Information Security Lead

1 day ago


Quezon City, National Capital Region, Philippines Asticom Technology Inc Full time $90,000 - $120,000 per year

Job Roles and Responsibilities:

I. Strategic Leadership and Governance:

  • Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.

  • Policy and Procedure Development: Create, maintain, and enforce comprehensive information security policies, procedures, and standards (e.g., access control, data handling, incident response, remote work security) that adhere to industry best practices and client SLAs.

  • Risk Management:

    • Conduct regular risk assessments to identify, analyze, and prioritize security vulnerabilities and threats across systems, networks, applications, and processes.

    • Develop and implement mitigation plans to address identified risks, recommending appropriate security controls and technologies.

  • Compliance and Regulatory Adherence:

    • Ensure the BPO's compliance with relevant national and international data protection regulations (e.g., GDPR, HIPAA, PCI-DSS, local Philippine privacy laws).

    • Oversee internal and external audits (e.g., ISO 27001, NIST) and ensure all security measures align with established frameworks.

    • Prepare detailed reports for management and clients on compliance status and audit findings.

  • Budget Management: Contribute to the development and management of the information security budget, ensuring optimal allocation of resources for security tools, training, and personnel.

II. Operational Security Management:

  • Incident Response and Management:

    • Develop and lead the organization's incident response plan (IRP), including detection, containment, eradication, recovery, and post-incident analysis.

    • Coordinate investigations into security breaches or incidents, performing root cause analysis and implementing corrective and preventive actions.

    • Communicate incident status and impact to stakeholders, including senior management, legal, compliance, and affected clients.

    • Conduct tabletop exercises and simulation drills to test the effectiveness of the IRP.

  • Vulnerability Management:

    • Lead regular vulnerability assessments and penetration testing activities on infrastructure, applications, and networks.

    • Oversee the patching and remediation of identified vulnerabilities.

    • Analyze threat reports and security advisories to proactively protect against new threats.

  • Security Monitoring and Operations:

    • Oversee the continuous monitoring of IT systems and networks for suspicious activities, trends, and patterns using SIEM (Security Information and Event Management) tools.

    • Ensure the effective operation and maintenance of security tools such as firewalls, IDS/IPS, antivirus, and data loss prevention (DLP) systems.

  • Access Control Management: Oversee the implementation and enforcement of robust access control policies, ensuring only authorized personnel have access to sensitive data and systems, especially crucial in multi-client BPO environments.

  • Data Protection and Privacy: Implement measures to protect the confidentiality, integrity, and availability of all data, including data encryption, secure data storage, and data backup and disaster recovery plans.

  • Vendor Security Management:

    • Assess and ensure the security posture of third-party vendors and partners.

    • Conduct risk assessments relevant to each vendor and collaborate with teams to address any identified risks.

    • Ensure vendor compliance with the organization's security and compliance obligations.

III. Team Leadership and Development:

  • Lead and Mentor: Guide, mentor, and manage a team of security professionals, fostering a security-first mindset across the organization.

  • Security Awareness and Training: Develop and deliver comprehensive security awareness and training programs for all employees, ensuring they understand their roles in maintaining security and recognizing potential threats (e.g., phishing).

  • Collaboration: Work closely with IT, operations, legal, HR, and client-facing teams to integrate security into all aspects of the organization's operations.

IV. BPO-Specific Considerations:

  • Client Relationship Management: Often serves as a key point of contact for clients regarding information security matters, including security audits, contractual compliance, and addressing client-specific security concerns.

  • Multi-Tenancy Security: Understand and manage the complexities of securing data for multiple clients within a shared infrastructure, ensuring strict segregation and adherence to individual client requirements.

  • Service Level Agreements (SLAs): Ensure that information security practices meet or exceed the security clauses defined in client SLAs.

  • Global Security Standards: In organizations serving international clients, the Infosec Lead must be well-versed in a wide range of global security standards and regulations.

Job Qualifications:

1. Stop the Bleeding: Fixing Our Security Weaknesses

An InfoSec Lead is like hiring a master craftsman for our vault. They'll come in and:

  • Rewrite the blueprints: They'll create clear, up-to-date security rules that everyone understands and follows.

  • Reinforce the walls: They'll put in place the right technical systems and tools to automatically block unauthorized access and prevent data from leaving our control.

  • Supervise the guards: They'll lead and train our existing IT team to be more vigilant and efficient in spotting and stopping threats. They'll also tell us exactly where we need more hands-on-deck if necessary.

