{"schemaVersion":"jobsearcher.job.v1","id":"69c8b303376bc78fbbaa3c85","url":"https://jobsearcher.com/jobs/69c8b303376bc78fbbaa3c85","canonicalUrl":"https://jobsearcher.com/jobs/69c8b303376bc78fbbaa3c85","title":"Security Analyst","description":"Who are we?\r\nMyPass Global is a multi-award-winning workforce compliance software company. Our cutting-edge technology helps companies in high-stakes industries reduce risk, save up to 70% on back-office costs, and create safer work environments through our digital workforce solutions. As we rapidly expand with offices worldwide, we are seeking the next generation of innovative MyPassers to join us in shaping the future of our industry.\r\nRead more about us here\r\nRole Outcome\r\nThe GRC Analyst supports the integrity and currency of MyPass's third-party provider, risk, policy, and CAPA registers, ensuring all entries are reviewed, updated, or progressed to closure on schedule with appropriate evidence. The role supports the Senior Corporate Services Manager's ISMS ownership and audit obligations, and provides broader coordination support across compliance platforms, training campaigns, system access, Google Workspace guidance, and process documentation.\r\nResponsibilities\r\nPolicy Register Management\r\nMonitor the policy lifecycle to ensure review deadlines are met\r\nCoordinate the policy review and approval process across all business areas\r\nPublish approved policies in Confluence and Drata\r\nMaintain the controlled document register, published versions, and master files\r\nMaintain controlled templates within the master files and Google Gallery\r\nRisk Register Support\r\nCoordinate the timely review of risks within Drata\r\nSupport the Senior Corporate Services Manager with risk assessment scheduling, expediting evidence with stakeholders, and preparing documentation for risk closure\r\nMonitor and report on risk review completion status\r\nDrata Control Readiness Oversight\r\nMonitor and report on Drata control readiness, identifying failing or at-risk technical, operational, and people controls\r\nCreate and manage Jira tickets for control issues requiring remediation, coordinating with control owners through to resolution\r\nCoordinate personnel compliance within Drata, including monitoring onboarding and offboarding status against required timeframes\r\nMaintain the Drata evidence register, ensuring evidence is current, complete, and mapped to the correct controls\r\nThird-Party Provider Register Management\r\nMaintain the third-party provider register covering software vendors, IT service providers, and other third-party providers\r\nCoordinate vendor due diligence and periodic performance reviews with relevant stakeholders\r\nEnsure vendor contract records, renewals, and review evidence are current and accurately maintained\r\nCAPA Register Management\r\nOwn the CAPA register within QT9, covering corrective actions arising from ISO audits, risk treatments, and incidents\r\nExpedite the collection of evidence from stakeholders to support timely CAPA closure\r\nPrepare and present evidence for review by the Senior Corporate Services Manager prior to closure, flagging any gaps or inconsistencies identified\r\nMaintain CAPA reporting and manage CAPA workflows end to end\r\nSupport the internal audit programme, providing CAPA status and evidence to the Lead Auditor and internal auditors as required\r\nKnowBe4 Training Campaign Support\r\nCoordinate the rollout of new KnowBe4 training campaigns\r\nMonitor the validity of training modules to ensure content remains current\r\nPrepare and distribute KnowBe4 completion and compliance reports\r\nSystem Access Reviews\r\nCoordinate and undertake system access reviews on a rolling schedule across managed platforms\r\nSupport timely remediation of identified access issues with relevant stakeholders\r\nGoogle Workspace Support\r\nProvide guidance to users on Google Workspace functionality, including templates and shared drives\r\nUndertake analysis of user needs for shared drives to inform structure and access decisions\r\nProject Support\r\nProvide project support as required across Corporate Services initiatives, including coordination, documentation, and status reporting\r\nProcess Documentation\r\nDocument GRC standard operating procedures in Confluence, keeping content current as processes evolve\r\nCompliance and Audit Support\r\nSupport external audit processes, including ISO 27001 certification and surveillance audits\r\nMaintain documentation, configurations, and evidence in