Sourcefit

Cybersecurity & Compliance Consultant

Sourcefit Quezon City, Metro Manila, Philippines

Outsourcing/Offshoring · 1,001-5,000 employees

Yesterday
security Junior (0-2 yrs) Full-time Philippines
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The consultant will support client engagements across various compliance frameworks including SOC 2, ISMS, and PCI DSS. Responsibilities include conducting gap analyses, gathering evidence, documenting controls, and coordinating with stakeholders to ensure audit readiness.

What they look for

SOC 2 ISMS Data Privacy PCI DSS Gap Analysis Audit Readiness Cybersecurity IT Audit GRC Compliance Frameworks Risk Management Internal Controls GDPR CCPA Documentation Communication

Requirements

Candidates should have a bachelor's degree in a technical field and 6 months to 2 years of experience in cybersecurity, IT audit, or compliance. Proficiency in frameworks like SOC 2, PCI DSS, or ISO 27001 is required, along with strong analytical and documentation skills.

Full description

Position Summary

We're seeking a Cybersecurity & Compliance Consultant to support client engagements across SOC 2, ISMS, Data Privacy, and PCI DSS. The role will assist with assessments, gap analysis, control documentation, evidence gathering and review, remediation tracking, and audit readiness.

The ideal candidate has foundational knowledge or practical exposure to cybersecurity, IT audit, GRC, or compliance frameworks and is comfortable working with clients and internal teams to support compliance engagements.

Job Details

Work set up: On-site (Bridgetowne, QC)

Schedule: Monday to Friday | 9 AM to 6 PM | Flexible to an extent

Holiday: Will follow PH Holidays

Key Responsibilities

  • Support SOC 2 Type 1 and Type 2 assessments, including scoping, control documentation, evidence gathering and review, and audit readiness activities.
  • Assist with ISMS assessments and audits, including documentation, control reviews, evidence collection, and tracking of action items.
  • Support privacy assessments, including PIAs, DPIAs, gap assessments, documentation reviews, and remediation tracking.
  • Assist in assessing compliance with privacy regulations and frameworks such as GDPR, CCPA, and local regulatory privacy requirements.
  • Support PCI DSS assessments and gap analyses, including evidence gathering, documentation review, and identification of potential compliance gaps.
  • Coordinate with clients, auditors, QSAs, legal, technology, and business teams to collect required information and evidence and track outstanding requirements.
  • Prepare assessment documentation, reports, trackers, and other compliance deliverables.
  • Support remediation activities and follow up on open findings and action items.
  • Participate in client meetings and provide support in explaining compliance requirements and assessment findings.
  • Stay updated on relevant cybersecurity, compliance, privacy, and industry best practices.

Qualifications & Skills

  • Bachelor's degree in Computer Science, Information Technology, Information Systems, or a related technical field preferred.
  • 6 months to 2 years of experience in cybersecurity, information security, GRC, IT audit, technology risk, compliance, or a related field, with exposure to governance, risk, controls, audit support, compliance documentation, or evidence gathering.
  • Exposure to at least one of the following: SOC 2 Trust Services Criteria, PCI DSS, data privacy requirements, ISO 27001, or NIST.
  • Hands On Experience on cybersecurity, risk management, internal controls, and compliance concepts.
  • Relevant certifications such as CISA, ISO 27001, Security+, or other cybersecurity/compliance certifications are preferred but not required.
  • Strong analytical, documentation, communication, and organizational skills.
  • Ability to work effectively with clients and cross-functional teams.
  • Willingness to learn and develop expertise in cybersecurity and compliance frameworks.

Similar roles