2. Protecting Our Reputation and Keeping Clients Happy

In the BPO world, trust is everything. Our clients choose us because they believe we can handle their sensitive data safely. Every security incident, no matter how small, chips away at that trust.

An InfoSec Lead will actively:

  • Build client confidence: They'll be our expert face when clients ask about our security. They'll assure them we're serious about protecting their data and demonstrate how we meet global privacy standards (like GDPR). This is crucial for keeping our current clients and winning new ones.

  • Keep us out of trouble: They'll make sure we comply with all the complex data privacy laws, both locally in the Philippines and internationally. This prevents costly fines, legal battles, and damaging headlines.



  • Quezon City, National Capital Region, Philippines Asticom Technology Inc. Full time $90,000 - $120,000 per year

    Job Roles and Responsibilities:I. Strategic Leadership and Governance:Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.Policy and Procedure Development: Create, maintain, and...


  • Quezon City, National Capital Region, Philippines beBeeSecurity Full time ₱80,000 - ₱120,000

    Information Security StrategistWe are seeking a seasoned Information Security Strategist to lead our security initiatives. The ideal candidate will possess in-depth knowledge of information security principles, practices, and industry standards.The successful applicant will develop, implement, and maintain comprehensive security strategies aligned with...


  • Makati City, National Capital Region, Philippines Michael Page Full time

    Step into a high-impact leadership role. Drive enterprise-wide security initiative and influence key stakeholders. About Our Client This organization serves as the data science and AI arm of a diversified business group, focused on enabling data-driven transformation across key industries such as energy, finance, and infrastructure. Its mandate is to...


  • Quezon City, National Capital Region, Philippines Bridge Technologies and Solutions(WMBE) Full time

    Information Security Officer, Global Security TeamJoin to apply for the Information Security Officer, Global Security Team role at Bridge Technologies and Solutions(WMBE)OverviewThe Associate will assist in generating reports and automating data integration for vulnerability assessments and penetration testing activities. The candidate must possess hands-on...


  • Mandaluyong City, National Capital Region, Philippines Unilab, Inc. Full time $80,000 - $120,000 per year

    It is the spirit of Bayanihan that drives us to continue our legacy of excellence and commitment to care. As an organization, we achieve our successes through good, honest, and persevering hard work - TOGETHER. It is in this way in which our company was built; we progressed as the country's leading Pharmaceutical company, not by sheer luck, but by pure...


  • Makati City, National Capital Region, Philippines beBeeSecurity Full time ₱900,000 - ₱1,200,000

    Job DescriptionAs a seasoned security professional, you will be responsible for developing and enforcing comprehensive security plans and standards to ensure the integrity of our networks and systems. This includes implementing best practices, preparing strategic security initiatives, and providing expert guidance on enterprise security projects.Key...


  • Quezon City, National Capital Region, Philippines Manulife Full time $60,000 - $80,000 per year

    We're looking for anInformation Security Analyst (Access Provisioning)to join our ETS Control and Governance team at MBPS. In this role, you are expected to define and maintain a standard access model for cloud resources, review and approve access requests every day within the committed SLA. You will enhance existing automation to make the review and...


  • Makati City, National Capital Region, Philippines First Metro Investment Corporation Full time ₱900,000 - ₱1,200,000 per year

    Job Description Company Description First Metro Investment Corporation, one of the largest investment banks in the Philippines, plays a vital role in capital markets and economic growth. With a 56-year history, it offers a range of services including debt and equity underwriting, financial advisory, and asset management. The company aims to be a leading...


  • Mandaluyong City, National Capital Region, Philippines beBeeRisk Full time ₱900,000 - ₱1,200,000

    Job Summary:We are seeking a seasoned professional to lead our risk assessment initiatives. As Talent Acquisition Officer @ Bank of Commerce - an affiliate of San Miguel Corporation, you will oversee employees, consultants, subsidiaries and vendor's compliance with ISPP regarding the security of the Bank's information assets.You will monitor the adequacy and...


  • Mandaluyong City, National Capital Region, Philippines Maya Bank Full time $90,000 - $120,000 per year

    Maya Mandaluyong, National Capital Region, PhilippinesWE ARE HIRING. Follow Maya to know more. CORE PROFILEThe Information Security Governance, Risk and Compliance (GRC) Manager is a people manager role within the Information Security Governance and Operations department. The scope includes all aspects of Governance, Risk Management and Compliance as it...