
Information Security Lead
1 day ago
Job Roles and Responsibilities:
I. Strategic Leadership and Governance:
-
Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.
-
Policy and Procedure Development: Create, maintain, and enforce comprehensive information security policies, procedures, and standards (e.g., access control, data handling, incident response, remote work security) that adhere to industry best practices and client SLAs.
-
Risk Management:
-
Conduct regular risk assessments to identify, analyze, and prioritize security vulnerabilities and threats across systems, networks, applications, and processes.
-
Develop and implement mitigation plans to address identified risks, recommending appropriate security controls and technologies.
-
-
Compliance and Regulatory Adherence:
-
Ensure the BPO's compliance with relevant national and international data protection regulations (e.g., GDPR, HIPAA, PCI-DSS, local Philippine privacy laws).
-
Oversee internal and external audits (e.g., ISO 27001, NIST) and ensure all security measures align with established frameworks.
-
Prepare detailed reports for management and clients on compliance status and audit findings.
-
-
Budget Management: Contribute to the development and management of the information security budget, ensuring optimal allocation of resources for security tools, training, and personnel.
II. Operational Security Management:
-
Incident Response and Management:
-
Develop and lead the organization's incident response plan (IRP), including detection, containment, eradication, recovery, and post-incident analysis.
-
Coordinate investigations into security breaches or incidents, performing root cause analysis and implementing corrective and preventive actions.
-
Communicate incident status and impact to stakeholders, including senior management, legal, compliance, and affected clients.
-
Conduct tabletop exercises and simulation drills to test the effectiveness of the IRP.
-
-
Vulnerability Management:
-
Lead regular vulnerability assessments and penetration testing activities on infrastructure, applications, and networks.
-
Oversee the patching and remediation of identified vulnerabilities.
-
Analyze threat reports and security advisories to proactively protect against new threats.
-
-
Security Monitoring and Operations:
-
Oversee the continuous monitoring of IT systems and networks for suspicious activities, trends, and patterns using SIEM (Security Information and Event Management) tools.
-
Ensure the effective operation and maintenance of security tools such as firewalls, IDS/IPS, antivirus, and data loss prevention (DLP) systems.
-
-
Access Control Management: Oversee the implementation and enforcement of robust access control policies, ensuring only authorized personnel have access to sensitive data and systems, especially crucial in multi-client BPO environments.
-
Data Protection and Privacy: Implement measures to protect the confidentiality, integrity, and availability of all data, including data encryption, secure data storage, and data backup and disaster recovery plans.
-
Vendor Security Management:
-
Assess and ensure the security posture of third-party vendors and partners.
-
Conduct risk assessments relevant to each vendor and collaborate with teams to address any identified risks.
-
Ensure vendor compliance with the organization's security and compliance obligations.
-
III. Team Leadership and Development:
-
Lead and Mentor: Guide, mentor, and manage a team of security professionals, fostering a security-first mindset across the organization.
-
Security Awareness and Training: Develop and deliver comprehensive security awareness and training programs for all employees, ensuring they understand their roles in maintaining security and recognizing potential threats (e.g., phishing).
-
Collaboration: Work closely with IT, operations, legal, HR, and client-facing teams to integrate security into all aspects of the organization's operations.
IV. BPO-Specific Considerations:
-
Client Relationship Management: Often serves as a key point of contact for clients regarding information security matters, including security audits, contractual compliance, and addressing client-specific security concerns.
-
Multi-Tenancy Security: Understand and manage the complexities of securing data for multiple clients within a shared infrastructure, ensuring strict segregation and adherence to individual client requirements.
-
Service Level Agreements (SLAs): Ensure that information security practices meet or exceed the security clauses defined in client SLAs.
-
Global Security Standards: In organizations serving international clients, the Infosec Lead must be well-versed in a wide range of global security standards and regulations.
Job Qualifications:
1. Stop the Bleeding: Fixing Our Security WeaknessesAn InfoSec Lead is like hiring a master craftsman for our vault. They'll come in and:
-
Rewrite the blueprints: They'll create clear, up-to-date security rules that everyone understands and follows.
-
Reinforce the walls: They'll put in place the right technical systems and tools to automatically block unauthorized access and prevent data from leaving our control.
-
Supervise the guards: They'll lead and train our existing IT team to be more vigilant and efficient in spotting and stopping threats. They'll also tell us exactly where we need more hands-on-deck if necessary.
In the BPO world, trust is everything. Our clients choose us because they believe we can handle their sensitive data safely. Every security incident, no matter how small, chips away at that trust.
