Head of Information Security

3 days ago


Manila, National Capital Region, Philippines Viventis Search Asia Full time

Job Summary:
We are seeking a highly experienced Head of Information Security & Data Privacy to lead and manage the organization's cybersecurity, risk management, regulatory compliance, and data protection strategy ensuring operational resilience and business continuity. This role will be responsible for securing digital banking platforms, financial transactions, and customer data, ensuring compliance with Bangko Sentral ng Pilipinas (BSP) regulations, Data Privacy Act of 2012 (RA 10173), and global security standards such as ISO 27001, PCI DSS, and NIST.

Key Responsibilities:

  1. Information Security Strategy & Leadership

    • Develop and implement a comprehensive Information Security and GRC strategy aligned with business and regulatory requirements.

    • Establish and enforce security governance frameworks based on ISO 27001, NIST, COBIT, and BSP Circulars (e.g., BSP Circular 982 on Cybersecurity Risk Management, BSP Circular 808 on IT Risk Management).

    • Implement Zero Trust Security Architecture, Multi-Factor Authentication (MFA), Encryption, and Identity & Access Management (IAM) solutions.

    • Collaborate with IT, Legal, Compliance, and Business Units to align security controls with operational and regulatory needs.
  2. Governance, Risk & Compliance (GRC)

    • Design and maintain the organization's IT governance framework, policies, and regulatory compliance programs.

    • Ensure compliance with BSP regulations, the Philippines Data Privacy Act (RA 10173), PCI DSS, ISO 27001, AMLA (Anti-Money Laundering Act), and other applicable financial regulations.

    • Lead Enterprise Risk Management (ERM) initiatives, performing risk assessments, compliance audits, and security policy enforcement.

    • Manage third-party risk assessments to ensure IT service providers and vendors comply with security and privacy standards.

    • Establish a Regulatory Compliance Monitoring Program, ensuring timely updates and adherence to new BSP and NPC guidelines.
  3. Data Privacy & Protection (DPO Role)

    • Serve as the organization's Data Protection Officer (DPO), ensuring compliance with the National Privacy Commission (NPC) guidelines.

    • Conduct Privacy Impact Assessments (PIA) to identify and mitigate data protection risks.

    • Implement Data Loss Prevention (DLP), encryption, and secure data handling practices.

    • Develop and enforce data retention, access control, and user privacy policies across digital banking and microfinance platforms.

    • Lead privacy training and awareness programs for employees and stakeholders.
  4. Cybersecurity Operations & Risk Management

    • Oversee Security Operations (SOC) activities, ensuring required monitoring, detection, and response to cyber threats.

    • Deploy Endpoint Detection & Response (EDR), Security Information and Event Management (SIEM), and Intrusion Prevention Systems (IPS/IDS) for proactive threat mitigation.

    • Implement penetration testing, vulnerability assessments, and cybersecurity awareness programs.

    • Ensure robust Incident Response, Cyber Threat Intelligence (CTI), and Fraud Prevention mechanisms are in place.

    • Drive AI-based security automation and threat hunting strategies.
  5. Digital Banking & Cloud Security

    • Secure mobile banking, digital payments, and API-based financial services by enforcing strong authentication, fraud detection, and secure coding practices.

    • Oversee cloud security architecture (AWS, Azure, GCP), ensuring compliance with BSP Circular 1122 on Cloud Computing and financial industry best practices.

    • Implement blockchain, tokenization, and digital identity verification to enhance security for financial transactions.
  6. Business Continuity & Incident Response

    • Develop and maintain the Cybersecurity Incident Response Plan (CSIRP), Business Continuity Plan (BCP), and Disaster Recovery Plan (DRP).

    • Conduct cyber drills, tabletop exercises, and simulated attack scenarios to test the organization's resilience.

    • Establish forensic investigation procedures to analyze security breaches and prevent recurrence.
  7. Team Leadership & Vendor Management

    • Lead and mentor the Information Security, Data Privacy, and GRC teams, ensuring continuous improvement and upskilling.

