Security and Compliance Manager
2 weeks ago
Elevate is recruiting an Security and Compliance Manager to join our high-performing team.
The Security and Compliance Manager is a dedicated Governance, Risk, and Compliance (GRC) role responsible for maintaining the organization's security posture through the development, execution, and continuous improvement of security policies, audit programs, and risk management processes. This role is essential for achieving and maintaining key regulatory and security certifications, such as ISO 27001, SOC2 and HIPAA and addressing customer information requests.
Specifically, the Security and Compliance Manager will
Compliance and Certification Management
- ISO 27001 Program Lead: Own and manage the Information Security Management System (ISMS) in accordance with the ISO 27001 standard. This includes coordinating all stages of internal and external audits.
- Audit Execution: Plan, lead, and report on internal security and compliance audits to identify control weaknesses and ensure audit readiness for external assessments (e.g., ISO 27001, SOC 2, HIPAA).
- Remediation Tracking: Manage the closure of findings (Non-Conformities) identified during audits, working with engineering and operations teams to implement corrective actions.
Governance and Policy
- Policy Management: Develop, write, and maintain a comprehensive suite of security policies, standards, and procedures to enforce compliance across the organization.
- Training & Awareness: Create and deliver security awareness and compliance training programs to ensure all employees understand their security responsibilities.
- Contract Review: Assist Legal and Procurement teams by reviewing security clauses in vendor contracts and customer agreements to ensure alignment with internal policies.
- Customer Facing Responsibilities. Respond to customer's request for information in a clear manner that reflects Elevate's security and privacy practices accurately.
Risk Management
- Risk Assessment: Lead regular, formal risk assessment activities, maintaining the risk register, and tracking residual risks to acceptable levels.
- Vulnerability Management Integration: Work with security operations to ensure identified vulnerabilities and threats are correctly incorporated into the organizational risk profile.
- Reporting: Prepare and present regular reports on the compliance status, key risks, and audit progress to senior leadership and management.
Experience
- 10+ years of experience in Information Security, with at least 5 years focused on GRC, compliance, and auditing.
- Has experience leading ISO 27001 certification and audit cycles for at least 5 years.
Skills for Success
- Excellent technical writing skills on policy and procedure development, and significant experience in customer facing communications.
Technical Skills
- Working knowledge of common security frameworks (e.g., SOC 2, NIST CSF).
- Working knowledge on SOC2 and HIPAA a plus
Qualifications
- Bachelor's degree in Computer science/ Information technology
- Mandatory: ISO 27001 Lead Auditor certification
Company Information
Elevate is a law company. We provide software and services for the intersection of business and law. Our legal, business, and technology professionals offer practical ways for global law departments and law firms to improve efficiency, quality, and business outcomes.
Our most recent achievements and distinctions include:
- Certified as one of the UK's Best Workplaces for Development 2025 by Great Place to Work
- Certified as a Great Place to Work 2025 in the US, UK, India, and Philippines
- For the tenth consecutive year, in 2025, Chambers & Partners named Elevate as a Top global services provider, ranking us as Band 1 (highest ranking) in all applicable categories (Contract Lifecycle Management, Litigation Services, and Flexible Legal Staffing) and as an Alternative Legal Service Provider in Asia-Pacific
- Newsweek named Elevate one of 'America's Greatest Workplaces in Professional Services' for 2025 and previously awarded it the highest rating in the 'America's Greatest Workplaces for Diversity' and 'America's Greatest Workplaces for 2024' lists
- For the fourth year in a row, Elevate's integrated law firm is designated as a top law firm in Commercial Litigation in the 2024 edition of Best Lawyers/US News & World Report Best Law Firms
- Elevate named a top ALSP in Asia by Thomson Reuters' Asian Legal Business in 2024
- Winner, Inc. 5000 Fastest-Growing Private Companies: 2022, 2021, 2020, 2018, 2017, and 2016
Learn more at
See more jobs at
Follow us on social media
Follow our Flexible Legal Resourcing Community
-
IT Security Risk and Compliance Analyst
2 weeks ago
Taguig, National Capital Region, Philippines Cushman & Wakefield Full time ₱1,200,000 - ₱2,400,000 per yearJob TitleIT Security Risk and Compliance AnalystJob Description SummaryJob SummaryThe IT Security Risk & Compliance Analyst is responsible for managing daily security operations, supporting cross-regional initiatives, and ensuring compliance with internal and external security standards. The role involves collaboration with various teams, including Legal and...