accordance with ISMS requirements\r\nRequirements\r\nCore GRC and Compliance Experience\r\nDemonstrated experience in GRC, risk, or compliance roles within an organisation managing information security or regulatory compliance obligations\r\nProven ability to manage and coordinate multiple compliance registers simultaneously, including policy, risk, and corrective action registers\r\nDemonstrated experience working within a GRC platform such as Drata or equivalent, including control monitoring, evidence management, and compliance reporting\r\nAudit and CAPA Support\r\nDemonstrated experience supporting internal or external audit programmes, including evidence preparation and coordination\r\nExperience managing or coordinating corrective action or CAPA workflows through to closure\r\nStakeholder Coordination\r\nProven ability to coordinate across multiple business areas to meet compliance deadlines without direct authority over stakeholders\r\nDemonstrated experience expediting evidence or actions from stakeholders and escalating appropriately where timelines are at risk\r\nSystems and Tooling\r\nExperience using Jira or equivalent ticketing tools for issue tracking and remediation coordination\r\nWorking knowledge of Google Workspace, including shared drive structure and administration (highly desirable)\r\nExperience documenting standard operating procedures in a platform such as Confluence\r\nPersonal Attributes\r\nDemonstrated critical thinking and independent problem-solving in past roles, with evidence of identifying and resolving issues without being directed to do so\r\nHigh attention to detail, particularly in reviewing and preparing compliance evidence\r\nInformation Security Accountabilities\r\nUnderstand own contribution to the effectiveness of the ISMS\r\nUnderstand own responsibilities within the ISMS (e.g. Acceptable Use of Assets Policy, Information Security Policy)\r\nUnderstand the consequences of non-compliance with the requirements of the ISMS\r\nUnderstand information security guidelines related to own job role\r\nLife at MyPass\r\nAccessible and friendly office in Cebu IT Park\r\nCelebrate You - Anniversary gifts as early as your first work anniversary!\r\nBe Healthy - Wellbeing policy with a strong focus on whatever makes you feel good from the inside out, and a company-sponsored Healthcare Insurance worth PHP 110,000.00.\r\nWork-Life Balance - Enjoy the right to disconnect with our 16 Paid Time Offs and 8 Compensatory Time Offs!\r\nFuel Your Growth Journey - Unlocking your potential with a blend of in-person and online learning and development opportunities\r\nGet Rewarded and Recognized - Your impact to the business is seen and recognized through our Monthly Value Awards\r\nBe Comfortable - Casual Friday every day!\r\nWe Love to Have Fun - Team outings, weekly lunches, team events, the list goes on…\r\nGenerous Employee Referral Program - Rewards for referring top talent\r\nFeel valuable\r\nWe're big on culture. So much so that the team we've carefully curated are not only high-performers, they're also excellent humans. We foster an environment that is open, respectful and collaborative, where the status quo is challenged and both success and failure are celebrated.\r\nMyPass champions diversity at all levels of the company, and we live by our core values that set us apart. We cultivate an inclusive culture and do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We are dedicated to creating a workplace where everyone feels valued, respectful, and empowered to bring their authentic selves to work. Our mantra is to make things happen, every single day.\r\nOur company values\r\nBring out the best\r\nWe connect and empower people to build a safer future. We strive to create a positive and enduring impact, no matter how small.\r\nChallenge the norm\r\nWe pursue innovation by practising curiosity and always asking 'why'. We challenge assumptions by seeking opportunities for growth and improvement.\r\nTreat people well\r\nWe treat our customers, employees and partners as equals. We foster meaningful relationships through trust, compassion and respect.\r\nWalk the walk\r\nWe are accountable for our goals, actions and collective vision. We work with integrity and are true to our word.\r\nJ-18808-Ljbffr","company":"Medium","rawCompany":"medium","city":"Manila","state":"AR","isRemote":false,"isActive":false,"createdAt":"2026-08-09T00:45:19.634Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"551114","title":"Corporate, Subsidiary, and Regional Managing Offices","slug":"corporate-subsidiary-and-regional-managing-offices"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Analyst","description":"Who are we?