    • Manage security vendors, negotiate contracts, and oversee SLAs to ensure compliance and service quality.

    • Optimize IT security and compliance budgets while balancing risk, performance, and regulatory demands.

Key Qualifications & Skills:

• Bachelor's or Master's degree in Cybersecurity, Information Technology, Computer Science, or related field.

• 15+ years of experience in Information Security, Risk Management, Compliance, or IT Governance, with 5+ years of which in a leadership role.

• Strong expertise in BSP cybersecurity regulations, the Philippines Data Privacy Act (RA 10173), PCI DSS, ISO 27001, COBIT, SOC2 and NIST frameworks.

• Experience securing core banking systems (CBS), digital wallets, mobile banking, and cloud-based financial platforms.

• Knowledge of financial fraud prevention, AI-driven security automation, and endpoint security solutions.

• Excellent stakeholder management skills, with the ability to interact with BSP, NPC, AMLC, and executive leadership teams.

Hands-On Experience or Certifications in the following:

• CISSP (Certified Information Systems Security Professional)

• CISM (Certified Information Security Manager)

• CRISC (Certified in Risk and Information Systems Control)

• CISA (Certified Information Systems Auditor)

• ISO 27001 Lead Implementer or Lead Auditor

• PCIP / QSA (PCI DSS Compliance)

• AWS/Azure Security Certifications

• CDPSE (Certified Data Privacy Solutions Engineer) or IAPP Privacy Certifications

#J-18808-Ljbffr

  • Manila, National Capital Region, Philippines PJ Lhuillier Group of Companies Full time

    The position is primarily responsible for overseeing the implementation of information security, cyber-security, and IT risk management programs of the bank. The position is also responsible for enforcing information security policies and procedures that protect the bank from any threats and security breaches.Duties and Responsibilities:Supports the...


  • Manila, National Capital Region, Philippines Total Information Management Corp. Full time

    We are seeking an experienced SOC Analyst to join our team at Total Information Management Corp. This is a challenging and rewarding role that requires strong analytical and problem-solving skills.Responsibilities:Analyze security logs and event data to identify potential security incidents.Collaborate with IT teams to resolve security-related issues.Stay...


  • Manila, National Capital Region, Philippines Planit Philippines Corporation Full time

    Job SummaryWe are hiring a Cybersecurity Specialist to assist the Information Security Head in supporting information security operations and compliance initiatives. The primary focus of this role is to help with the implementation, maintenance, and improvement of security frameworks, policies, risk assessments, and compliance activities.This role is highly...


  • Manila, National Capital Region, Philippines PJ Lhuillier Group of Companies Full time

    About the Role:PJ Lhuillier Group of Companies seeks an experienced Information Security Officer to lead the development and implementation of comprehensive information security strategies. The ideal candidate will possess strong technical expertise in information security and risk management.Key Responsibilities:Formulate and implement information security...

  • IT Security Head

    18 hours ago


    Manila, National Capital Region, Philippines PETNET, INC. Full time

    This position shall ensure the effective management and administration of the company's security infrastructure and the protection of the company's computer network, systems, and information assets in alignment with security standards. He/She will also be responsible for implementing and managing all security defense-in-depth applications and documenting...


  • Manila, National Capital Region, Philippines NEXUS TECHNOLOGIES INCORPORATED Full time

    The Information Security Officer will help the organization with its compliance initiative including but not limited to Information Security Management System (ISO27001), Business Continuity Management System (ISO23001), CREST, SOC 2 and other requirements including implementation and management of program. The Information Security Officer will assist the...


  • Manila, National Capital Region, Philippines Planit Philippines Corporation Full time

    Planit are world leaders in application testing and quality engineering. We provide solutions that support organisations to deliver high quality systems, applications, and IT architecture. Planit is now a proud NRI company and part of a global movement to deliver a sustainable and secure future through better Information Technology exchanges.Our team offer...


  • Manila, National Capital Region, Philippines Cambridge University Press & Assessment | Manila Full time

    Information Security Lead**About the Role**The Information Security Lead will play a vital role in ensuring the highest standards of protection for our organisation. You will oversee the daily activities of our Security Operations Center (SOC) and lead the implementation of strategic initiatives led by the Head of Security Operations.**Responsibilities***...


