Information Security Lead
2 weeks ago
Information Security Lead (Risk Assessment) Makati, National Capital Region, Philippines Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance. Policy and Procedure Development: Create, maintain, and enforce comprehensive information security policies, procedures, and standards (e.g., access control, data handling, incident response, remote work security) that adhere to industry best practices and client SLAs. Conduct regular risk assessments to identify, analyze, and prioritize security vulnerabilities and threats across systems, networks, applications, and processes. Develop and implement mitigation plans to address identified risks, recommending appropriate security controls and technologies. Compliance and Regulatory Adherence: Ensure the BPO's compliance with relevant national and international data protection regulations (e.g., GDPR, HIPAA, PCI-DSS, local Philippine privacy laws). Oversee internal and external audits (e.g., ISO 27001, NIST) and ensure all security measures align with established frameworks. Prepare detailed reports for management and clients on compliance status and audit findings. Budget Management: Contribute to the development and management of the information security budget, ensuring optimal allocation of resources for security tools, training, and personnel. Operational Security Management Incident Response and Management: Develop and lead the organization's incident response plan (IRP), including detection, containment, eradication, recovery, and post-incident analysis. Coordinate investigations into security breaches or incidents, performing root cause analysis and implementing corrective and preventive actions. Communicate incident status and impact to stakeholders, including senior management, legal, compliance, and affected clients. Conduct tabletop exercises and simulation drills to test the effectiveness of the IRP. Vulnerability Management: Lead regular vulnerability assessments and penetration testing activities on infrastructure, applications, and networks. Oversee the patching and remediation of identified vulnerabilities. Analyze threat reports and security advisories to proactively protect against new threats. Security Monitoring and Operations: Oversee the continuous monitoring of IT systems and networks for suspicious activities, trends, and patterns using SIEM tools. Ensure the effective operation and maintenance of security tools such as firewalls, IDS/IPS, antivirus, and data loss prevention (DLP) systems. Access Control Management: Oversee the implementation and enforcement of robust access control policies, ensuring only authorized personnel have access to sensitive data and systems. Data Protection and Privacy: Implement measures to protect the confidentiality, integrity, and availability of all data, including encryption, secure storage, backup and disaster recovery plans. Vendor Security Management: Assess and ensure the security posture of third-party vendors and partners. Conduct risk assessments relevant to each vendor and collaborate with teams to address any identified risks. Ensure vendor compliance with the organization's security and compliance obligations. Team Leadership and Development Lead and Mentor: Guide, mentor, and manage a team of security professionals, fostering a security-first mindset across the organization. Security Awareness and Training: Develop and deliver comprehensive security awareness and training programs for all employees. Collaboration: Work closely with IT, operations, legal, HR, and client-facing teams to integrate security into all aspects of operations. BPO‑Specific Considerations Client Relationship Management: Serve as key point of contact for clients regarding information security matters, audits, compliance, and concerns. Multi‑Tenancy Security: Understand and manage complexities of securing data for multiple clients within shared infrastructure. Service Level Agreements (SLAs): Ensure security practices meet or exceed security clauses defined in client SLAs. Global Security Standards: Be well‑versed in a wide range of global security standards and regulations. Job Qualifications: Rewrite the blueprints: Create clear, up-to-date security rules everyone follows. Reinforce the walls: Implement technical systems and tools to block unauthorized access and prevent data exfiltration. Supervise the guards: Lead and train the existing IT team to detect and stop threats efficiently. Build client confidence: Act as the expert face with clients on security, demonstrating compliance with global privacy standards (e.g., GDPR). Keep us out of trouble: Ensure compliance with all data privacy laws locally and internationally to avoid fines and legal issues. #J-18808-Ljbffr
-
Information Security Lead
6 days ago
Quezon City, National Capital Region, Philippines Asticom Technology Inc Full time ₱900,000 - ₱1,200,000 per yearJob Roles and ResponsibilitiesI. Strategic Leadership and Governance:Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.Policy and Procedure Development: Create, maintain, and...
-
Information Security Lead
6 days ago
Quezon City, National Capital Region, Philippines Asticom Technology Inc. Full timeJob Roles and ResponsibilitiesI. Strategic Leadership and Governance:Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.Policy and Procedure Development: Create, maintain, and...
-
Information Security Manager
4 weeks ago
Quezon City, Philippines Metro Pacific Tollways Corporation Full timeOverview The Information Security Manager will help develop and implement the organization’s cybersecurity strategy and manage a team of Information Security personnel in securing Metro Pacific Tollway Corporation’s information systems, infrastructure, and data against internal and external threats. Responsibilities Design, develop, and implement the...
-
Security Information and Event Management
2 days ago
Quezon City, National Capital Region, Philippines SpringSkill Full time ₱500,000 - ₱1,000,000 per yearJob Title: SIEM Associate ManagerLocation: Quezon CitySalary: NegotiableAbout the RoleWe are looking for a SIEM Associate Manager to lead, design, and implement advanced cybersecurity solutions that protect enterprise systems, applications, data, and infrastructure. This role requires both technical expertise and strong leadership to ensure the integrity and...
-
Security Lead
4 weeks ago
Quezon City, Philippines Miescor Builders Inc. Full timeJob Summary Performs under the supervision of Safety Health & Environment Officer (SHE) Department Head. Serves as Security Lead of the company. The Security Lead monitors the compliance of security providers on security standards and other security requirements of MIESCOR BUILDERS INC. security end-users. Assists Head, Security in ensuring compliance with...
-
Security Lead
4 days ago
Quezon City, National Capital Region, Philippines Miescor Builders Inc. Full time ₱900,000 - ₱1,200,000 per yearJob SummaryPerforms under the supervision of Safety Health & Environment Officer (SHE) Department Head. Serves as Security Lead of the company.The Security Lead monitors the compliance of security providers on security standards and other security requirements of MIESCOR BUILDERS INC. security end-users. Assists Head, Security in ensuring compliance with...
-
Cloud Information Security Engineer
10 hours ago
Quezon City, National Capital Region, Philippines Manulife Full time $60,000 - $120,000 per yearWe're looking for a Cloud Information Security Engineer to join our Enterprise Technology & Services team at MBPS. In this role, you are expected to be part of the team which will work with different service areas within ETS and serve as a trusted partner and domain expert to the business and help them protect their information assets. Participate in...
-
Information Security Manager, IAM
4 weeks ago
Quezon City, Philippines Manulife Financial Full timeOverview We’re looking for an Information Security Manager, Identity Access Management (IAM) Consultant to join our Group Functions IT Information Security and Business Resilience Team at MBPS. In this role, you are expected to apply identity access security risk knowledge and expertise to assist with IT information security First Line of Defense...
-
Information Security Manager
6 days ago
Mandaluyong City, National Capital Region, Philippines Data Analytics Ventures, Inc. Full time ₱1,200,000 - ₱2,400,000 per yearThe Information Security Manager is responsible for safeguarding the organization's information assets by implementing, managing, and overseeing the company's security policies, protocols, and procedures. This role involves identifying and mitigating security risks, ensuring compliance with industry standards, and leading efforts to protect sensitive data...
-
Information Security Manager, IAM
4 weeks ago
Quezon City, Philippines Manulife Full timeManulife, Quezon City, National Capital Region, Philippines Overview Information Security Manager, Identity Access Management (IAM) Consultant to join our Group Functions IT Information Security and Business Resilience Team at MBPS. In this role, you are expected to apply identity access security risk knowledge and expertise to assist with IT information...