Act, GDPR)
- Incident response and root-cause analysis methodologies
Soft Skills:
- Strong analytical and critical thinking skills
- Excellent communication and presentation skills
- High attention to detail and sense of urgency in handling security incidents
- Ability to work independently and collaboratively across teams
- Sound judgment and discretion when handling sensitive information
- Adaptability and a continuous-learning mindset given the evolving threat landscape
- Results-driven and proactive approach to problem-solving
- Ability to manage multiple priorities in a fast-paced environment
GROWTH AND DEVELOPMENT OPPORTUNITIES
This role offers the opportunity to build deep expertise in information security operations and risk management while working closely with the IT Manager and broader technology team. It provides a strong career development path toward specialized roles in cybersecurity, IT risk and compliance, or security leadership, with exposure to enterprise-wide security tools and initiatives.
WORK ENVIRONMENT
- Hybrid Work Setup: Combination of remote work and on-site collaboration
- Travel Requirements: Occasional travel as needed for site visits or security assessments
- Work Conditions: Fast-paced environment requiring strong prioritization, availability for incident response, and problem-solving capabilities
SALARY BENCHMARK NOTE
Based on current Philippine market data (Glassdoor, Payscale, and ERI SalaryExpert, 2026), Information Security Analyst / IT Security Analyst roles with 2–4 years of experience typically range from approximately ₱600,000 to ₱1,000,000 per year (roughly ₱50,000–₱80,000 per month gross), with variation by company size, industry, and certifications held. The proposed budget above reflects a competitive mid-range position for this level.
EQUAL OPPORTUNITY STATEMENT
Dermorepubliq is an equal opportunity employer and is committed to fostering a diverse and inclusive work environment.