Information Security Lead

2 weeks ago


Quezon City, National Capital Region, Philippines Asticom Technology Inc. Full time

Job Roles and Responsibilities

I. Strategic Leadership and Governance:

  • Develop and Execute Security Strategy:
    Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.
  • Policy and Procedure Development:
    Create, maintain, and enforce comprehensive information security policies, procedures, and standards (e.g., access control, data handling, incident response, remote work security) that adhere to industry best practices and client SLAs.
  • Risk Management:
  • Conduct regular risk assessments to identify, analyze, and prioritize security vulnerabilities and threats across systems, networks, applications, and processes.
  • Develop and implement mitigation plans to address identified risks, recommending appropriate security controls and technologies.
  • Compliance and Regulatory Adherence:
  • Ensure the BPO's compliance with relevant national and international data protection regulations (e.g., GDPR, HIPAA, PCI-DSS, local Philippine privacy laws).
  • Oversee internal and external audits (e.g., ISO 27001, NIST) and ensure all security measures align with established frameworks.
  • Prepare detailed reports for management and clients on compliance status and audit findings.
  • Budget Management:
    Contribute to the development and management of the information security budget, ensuring optimal allocation of resources for security tools, training, and personnel.

II. Operational Security Management:

  • Incident Response and Management:
  • Develop and lead the organization's incident response plan (IRP), including detection, containment, eradication, recovery, and post-incident analysis.
  • Coordinate investigations into security breaches or incidents, performing root cause analysis and implementing corrective and preventive actions.
  • Communicate incident status and impact to stakeholders, including senior management, legal, compliance, and affected clients.
  • Conduct tabletop exercises and simulation drills to test the effectiveness of the IRP.
  • Vulnerability Management:
  • Lead regular vulnerability assessments and penetration testing activities on infrastructure, applications, and networks.
  • Oversee the patching and remediation of identified vulnerabilities.
  • Analyze threat reports and security advisories to proactively protect against new threats.
  • Security Monitoring and Operations:
  • Oversee the continuous monitoring of IT systems and networks for suspicious activities, trends, and patterns using SIEM (Security Information and Event Management) tools.
  • Ensure the effective operation and maintenance of security tools such as firewalls, IDS/IPS, antivirus, and data loss prevention (DLP) systems.
  • Access Control Management:
    Oversee the implementation and enforcement of robust access control policies, ensuring only authorized personnel have access to sensitive data and systems, especially crucial in multi-client BPO environments.
  • Data Protection and Privacy:
    Implement measures to protect the confidentiality, integrity, and availability of all data, including data encryption, secure data storage, and data backup and disaster recovery plans.
  • Vendor Security Management:
  • Assess and ensure the security posture of third-party vendors and partners.
  • Conduct risk assessments relevant to each vendor and collaborate with teams to address any identified risks.
  • Ensure vendor compliance with the organization's security and compliance obligations.

III. Team Leadership and Development:

  • Lead and Mentor:
    Guide, mentor, and manage a team of security professionals, fostering a security-first mindset across the organization.
  • Security Awareness and Training:
    Develop and deliver comprehensive security awareness and training programs for all employees, ensuring they understand their roles in maintaining security and recognizing potential threats (e.g., phishing).
  • Collaboration:
    Work closely with IT, operations, legal, HR, and client-facing teams to integrate security into all aspects of the organization's operations.

IV. BPO-Specific Considerations:

  • Client Relationship Management:
    Often serves as a key point of contact for clients regarding information security matters, including security audits, contractual compliance, and addressing client-specific security concerns.
  • Multi-Tenancy Security:
    Understand and manage the complexities of securing data for multiple clients within a shared infrastructure, ensuring strict segregation and adherence to individual client requirements.
  • Service Level Agreements (SLAs):
    Ensure that information security practices meet or exceed the security clauses defined in client SLAs.
  • Global Security Standards:
    In organizations serving international clients, the Infosec Lead must be well-versed in a wide range of global security standards and regulations.

Job Qualifications:

1. Stop the Bleeding: Fixing Our Security Weaknesses

An
InfoSec Lead
is like hiring a master craftsman for our vault. They'll come in and:

  • Rewrite the blueprints:
    They'll create clear, up-to-date security rules that everyone understands and follows.
  • Reinforce the walls:
    They'll put in place the right technical systems and tools to automatically block unauthorized access and prevent data from leaving our control.
  • Supervise the guards:
    They'll lead and train our existing IT team to be more vigilant and efficient in spotting and stopping threats. They'll also tell us exactly where we need more hands-on-deck if necessary.