An InfoSec Lead will actively:
-
Build client confidence: They'll be our expert face when clients ask about our security. They'll assure them we're serious about protecting their data and demonstrate how we meet global privacy standards (like GDPR). This is crucial for keeping our current clients and winning new ones.
-
Keep us out of trouble: They'll make sure we comply with all the complex data privacy laws, both locally in the Philippines and internationally. This prevents costly fines, legal battles, and damaging headlines.
-
Information Security Lead
1 day ago
Quezon City, National Capital Region, Philippines Asticom Technology Inc. Full time $90,000 - $120,000 per yearJob Roles and Responsibilities:I. Strategic Leadership and Governance:Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.Policy and Procedure Development: Create, maintain, and...
-
Chief Information Security Officer
5 days ago
Quezon City, National Capital Region, Philippines beBeeSecurity Full time ₱80,000 - ₱120,000Information Security StrategistWe are seeking a seasoned Information Security Strategist to lead our security initiatives. The ideal candidate will possess in-depth knowledge of information security principles, practices, and industry standards.The successful applicant will develop, implement, and maintain comprehensive security strategies aligned with...
-
Information Security Manager
4 days ago
Makati City, National Capital Region, Philippines Michael Page Full timeStep into a high-impact leadership role. Drive enterprise-wide security initiative and influence key stakeholders. About Our Client This organization serves as the data science and AI arm of a diversified business group, focused on enabling data-driven transformation across key industries such as energy, finance, and infrastructure. Its mandate is to...
-
Quezon City, National Capital Region, Philippines Bridge Technologies and Solutions(WMBE) Full timeInformation Security Officer, Global Security TeamJoin to apply for the Information Security Officer, Global Security Team role at Bridge Technologies and Solutions(WMBE)OverviewThe Associate will assist in generating reports and automating data integration for vulnerability assessments and penetration testing activities. The candidate must possess hands-on...
-
information security specialist
1 day ago
Mandaluyong City, National Capital Region, Philippines Unilab, Inc. Full time $80,000 - $120,000 per yearIt is the spirit of Bayanihan that drives us to continue our legacy of excellence and commitment to care. As an organization, we achieve our successes through good, honest, and persevering hard work - TOGETHER. It is in this way in which our company was built; we progressed as the country's leading Pharmaceutical company, not by sheer luck, but by pure...
-
Information Security Strategist
5 days ago
Makati City, National Capital Region, Philippines beBeeSecurity Full time ₱900,000 - ₱1,200,000Job DescriptionAs a seasoned security professional, you will be responsible for developing and enforcing comprehensive security plans and standards to ensure the integrity of our networks and systems. This includes implementing best practices, preparing strategic security initiatives, and providing expert guidance on enterprise security projects.Key...
-
Information Security Analyst
24 hours ago
Quezon City, National Capital Region, Philippines Manulife Full time $60,000 - $80,000 per yearWe're looking for anInformation Security Analyst (Access Provisioning)to join our ETS Control and Governance team at MBPS. In this role, you are expected to define and maintain a standard access model for cloud resources, review and approve access requests every day within the committed SLA. You will enhance existing automation to make the review and...
-
Information Security Manager
1 day ago
Makati City, National Capital Region, Philippines First Metro Investment Corporation Full time ₱900,000 - ₱1,200,000 per yearJob Description Company Description First Metro Investment Corporation, one of the largest investment banks in the Philippines, plays a vital role in capital markets and economic growth. With a 56-year history, it offers a range of services including debt and equity underwriting, financial advisory, and asset management. The company aims to be a leading...
-
Information Security Manager
2 days ago
Mandaluyong City, National Capital Region, Philippines beBeeRisk Full time ₱900,000 - ₱1,200,000Job Summary:We are seeking a seasoned professional to lead our risk assessment initiatives. As Talent Acquisition Officer @ Bank of Commerce - an affiliate of San Miguel Corporation, you will oversee employees, consultants, subsidiaries and vendor's compliance with ISPP regarding the security of the Bank's information assets.You will monitor the adequacy and...
-
Information Security GRC Manager
1 day ago
Mandaluyong City, National Capital Region, Philippines Maya Bank Full time $90,000 - $120,000 per yearMaya Mandaluyong, National Capital Region, PhilippinesWE ARE HIRING. Follow Maya to know more. CORE PROFILEThe Information Security Governance, Risk and Compliance (GRC) Manager is a people manager role within the Information Security Governance and Operations department. The scope includes all aspects of Governance, Risk Management and Compliance as it...