  • Manila, National Capital Region, Philippines Asialink Finance Corporation Full time

    About the RoleWe are seeking an experienced Information Security Consultant to join our team at Asialink Finance Corporation. In this role, you will be responsible for assisting in the IT audit annual planning, data collection, and updating of necessary information requirements.Key Responsibilities:Assist in the preparation/documentation of internal audit...


  • Manila, National Capital Region, Philippines MBM Information Technology Consulting Full time

    About the RoleThe ideal candidate will have deep technical knowledge, strong communication skills, and a proven ability to translate complex security concepts into actionable strategies. They will be responsible for conducting risk assessments, developing security solutions, and providing expert advice to clients.ResponsibilitiesAdvise clients on best...


  • Manila, National Capital Region, Philippines CMC Energy and Infrastructure Asia, Inc. Full time

    Cybersecurity Strategy:The Head of Cybersecurity will lead the development and implementation of the organization's cybersecurity strategy, ensuring the protection of critical assets and data.Key Performance Indicators (KPIs):Evaluate and improve the effectiveness of security controls.Monitor and report on security-related metrics.


  • Manila, National Capital Region, Philippines Manpower Philippines Full time

    Join Manpower Philippines as we seek an exceptional professional to fill the role of Head of Application Security Engineering. In this position, you will be responsible for leading our cybersecurity efforts and ensuring the development of secure software practices across the organization.


  • Manila, National Capital Region, Philippines Lazada Full time

    Lazada is seeking an Information Security Lead to join our team and oversee our information security program.About the Role:The successful candidate will be responsible for ensuring that our information security program is robust and effective, including conducting regular risk assessments and developing mitigation strategies.Strong communication and...


  • Manila, National Capital Region, Philippines Philippine Clearing House Corporation Full time

    PCHC is a dynamic organization that requires a skilled Information Security Assistant to support its risk management initiatives.The Role:As an Information Security Assistant, you will play a key role in supporting the development and implementation of comprehensive information security policies and procedures. You will work closely with the Information...


  • Manila, National Capital Region, Philippines Viventis Search Asia Full time

    About the JobViventis Search Asia is a leading recruitment firm that specializes in placing top talent in the financial sector. We are currently seeking a highly experienced Information Security Strategist to join our client's team.The ideal candidate will have a proven track record in developing and implementing information security strategies that align...


  • Manila, National Capital Region, Philippines Private Advertiser Full time

    Job OverviewThe Private Advertiser is seeking an experienced Information Security Manager to lead the development and implementation of comprehensive information security policies, standards, and procedures. As a key member of the team, you will be responsible for overseeing and implementing security measures to protect our organization's computer systems,...


  • Manila, National Capital Region, Philippines Private Advertiser Full time

    As the Information Security Manager, you will be responsible for overseeing and implementing security measures to protect our organization's computer systems, networks, and data. You will play a crucial role in developing, implementing, and monitoring security policies and procedures, conducting security assessments, and responding to security incidents....


  • Manila, National Capital Region, Philippines Manulife Full time

    We are looking for an experienced Information Security Specialist to join our team. The successful candidate will have a strong background in technology and security, with experience in performing third-party information security risk assessments.The role involves reviewing independent audit reports and drafting final output/deliverables, as well as...


  • Manila, National Capital Region, Philippines RIMES Technologies Limited Full time

    RIMES Technologies Limited provides data management solutions to the global investment community. We deliver cutting-edge information intelligence that empowers our clients to make informed investment decisions.The role of GRC Analyst is designed to support our Cyber Security team in driving maturity in our information security compliance initiatives. This...


  • Manila, National Capital Region, Philippines Blaseek Full time

    Position Overview:As a Security Architect, you will engage across various domains within information security, focusing on:Evaluating and auditing existing security controls and solutions.Designing and implementing new security measures.Providing expert counsel within the department and beyond.Assisting in the design and optimization of our SIEM/MDR...