2. Protecting Our Reputation and Keeping Clients Happy

In the BPO world, trust is everything. Our clients choose us because they believe we can handle their sensitive data safely. Every security incident, no matter how small, chips away at that trust.

An
InfoSec Lead
will actively:

  • Build client confidence:
    They'll be our expert face when clients ask about our security. They'll assure them we're serious about protecting their data and demonstrate how we meet global privacy standards (like GDPR). This is crucial for keeping our current clients and winning new ones.
  • Keep us out of trouble:
    They'll make sure we comply with all the complex data privacy laws, both locally in the Philippines and internationally. This prevents costly fines, legal battles, and damaging headlines.


  • Quezon City, National Capital Region, Philippines Manulife Full time ₱1,500,000 - ₱3,000,000 per year

    As a Business Unit Security Officer (BUSO) within the Information Risk Management team under Global Wealth Asset Management (GWAM) Information Technology First Line of Defense, you will play a critical role in safeguarding the organization's IT environment. This role involves conducting risk assessments for new and existing applications, infrastructure, and...


  • Quezon City, National Capital Region, Philippines Manulife Full time ₱250,000 - ₱500,000 per year

    We're seeking an Information Security Analyst to join our Group Functions IT – Information Security Management and Business Resilience (GFT ISM & BR) team at MBPS. In this role, you will play a key part in delivering BUSO services and driving continuous security monitoring across the organization. Your responsibilities will include managing security...


  • Quezon City, National Capital Region, Philippines Manulife Full time ₱1,500,000 - ₱3,000,000 per year

    TheInformation Security Managerevaluates technology environments through control testing, compliance assessments, identifies key gaps and recommends actions for remediation. Partners with other teams for cybersecurity controls assessment and tests effectiveness of cybersecurity controls ensuring that systems and processes meet industry standards and...


  • Mandaluyong City, National Capital Region, Philippines Data Analytics Ventures, Inc. Full time ₱1,200,000 - ₱2,400,000 per year

    The Information Security Manager is responsible for safeguarding the organization's information assets by implementing, managing, and overseeing the company's security policies, protocols, and procedures. This role involves identifying and mitigating security risks, ensuring compliance with industry standards, and leading efforts to protect sensitive data...

  • Security Lead

    1 week ago


    Quezon City, National Capital Region, Philippines Miescor Builders Inc. Full time ₱900,000 - ₱1,200,000 per year

    Job SummaryPerforms under the supervision of Safety Health & Environment Officer (SHE) Department Head. Serves as Security Lead of the company.The Security Lead monitors the compliance of security providers on security standards and other security requirements of MIESCOR BUILDERS INC. security end-users. Assists Head, Security in ensuring compliance with...


  • Quezon City, National Capital Region, Philippines Manulife Full time ₱1,200,000 - ₱2,400,000 per year

    We're looking for an Information Security Manager, Identity Access Management (IAM) Consultant to join our Group Functions IT Information Security and Business Resilience Team at MBPS. In this role, you are expected to apply identity access security risk knowledge and expertise to assist with IT information security First Line of Defense activities to help...


  • Quezon City, National Capital Region, Philippines Manulife Full time ₱1,200,000 - ₱2,400,000 per year

    We're looking for an Information Risk Manager (RCSA) to join our Group Functions IT Information Security and Business Resilience Team at MBPS. In this role, you will be responsible for planning, executing, leading, and completing Risk and Control Self-Assessments (RCSA) and continuous monitoring activities. This includes RCSA, Integrated RCSA for Critical...


  • Makati City, National Capital Region, Philippines PSBank Official Full time ₱1,200,000 - ₱2,400,000 per year

    Job PurposeResponsible for coordinating walkthroughs and obtaining supporting documents from relevant departments, necessary to assist both internal and external auditors/reviewers. The Information Security Compliance Officer shall, keep track of ISG related outstanding issues to support the Manager in ensuring timely resolution. Information Security...


  • Makati City, National Capital Region, Philippines 1881b99f-5d2c-4da9-ac26-25cafe743eb4 Full time ₱1,500,000 - ₱3,000,000 per year

    About the RoleAs an Information Security Risk Manager you are responsible for helping ensure that SBC's Information Security policies and procedures align with all relevant regulation and company values. S/He helps to facilitate the wider team's understanding of their compliance responsibilities under the relevant regulations and company values and how to...


  • Makati City, National Capital Region, Philippines Smart Communications, Inc. Full time ₱1,200,000 - ₱3,600,000 per year

    EducationBachelor's Degree of Information Technology or any related IT course.QualificationsQualificationsProven experience in designing, implementing, and maintaining scalable IAM solutions and platformsExpertise in developing and enforcing access control policies and proceduresHands-on experience with implementing automated workflows for identity and...