Cookies & analytics consent
We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.
Read how we use data in our Privacy Policy and Terms of Service.
🤖 15+ AI Agents working for you. Find jobs, score and update resumes, cover letter, interview questions, missing keywords, and lots more.

Bank of Commerce (Philippines) • Mandaluyong, Metro Manila, Philippines
Role & seniority: STA Analyst (Security Testing and Assurance); mid-level technical security professional
Stack/tools: vulnerability assessments, penetration testing, red/purple team exercises; Darktrace NDR; incident response support; risk documentation; familiarity with SIEM/EDR/NDR tooling; MS Office; reference standards (NIST, OWASP, MITRE ATT&CK)
Execute and support security testing engagements (VA, pentests, app reviews, red/purple team, compromise assessments) within scope and timeline
Validate, document, and draft reports; coordinate with system owners, teams, and vendors; track findings to closure
Monitor Darktrace NDR alerts, assist incident response, maintain testing records, and contribute to policy updates and awareness efforts
Bachelor’s degree in Information Security, CS, or related field
2+ years in cybersecurity/IT risk; experience with vulnerability assessments or incident response
Knowledge of vulnerability management, secure coding, red team methods
Familiarity with NIST/OWASP/MITRE ATT&CK; ability to interpret technical reports and produce clear doc
Proficiency in MS Office; strong coordination/communication skills
Certifications (OSCP, GPEN, GWAPT, CEH)
Experience with SIEM/EDR/NDR tools (e.g., Darktrace)
Experience with third-party testing projects and risk/compliance integration
Location & work type: location not specified; work type not
The Security Testing and Assurance (STA) Analyst supports and executes the Bank’s technical security testing activities under the direction of the Section Head. The role provides hands-on assistance in vulnerability assessments, penetration testing, compromise assessments, red and purple team exercises, and threat monitoring. The Analyst may be tasked to handle specific projects or testing engagements, ensuring findings are validated, documented, and tracked to closure. The position also supports the administration of Darktrace NDR, maintains risk documentation, and contributes to incident response and policy improvement initiatives.
Execute and support security testing engagements including vulnerability assessments, penetration testing, application security reviews, red and purple team exercises, compromise assessments, and physical security testing, as directed by the Section Head, ensuring activities are conducted in line with the agreed scope and timelines. Validate and document results by reviewing initial findings from security testing engagements, confirming their accuracy, and preparing draft reports with supporting evidence for Section Head review. Coordinate with system owners, application teams, and vendors during testing projects to clarify requirements, resolve issues, and escalate critical matters to the Section Head for decision. Support vendor documentation and planning by assisting in the preparation of requirements, project scopes, and related documents needed for third-party testing engagements to ensure clarity of objectives and deliverables. Track vendor outputs by monitoring submissions and timelines, verifying completeness and accuracy of reports, and raising delays or deficiencies to the Section Head for resolution Provide Darktrace monitoring support by reviewing alerts and anomalies flagged by the NDR platform, performing initial assessments, and escalating suspicious activity to the MSOC or Section Head for further investigation. Log and distribute advisories by recording and circulating intelligence reports and threat notifications received from the BAP-CID Threat Intelligence and Collaboration Platform, ensuring relevant teams are promptly informed. Maintain testing records by keeping well-organized documentation of all testing engagements, including activity logs, remediation status, and revalidation outcomes, for compliance and audit purposes Support integration of testing results by coordinating with the RA&A and ITGC sections to ensure outputs from security testing are reflected in risk assessments and compliance requirements. Provide technical inputs to incident response by supplying validated technical data and findings from testing and threat monitoring to support investigations and response activities when assigned. Assist in policy updates by providing input to the review and updating of security testing-related policies, procedures, and technical standards, ensuring they reflect current practices and findings. Contribute to awareness initiatives by helping prepare materials and training inputs that reflect lessons learned from testing engagements and highlight emerging threat trends. Stay informed on emerging threats by continuously monitoring developments in attack techniques, vulnerabilities, and testing tools to improve technical knowledge and contributions. Perform other related tasks as may be assigned by the Section Head or CISO to support the overall objectives of the Security Testing and Assurance Section
Bachelor’s degree in Information Security, Computer Science, or related field Certifications in information security or IT-related domains (e.g., OSCP, GPEN, GWAPT, CEH) are considered an advantage and may strengthen the candidate’s suitability for the role. At least 2 years of experience in cybersecurity or IT Risk, preferably with exposure to vulnerability assessments, penetration testing, or incident response. Solid understanding of vulnerability management, secure coding practices, and red team methodologies. Familiar with NIST, OWASP, MITRE ATT&CK, and BSP regulatory standards (e.g., Cir. 982, 1140). Capable of interpreting technical reports and preparing clear documentation. Proficient in Microsoft Office (Excel, Word, PowerPoint); familiarity with SIEM, EDR, or NDR tools (e.g., Darktrace) is an advantage. Effective communication skills for coordinating with technical teams, vendors, and auditors Show more Show less