Information Security Manager
1 day ago
The
Information Security Manager
evaluates technology environments through control testing, compliance assessments, identifies key gaps and recommends actions for remediation. Partners with other teams for cybersecurity controls assessment and tests effectiveness of cybersecurity controls ensuring that systems and processes meet industry standards and regulatory requirements.
Position Responsibilities
- Plans, conducts and manages cybersecurity and technology controls testing, compliance assessments including IT systems and processes for design and operating effectiveness.
- Develops and maintains test procedures and plans for IT Security Controls, ensuring alignment with key objectives, industry standards and regulatory requirements.
- Evaluates the organization's compliance with preferred cybersecurity frameworks.
- Performs control testing, security assessments, and risk analysis on systems, applications, and network infrastructure to identify potential weaknesses and security gaps.
- Analyzes test results, identifies security control deficiencies, and recommends solutions to resolve identified issues.
- Partners with operations and IT teams to ensure that all IT security controls are adequately tested and implemented.
- Tracks security issues/risks, prepares comprehensive reports outlining findings, recommendations and actionable insights to senior management and stakeholders.
- Collaborates with cross-functional teams including IT, legal, compliance and liaises with law enforcement and other external entities to address findings and implement corrective action.
- Develops innovative approaches and solutions, including use of data analytics, Agile methodology, and automation to improve overall effectiveness and value of the controls testing team.
- Ensures compliance with applicable security policies and standards.
- Stays updated on latest cybersecurity threats, vulnerabilities, and testing techniques, contributing to the enhancement of cybersecurity practices within the organization.
- Provides professional advice – takes a lead role of process or program execution
- Is accountable for own work and contributes to setting standards through expertise in own job discipline that impact others' deliverables
- Work is guided by cascaded policies or business plans
- May lead medium to large size projects or work streams with moderate resource requirements, risk and/or complexity with multiple teams representing different interests
Required Qualifications
- Knowledge of IT security controls and technologies, IT systems and networks, security testing, security policies, standards, and regulations
- Experience performing compliance and control testing assessments
- Knowledge of frameworks such as NIST CSF, ISO 27001 and CIS Top 20 Controls
- Proficiency in understanding operating systems (Windows, Linux, Unix), network protocols, and cybersecurity frameworks
- Understanding of cloud computing security principles and leading practices
- Understanding of legal and regulatory requirements related to cybersecurity, privacy, and data protection laws relevant to the organization
- Knowledge of data privacy laws, data security issues, encryption techniques, data classification, and data loss prevention mechanism
Skills
- Cybersecurity
- Security Compliance
- IT Controls
- IT Audit
- IT Regulatory Compliance
- Risk Assessment
- Control Testing
When You Join Our Team
- We'll empower you to learn and grow the career you want.
- We'll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
- As part of our global team, we'll support you in shaping the future you want to see.
About Manulife And John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact
Working Arrangement
Hybrid
-
Information Security Manager
7 days ago
Quezon City, National Capital Region, Philippines Metro Pacific Tollways Corporation Full time ₱2,000,000 - ₱2,500,000 per yearThe Information Security Manager will help develop and implement the organization's cybersecurity strategy and manage a team of Information Security personnel in securing Metro Pacific Tollway Corporation's information systems, infrastructure and data against internal and external threats.Roles and ResponsibilitiesDesign, develop, and implement the...
-
Information Security Manager
7 days ago
Mandaluyong City, National Capital Region, Philippines Data Analytics Ventures, Inc. | Go Rewards Full time ₱80,000 - ₱120,000 per yearWhat can you tell your friends when they ask what you do?The Information Security Manager is responsible for safeguarding the organization's information assets by implementing, managing, and overseeing the company's security policies, protocols, and procedures. This role involves identifying and mitigating security risks, ensuring compliance with industry...
-
Information Security Analyst
1 day ago
Quezon City, National Capital Region, Philippines Manulife Full time ₱250,000 - ₱500,000 per yearWe're seeking an Information Security Analyst to join our Group Functions IT – Information Security Management and Business Resilience (GFT ISM & BR) team at MBPS. In this role, you will play a key part in delivering BUSO services and driving continuous security monitoring across the organization. Your responsibilities will include managing security...
-
Information Security Consultant
1 day ago
Quezon City, National Capital Region, Philippines Manulife Full time ₱1,500,000 - ₱3,000,000 per yearAs a Business Unit Security Officer (BUSO) within the Information Risk Management team under Global Wealth Asset Management (GWAM) Information Technology First Line of Defense, you will play a critical role in safeguarding the organization's IT environment. This role involves conducting risk assessments for new and existing applications, infrastructure, and...
-
Information Security Analyst
7 days ago
Quezon City, National Capital Region, Philippines J-K Network Manpower Services Full timeCompany Profile: A global business and technology transformation partner that helps firms accelerate their dual transition to a digital and sustainable future while making tangible difference for businesses and society.Position: Information Security AnalystIndustry: IT CompanyLocation: Quezon CitySchedule: Night Shift / ShiftingSalary: 60,000-120,000Work...
-
Information Technology Security Manager
7 days ago
Mandaluyong City, National Capital Region, Philippines San Miguel Corporation Full time ₱1,500,000 - ₱2,500,000 per yearMinimum RequirementsAround 5 years or more experience in Information Security or equivalent (at least 3 years or more experience if working on Information Security with multiple companies);Background in Information Security Governance Roles such as experience with Information Security Policies, Compliance Audits, Risk Assessments, and Infosec...
-
Information Security Risk Manager
1 day ago
Makati City, National Capital Region, Philippines 1881b99f-5d2c-4da9-ac26-25cafe743eb4 Full time ₱1,500,000 - ₱3,000,000 per yearAbout the RoleAs an Information Security Risk Manager you are responsible for helping ensure that SBC's Information Security policies and procedures align with all relevant regulation and company values. S/He helps to facilitate the wider team's understanding of their compliance responsibilities under the relevant regulations and company values and how to...
-
Information Security Officer
2 weeks ago
Makati City, National Capital Region, Philippines Sumisho Motor Finance Corporation Full time ₱900,000 - ₱1,200,000 per yearQualifications:Must have a Bachelor's degree in information Technology, Computer Science or other security-related field;- Preferably with 3-4 years of experience in information security related to security administration, security operations or security implementation; OR- 5-6 years of experience in security audits focusing on network, servers, database,...
-
Information Security Specialist
7 days ago
Mandaluyong City, National Capital Region, Philippines It Full time ₱1,000,000 - ₱2,500,000 per yearIt is the spirit of Bayanihan that drives us to continue our legacy of excellence and commitment to care. As an organization, we achieve our successes through good, honest, and persevering hard work - TOGETHER. It is in this way in which our company was built; we progressed as the country's leading Pharmaceutical company, not by sheer luck, but by pure...
-
Information Security Engineer
2 weeks ago
Makati City, National Capital Region, Philippines Etrading Software Full time ₱1,200,000 - ₱2,400,000 per yearInformation Security Engineer IIIExperience Level: 5+ yearsAbout the RoleWe're looking for a highly skilled Information Security Engineer to strengthen and scale security across our cloud, application, and enterprise environments. In this role, you'll:Lead secure SDLC practices and embed security into every stage ofÂ...