\r\nMyPass Global is a multi-award-winning workforce compliance software company. Our cutting-edge technology helps companies in high-stakes industries reduce risk, save up to 70% on back-office costs, and create safer work environments through our digital workforce solutions. As we rapidly expand with offices worldwide, we are seeking the next generation of innovative MyPassers to join us in shaping the future of our industry.\r\nRead more about us here\r\nRole Outcome\r\nThe GRC Analyst supports the integrity and currency of MyPass's third-party provider, risk, policy, and CAPA registers, ensuring all entries are reviewed, updated, or progressed to closure on schedule with appropriate evidence. The role supports the Senior Corporate Services Manager's ISMS ownership and audit obligations, and provides broader coordination support across compliance platforms, training campaigns, system access, Google Workspace guidance, and process documentation.\r\nResponsibilities\r\nPolicy Register Management\r\nMonitor the policy lifecycle to ensure review deadlines are met\r\nCoordinate the policy review and approval process across all business areas\r\nPublish approved policies in Confluence and Drata\r\nMaintain the controlled document register, published versions, and master files\r\nMaintain controlled templates within the master files and Google Gallery\r\nRisk Register Support\r\nCoordinate the timely review of risks within Drata\r\nSupport the Senior Corporate Services Manager with risk assessment scheduling, expediting evidence with stakeholders, and preparing documentation for risk closure\r\nMonitor and report on risk review completion status\r\nDrata Control Readiness Oversight\r\nMonitor and report on Drata control readiness, identifying failing or at-risk technical, operational, and people controls\r\nCreate and manage Jira tickets for control issues requiring remediation, coordinating with control owners through to resolution\r\nCoordinate personnel compliance within Drata, including monitoring onboarding and offboarding status against required timeframes\r\nMaintain the Drata evidence register, ensuring evidence is current, complete, and mapped to the correct controls\r\nThird-Party Provider Register Management\r\nMaintain the third-party provider register covering software vendors, IT service providers, and other third-party providers\r\nCoordinate vendor due diligence and periodic performance reviews with relevant stakeholders\r\nEnsure vendor contract records, renewals, and review evidence are current and accurately maintained\r\nCAPA Register Management\r\nOwn the CAPA register within QT9, covering corrective actions arising from ISO audits, risk treatments, and incidents\r\nExpedite the collection of evidence from stakeholders to support timely CAPA closure\r\nPrepare and present evidence for review by the Senior Corporate Services Manager prior to closure, flagging any gaps or inconsistencies identified\r\nMaintain CAPA reporting and manage CAPA workflows end to end\r\nSupport the internal audit programme, providing CAPA status and evidence to the Lead Auditor and internal auditors as required\r\nKnowBe4 Training Campaign Support\r\nCoordinate the rollout of new KnowBe4 training campaigns\r\nMonitor the validity of training modules to ensure content remains current\r\nPrepare and distribute KnowBe4 completion and compliance reports\r\nSystem Access Reviews\r\nCoordinate and undertake system access reviews on a rolling schedule across managed platforms\r\nSupport timely remediation of identified access issues with relevant stakeholders\r\nGoogle Workspace Support\r\nProvide guidance to users on Google Workspace functionality, including templates and shared drives\r\nUndertake analysis of user needs for shared drives to inform structure and access decisions\r\nProject Support\r\nProvide project support as required across Corporate Services initiatives, including coordination, documentation, and status reporting\r\nProcess Documentation\r\nDocument GRC standard operating procedures in Confluence, keeping content current as processes evolve\r\nCompliance and Audit Support\r\nSupport external audit processes, including ISO 27001 certification and surveillance audits\r\nMaintain documentation, configurations, and evidence in accordance with ISMS requirements\r\nRequirements\r\nCore GRC and Compliance Experience\r\nDemonstrated