Security Testing and Assurance Section Head

16 hours ago


Philippines Bank of Commerce (Philippines) Full time

Overview

JOB SUMMARY

The Section Head of Security Testing and Assurance (STA) is responsible for overseeing all technical security testing activities. This includes the planning, coordination, execution, and oversight of outsourced services related to vulnerability assessments, penetration testing, compromise assessments, threat hunting, red/purple teaming, physical security testing, and application security reviews. The role ensures that all testing initiatives are risk-based, properly documented, and aligned with the Bank’s regulatory obligations, internal security policies, and industry standards. The Section Head manages relationships with third-party providers, validates findings, tracks remediation efforts, and ensures the integration of security testing results into the Bank’s broader risk management and incident response programs. This role also oversees the administration of the Bank’s Network Detection and Response (NDR) tool, Darktrace, and is responsible for monitoring and filing threat intelligence reports from the BAP-CID Threat Intelligence and Collaboration Platform.

JOB DESCRIPTION

  • Manage the execution of all technical security testing activities across the Bank, under the strategic oversight of the CISO, ensuring alignment with the Bank’s approved risk appetite and the objectives of the Information Security Strategic Plan (ISSP).
  • Plan, coordinate, and manage the delivery of outsourced technical security testing services to identify potential vulnerabilities and assess the effectiveness of the Bank’s defenses. These services include, but are not limited to: Vulnerability Assessments (VA), Penetration Testing (PT), Application Security Testing, Red and Purple Team Exercises, Compromise Assessments, Threat Hunting
  • Ensure that all new system applications undergo a thorough vulnerability assessment (VA) before go-live. Similarly, require vulnerability assessments for existing systems that have undergone major enhancements or significant changes, to confirm that new risks have not been introduced prior to deployment.
  • Define the appropriate testing methods, success criteria, and priority systems for testing, based on emerging threats and the critical role each system plays in the Bank’s operations.
  • Oversee third-party service providers by clearly defining the scope of work, expected deliverables, and service levels through well-structured RFIs, RFPs, contracts, and project plans.
  • Assess and confirm the vendor’s capabilities, tools, and testing methodologies before engagement to ensure they meet the Bank’s security standards and requirements.
  • Monitor vendor performance using defined metrics such as timeliness of delivery, accuracy of test results, and the effectiveness of remediation recommendations.
  • Ensure that vendors submit clear, complete, and timely assessment reports. Provide support to stakeholders in interpreting technical findings and clarifying results when needed.
  • Oversee the configuration, tuning, and alert monitoring of the Bank’s Darktrace Network Detection and Response (NDR) platform to ensure accurate detection of unusual or suspicious activity.
  • Review, document, and distribute intelligence reports received from the BAP-CID Threat Intelligence and Collaboration Platform for Banks. Escalate relevant advisories or threat indicators to appropriate teams for action and tracking
  • Facilitate information security training sessions for new employees as part of the onboarding process, and deliver on-demand security briefings or awareness sessions as requested by business or support units. Ensure that training content reflects relevant findings from security testing activities and emerging threat trends.
  • Monitor emerging cyber threats, attack techniques, and advancements in security testing technologies to continually improve the Bank’s testing approach and inform enhancements to third-party service provider capabilities.
  • Perform other related tasks and responsibilities as may be assigned by the CISO or ITRMD Head.

JOB QUALIFICATION

  • Bachelor’s degree in information security, Computer Science, or related field
  • Certifications in information security or IT-related domains (e.g., OSCP, GPEN, GWAPT, CEH, CISSP) are considered an advantage and may strengthen the candidate’s suitability for the role.
  • At least 3 years of experience in cybersecurity, including a minimum of 1 year in a leadership or coordination role focused on security testing or offensive security. Should have hands-on experience managing third-party security vendors and overseeing complex technical assessments across systems, applications, or infrastructure.
  • Good understanding of cybersecurity concepts, including vulnerability management, secure development practices, and red team methodologies
  • Familiar with relevant industry standards (e.g., NIST, OWASP, MITRE, CIS) and regulatory frameworks (e.g., BSP Cir. 982, 1140)
  • Able to interpret technical security reports and communicate key risks and insights to both technical and non-technical stakeholders
  • Capable of managing projects, coordinating with teams, and preparing structured documentation and executive-ready reports
#J-18808-Ljbffr

  • , Metro Manila, Philippines GCash Full time

    Overview AVP, Service Assurance Head at GCash. The Head of Service Assurance is a senior leadership role responsible for ensuring the quality, reliability, and resilience of IT service delivery. This role leads the Service Assurance function, overseeing key portfolios including Service Level Management (SLM), Partner Reliability, Fund Loss and Risk...


  • , , Philippines Metrobank Full time

    Press Tab to Move to Skip to Content Link Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure...


  • , Metro Manila, Philippines Canonical Full time

    This global leadership role in cyber security is to manage the Security Operations (SecOps) team responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies. The team is the primary owner of strategy and practices that determine how Canonical secures its data, internal infrastructure and build...

  • Information Security

    17 hours ago


    , Metro Manila, Philippines Hrtx Full time

    Information Security & Infrastructure Strategy Head Seeking a senior Filipino technology leader to head their regional information security and infrastructure capability. This role is ideal for a returnee talent: a Filipino citizen with substantial, hands-on experience working in a senior IT or cybersecurity leadership capacity overseas. The position blends...


  • , , Philippines Tyler Technologies, Inc. Full time

    We are seeking a detail-oriented and collaborative Quality Assurance Test Analyst to join our dynamic team. In this role, you will play a critical part in ensuring the delivery of high-quality software by validating functionality, usability, and performance through both structured and exploratory testing. As a QA Test Analyst, you will work closely with...


  • , , Philippines Buscojobs Full time

    Quality Assurance Assistant Manager - Cabuyao, Laguna Posted today Qualifications : Preferably less than 1-year experience specialized in Quality Control/Assurance or equivalent Hardworking, creative, analytic and technically inclined Fast learner and can work with minimum supervision Advanced functions in MS Windows Fresh graduates are encouraged to apply ...


  • , Metro Manila, Philippines Metrobank Full time

    Join to apply for the Secured Collections Operations Head role at Metrobank 1 day ago Be among the first 25 applicants Join to apply for the Secured Collections Operations Head role at Metrobank Get AI-powered advice on this job and more exclusive features. Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide...


  • , Pampanga, Philippines Quanta Paper Corporation Full time

    The Quality Assurance Supervisor assists the QA Head of Department in overseeing the Lot 7 QA team and ensuring that all quality objectives are achieved in manufacturing the company products through regular testing and inspection. He/She works in close coordination with the production team to resolve quality issues and address customer concerns. EDUCATION ...


  • , Misamis Occidental, Philippines Buscojobs Full time

    Overview Registered Nurse Quality Assurance QA Reviewer for Inoac Philippines Corporation. An exciting opportunity for a global company with continued expansion; the organization seeks potential leaders. Job Description Responsibilities and requirements are described below. This role focuses on quality control/assurance activities within the production...


  • , , Philippines Metrobank Full time

    Press Tab to Move to Skip to Content Link PERFORMANCE TEST SPECIALIST, AUTOMATION AND PERFORMANCE TESTING DEPARTMENT TO FOLLOW Be #InGoodHands with Metrobank Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual....