
Cybersecurity Specialist
- 🇵🇠Philippines
- On-site
- 1 day ago
- Vulnerability Management
- Incident Response
- ISO 27001
- CMMC
- AI
- Windows
- Jira
- Disaster Recovery
- SOC2
- CISSP
- CISM
- CompTIA Security+
- Equity
Description
TrueNAS is redefining enterprise storage by delivering proven data resilience, performance, and flexibility without the complexity or constraints of legacy solutions. As the most deployed storage platform in the world, TrueNAS already powers critical data storage infrastructure for businesses, research institutions, and government agencies across 140+ countries and millions of users. Our mission is simple: to become the most trusted name in data storage.
Originally founded in Silicon Valley in 2002 under the name iXsystems, TrueNAS is a profitable, independent company with a culture rooted in trust, curiosity, technical excellence, and continuous improvement. Whether you work remotely or on-site, you’ll be part of a team that values collaboration and meaningful impact - where people come before profit, and bold ideas drive the future of data infrastructure.
If you’re ready to help shape the future of enterprise storage, we’d love to connect.
Position Overview:We are looking for a Cybersecurity Specialist to own the security of our systems, data, and people. This person leads our security operations and program, from access reviews and vulnerability management to incident response, compliance, and the policies that tie them together, and works with the systems and network administrators to build security into how we operate.
This is an in-office role (5 days M-F) in our Makati office. The hours for this position are 9:00 pm - 6:00 am PHT
Base Pay Range
The base pay range of this position is ₱128,692 to ₱168,069 per month.In addition to base salary, this position is eligible to participate in the Company’s bonus program with a target bonus opportunity of10% of base salary, subject to the achievement of individual and Company performance objectives and the terms of the applicable Company bonus plan.Â
Please note that the provided range reflects the pay spectrum for positions within the same job category as the one to which this position belongs. The final offer will consider various factors, such as location, education, and prior experience, to ensure a comprehensive and fair compensation assessment.Â
TrueNAS offers a comprehensive package of benefits including health, dental, vision, paid time off, and stock options. Benefits program.Â
Expected Posting Timelines
This position will be open for a minimum of 5 days, a maximum of 90 days.
The Day-to-Day
The essential functions and responsibilities for this position include but are not limited to, the following. Other duties may be assigned as needed.
- Protect the confidentiality, integrity, and availability of the company's systems, data, and users by leading day-to-day security operations and driving the long-term improvement of our security program.
- Build and improve endpoint monitoring and detection with key stakeholders across IT, engineering, and the business, monitor systems, endpoints, and network activity for threats, manage endpoint protection, email security, patch compliance, and vulnerability scans, and lead incident response from investigation through recovery and post-incident review.
- Conduct user access reviews, and enforce least-privilege access, MFA, and password policies across applications and directory and MDM services.
- Lead and execute the overarching cybersecurity program strategy. Design, implement, and enforce comprehensive IT security policies, standards, and procedures aligned to ISO 27001 and CMMC compliance standards.Â
- Establish and maintain AI security governance, including policies for the approved use of AI tools, review of AI applications and integrations before adoption, controls on what company data can be shared with them, and monitoring for unapproved use.
- Own security patch management for servers and VMs, including tracking advisories, prioritizing patches by risk, coordinating maintenance windows with key users and stakeholders, and verifying and reporting patch compliance.
- Lead internal and external audits, compliance and risk assessments, and track corrective actions through to closure.
- Act as the security resource on IT and business projects, from planning and scoping through rollout, so new systems launch securely.
- Serve as the subject matter expert and point of escalation for security concerns, handle escalated security tickets via Jira, and report on security posture and risks to management.
- Review firewall rules, VPN, and network segmentation with the Senior Network Administrator and key Business Technology group key leaders, and advise on secure configuration for new systems, applications, and vendors before adoption.
- Verify that backups and disaster recovery plans are tested and protected against ransomware and data loss.
- Run security awareness activities, including phishing simulations and onboarding briefings, and remind users of basic security hygiene.
- Evaluate new security tools and solutions, recommend improvements to management, and keep incident records, risk registers, runbooks, and security documentation up to date.
- Guide IT team members on security practices, and help build the team's security capability.
- Available for after-hours response during security incidents.
Education and Experience
We have identified the following that have helped others find success in this role. We understand that knowledge comes from many forms of learning and experience, and we value each person's unique path.
- Bachelor's degree in Information Technology, Computer Science, Computer Engineering, or related field.
- At least 5 years of experience in IT, with at least 4 years in a dedicated IT security role.
- Proven experience leading security incident response, from investigation through containment, recovery, and post-incident review.
- Experience building or running a vulnerability management, access review, or security awareness program in a business environment.
- Experience leading or supporting ISO 27001, SOC2, or data privacy compliance work, including audits and corrective actions.
- Experience writing security policies and presenting risks and recommendations to leadership.
- The following certifications are a big advantage: CISSP or CISM, and ISO/IEC 27001 Lead Implementer, CompTIA Security+, and Certified Data Protection
Equal Employment Opportunity:
iXsystems DBA TrueNAS, Inc. provides equal employment opportunities to all employees and applicants in all company facilities without regard to race, color, religious creed, sex, national origin, ancestry, citizenship status, pregnancy, childbirth, physical disability, mental and intellectual disability, age, military status or status as a Vietnam-era or special disabled veteran, marital status, registered domestic partner or civil union status, gender (including sex stereotyping and gender identity or expression), medical condition (including, but not limited to, cancer-related or HIV/AIDS-related), genetic information, or sexual orientation in accordance with applicable federal, state and local laws. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Cybersecurity Specialist · TrueNAS