experience in GRC, risk, or compliance roles within an organisation managing information security or regulatory compliance obligations\r\nProven ability to manage and coordinate multiple compliance registers simultaneously, including policy, risk, and corrective action registers\r\nDemonstrated experience working within a GRC platform such as Drata or equivalent, including control monitoring, evidence management, and compliance reporting\r\nAudit and CAPA Support\r\nDemonstrated experience supporting internal or external audit programmes, including evidence preparation and coordination\r\nExperience managing or coordinating corrective action or CAPA workflows through to closure\r\nStakeholder Coordination\r\nProven ability to coordinate across multiple business areas to meet compliance deadlines without direct authority over stakeholders\r\nDemonstrated experience expediting evidence or actions from stakeholders and escalating appropriately where timelines are at risk\r\nSystems and Tooling\r\nExperience using Jira or equivalent ticketing tools for issue tracking and remediation coordination\r\nWorking knowledge of Google Workspace, including shared drive structure and administration (highly desirable)\r\nExperience documenting standard operating procedures in a platform such as Confluence\r\nPersonal Attributes\r\nDemonstrated critical thinking and independent problem-solving in past roles, with evidence of identifying and resolving issues without being directed to do so\r\nHigh attention to detail, particularly in reviewing and preparing compliance evidence\r\nInformation Security Accountabilities\r\nUnderstand own contribution to the effectiveness of the ISMS\r\nUnderstand own responsibilities within the ISMS (e.g. Acceptable Use of Assets Policy, Information Security Policy)\r\nUnderstand the consequences of non-compliance with the requirements of the ISMS\r\nUnderstand information security guidelines related to own job role\r\nLife at MyPass\r\nAccessible and friendly office in Cebu IT Park\r\nCelebrate You - Anniversary gifts as early as your first work anniversary!\r\nBe Healthy - Wellbeing policy with a strong focus on whatever makes you feel good from the inside out, and a company-sponsored Healthcare Insurance worth PHP 110,000.00.\r\nWork-Life Balance - Enjoy the right to disconnect with our 16 Paid Time Offs and 8 Compensatory Time Offs!\r\nFuel Your Growth Journey - Unlocking your potential with a blend of in-person and online learning and development opportunities\r\nGet Rewarded and Recognized - Your impact to the business is seen and recognized through our Monthly Value Awards\r\nBe Comfortable - Casual Friday every day!\r\nWe Love to Have Fun - Team outings, weekly lunches, team events, the list goes on…\r\nGenerous Employee Referral Program - Rewards for referring top talent\r\nFeel valuable\r\nWe're big on culture. So much so that the team we've carefully curated are not only high-performers, they're also excellent humans. We foster an environment that is open, respectful and collaborative, where the status quo is challenged and both success and failure are celebrated.\r\nMyPass champions diversity at all levels of the company, and we live by our core values that set us apart. We cultivate an inclusive culture and do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We are dedicated to creating a workplace where everyone feels valued, respectful, and empowered to bring their authentic selves to work. Our mantra is to make things happen, every single day.\r\nOur company values\r\nBring out the best\r\nWe connect and empower people to build a safer future. We strive to create a positive and enduring impact, no matter how small.\r\nChallenge the norm\r\nWe pursue innovation by practising curiosity and always asking 'why'. We challenge assumptions by seeking opportunities for growth and improvement.\r\nTreat people well\r\nWe treat our customers, employees and partners as equals. We foster meaningful relationships through trust, compassion and respect.\r\nWalk the walk\r\nWe are accountable for our goals, actions and collective vision. We work with integrity and are true to our word.\r\nJ-18808-Ljbffr","datePosted":"2026-08-09T00:45:19.634Z","dateModified":"2026-08-09T00:45:19.634Z","hiringOrganization":{"@type":"Organization","name":"Medium","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Manila","addressRegion":"AR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"69c8b303376bc78fbbaa3c85"},"url":"https://jobsearcher.com/jobs/69c8b303376bc78fbbaa3c85"}}