-
IT Security Risk and Compliance Analyst
2 weeks ago
Taguig, National Capital Region, Philippines Cushman & Wakefield Full time ₱1,200,000 - ₱2,400,000 per yearJob TitleIT Security Risk and Compliance AnalystJob Description SummaryJob SummaryThe IT Security Risk & Compliance Analyst is responsible for managing daily security operations, supporting cross-regional initiatives, and ensuring compliance with internal and external security standards. The role involves collaboration with various teams, including Legal and...
-
executive security manager
1 week ago
Taguig, National Capital Region, Philippines KKG DETECTIVE AGENCY INC. Full time ₱120,000 - ₱180,000 per yearWe're HiringExecutive Security Manager & Corporate Security Supervisor Location: Metro Manila Company: KKG Detective Agency, Inc.Join Our Leadership TeamWe're looking for experienced security professionals with strong backgrounds in: Corporate & Private Sector Security Risk Management & Compliance Multinational Operations Team Leadership & Crisis...
-
Cyber Security Manager
2 weeks ago
Taguig, National Capital Region, Philippines NCS Group Full time ₱1,500,000 - ₱2,500,000 per yearNCS is the leading technology services firm that operates across the Asia Pacific region in over 20 cities, providing consulting, digital services, technology solutions, and more. We believe in harnessing the power of technology to achieve extraordinary things, creating lasting value and impact for our communities, partners, and people.Our diverse workforce...
-
Security Admin
2 weeks ago
Taguig, National Capital Region, Philippines Tata Consultancy Services Full time ₱600,000 - ₱1,200,000 per yearMust-HaveConfigure and maintain native security components such as firewalls, network security groups, security lists, network access control lists (ACLs), and Web Application Firewalls (WAF).Configuration of native security solution.Design, deploy, and upgrade security solutions for hybrid cloud and on-premises environments, ensuring compliance with all...
-
Cloud Security
1 week ago
Taguig, National Capital Region, Philippines SnOw Talent Solutions Full time ₱1,500,000 - ₱2,500,000 per yearJob Title: Cloud Security SMEWork Location: BGC Taguig or MakatiShift: Night Shift/ Shifting - This role requires flexibilityWork Set-up: RTWO/ HybridSalary range: K BasicDesired experience: 6-10 yearsMust-Have:Must have worked on Cloud Security, for more than 5 years in managing and implementing below areas2. Identifying Cloud Security Threats,...
-
Cloud Security Engineer
1 week ago
Taguig, National Capital Region, Philippines Pan Asia Resources PH Inc. Full time ₱120,000 - ₱180,000 per yearKey ResponsibilitiesCloud & Hybrid Security Architecture● Design and Implement secure cloud architectures for hybrid environments (e.g.,AWS/Azure/GCP + On-Premises) ensuring consistent security policies and controlsacross all platforms.● Develop and enforce security standards for Red Hat OpenShift Container Platform(RHOCP) clusters, including the control...
-
Tech Security Engineer
2 weeks ago
Taguig, National Capital Region, Philippines Bershaw Consultancy Full time ₱1,500,000 - ₱2,500,000 per yearThe Technology Security Incident & Event Management (SIEM) Manager is responsible for managing the security incidents and events within an organization's technology infrastructure.This individual is responsible for monitoring, detecting, and responding to security incidents and events that could affect the confidentiality, integrity, or availability of the...
-
IT Governance and Security Lead
2 weeks ago
Taguig, National Capital Region, Philippines EastWest Ageas Insurance Full time ₱1,200,000 - ₱3,600,000 per yearOverall purpose, duties and responsibilities of the role:The IT Governance and Security Lead is responsible for establishing and maintaining a framework to ensure that IT investments support business objectives, deliver value, and mitigate risks. This role leads the development and implementation of governance policies, standards, and processes across IT...
-
Security Operations Engineer
1 week ago
Taguig, National Capital Region, Philippines WTW Full time ₱900,000 - ₱1,200,000 per yearDescriptionThe RoleAs a Security Operations Engineer, you will analyze software designs and implementations from a security perspective and identify and propose resolutions to security issues.You will include the appropriate security analysis, tooling and techniques to uncover InfoSec vulnerabilities, both static and dynamically, in our software...