Information Security Manager

1 week ago


Quezon City, National Capital Region, Philippines Manulife Full time

The
Information Security Manager
evaluates technology environments through control testing, compliance assessments, identifies key gaps and recommends actions for remediation. Partners with other teams for cybersecurity controls assessment and tests effectiveness of cybersecurity controls ensuring that systems and processes meet industry standards and regulatory requirements.

Position Responsibilities

  • Plans, conducts and manages cybersecurity and technology controls testing, compliance assessments including IT systems and processes for design and operating effectiveness.
  • Develops and maintains test procedures and plans for IT Security Controls, ensuring alignment with key objectives, industry standards and regulatory requirements.
  • Evaluates the organization's compliance with preferred cybersecurity frameworks.
  • Performs control testing, security assessments, and risk analysis on systems, applications, and network infrastructure to identify potential weaknesses and security gaps.
  • Analyzes test results, identifies security control deficiencies, and recommends solutions to resolve identified issues.
  • Partners with operations and IT teams to ensure that all IT security controls are adequately tested and implemented.
  • Tracks security issues/risks, prepares comprehensive reports outlining findings, recommendations and actionable insights to senior management and stakeholders.
  • Collaborates with cross-functional teams including IT, legal, compliance and liaises with law enforcement and other external entities to address findings and implement corrective action.
  • Develops innovative approaches and solutions, including use of data analytics, Agile methodology, and automation to improve overall effectiveness and value of the controls testing team.
  • Ensures compliance with applicable security policies and standards.
  • Stays updated on latest cybersecurity threats, vulnerabilities, and testing techniques, contributing to the enhancement of cybersecurity practices within the organization.
  • Provides professional advice – takes a lead role of process or program execution
  • Is accountable for own work and contributes to setting standards through expertise in own job discipline that impact others' deliverables
  • Work is guided by cascaded policies or business plans
  • May lead medium to large size projects or work streams with moderate resource requirements, risk and/or complexity with multiple teams representing different interests

Required Qualifications

  • Knowledge of IT security controls and technologies, IT systems and networks, security testing, security policies, standards, and regulations
  • Experience performing compliance and control testing assessments
  • Knowledge of frameworks such as NIST CSF, ISO 27001 and CIS Top 20 Controls
  • Proficiency in understanding operating systems (Windows, Linux, Unix), network protocols, and cybersecurity frameworks
  • Understanding of cloud computing security principles and leading practices
  • Understanding of legal and regulatory requirements related to cybersecurity, privacy, and data protection laws relevant to the organization
  • Knowledge of data privacy laws, data security issues, encryption techniques, data classification, and data loss prevention mechanism

Skills

  • Cybersecurity
  • Security Compliance
  • IT Controls
  • IT Audit
  • IT Regulatory Compliance
  • Risk Assessment
  • Control Testing

When You Join Our Team

  • We'll empower you to learn and grow the career you want.
  • We'll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we'll support you in shaping the future you want to see.

About Manulife And John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit

Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact

Working Arrangement
Hybrid



  • Quezon City, National Capital Region, Philippines Asticom Technology Inc. Full time

    Job Roles and ResponsibilitiesI. Strategic Leadership and Governance:Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.Policy and Procedure Development: Create, maintain, and...


  • Quezon City, National Capital Region, Philippines Manulife Full time

    As a Business Unit Security Officer (BUSO) within the Information Risk Management team under Global Wealth Asset Management (GWAM) Information Technology First Line of Defense, you will play a critical role in safeguarding the organization's IT environment. This role involves conducting risk assessments for new and existing applications, infrastructure, and...


  • Quezon City, National Capital Region, Philippines UCPB Savings Bank Full time

    JOB SUMMARYAssists the Risk Management Division head in its risk oversight function on technology risk through the use of applicable risk management tools to identify, measure, monitor, and control technology risks;Directs the Bank in protecting all information assets and assists the Senior Management Response Team (MANCOM) in its business continuity and...


  • Quezon City, National Capital Region, Philippines Global Payments Inc. Full time

    SummaryDescriptionSummary of This RoleEvaluates, tests, recommends, develops, coordinates, monitors, and maintains information security policies, procedures and systems, including hardware, firmware and software . Ensures that IS security architecture/designs, plans, controls, processes, standards, policies and procedures are aligned with IS standards and...


  • Quezon City, National Capital Region, Philippines Global Payments Full time

    Every day, Global Payments makes it possible for millions of people to move money between buyers and sellers using our payments solutions for credit, debit, prepaid and merchant services. Our worldwide team helps over 3 million companies, more than 1,300 financial institutions and over 600 million cardholders grow with confidence and achieve amazing results....


  • Makati City, National Capital Region, Philippines PSBank Official Full time

    Job PurposeResponsible for coordinating walkthroughs and obtaining supporting documents from relevant departments, necessary to assist both internal and external auditors/reviewers. The Information Security Compliance Officer shall, keep track of ISG related outstanding issues to support the Manager in ensuring timely resolution. Information Security...


  • Makati City, National Capital Region, Philippines Emapta Full time

    Build Stronger, Smarter Security for a Worldwide Network of Industry Experts At Emapta, we are at the forefront of global outsourcing, connecting businesses with elite, high-performing talent across borders. With 15 years of success and 10,000+ professionals in 11 countries, we deliver seamless operations, robust cybersecurity, and innovative workforce...


  • Quezon City, National Capital Region, Philippines RELX Full time

    Key ResponsibilitiesSecurity Assessment ManagementServe as an advanced technical advisor for third-party assessments, providing detailed security insights and solutions.Perform in-depth security reviews and risk assessments for new and existing third-party vendors, ensuring compliance with organizational and regulatory requirements.Demonstrate advanced...


  • Makati City, National Capital Region, Philippines Smart Communications, Inc. Full time

    Responsibilities:Actively monitor, detect, and respond to security alerts and incidents per defined SLA.Incidents are acknowledged and responded to within the agreed response SLOPerform alert triage and analysis including asset and custodian identification, reputational checking, and alert validationPerform containment and eradication within the agreed...


  • Makati City, National Capital Region, Philippines Total Information Management Corporation Full time

    A Network and Security Engineer is responsible for the design, implementation, and continuous improvement of the entire infrastructure's security posture — encompassing network systems, servers, endpoints, cloud platforms, and perimeter defenses. This role goes beyond traditional network responsibilities, ensuring that all layers of infrastructure are...