Information Security Manager
1 week ago
The Information Security Manager is responsible for safeguarding the organization's information assets by implementing, managing, and overseeing the company's security policies, protocols, and procedures. This role involves identifying and mitigating security risks, ensuring compliance with industry standards, and leading efforts to protect sensitive data across all digital platforms.
- Assess risk and ensure security systems and operations comply with organizational and regulatory requirements
- Lead the development and execution of security strategies and policies
- Responsible for day to day execution of security policies and procedures. Using monitoring tools to identify threats and incidents
- Analyze, design, manage and deliver the services required to minimize the negative impact of security incidents and restoring normal service operation as quickly as possible
Roles and Responsibilities
- Advise appropriate senior leadership on risk levels and changes affecting the organization's cybersecurity posture.
- Work with the necessary resources, including leadership support, financial resources, and key security personnel, to support information technology (IT) security goals and objectives and reduce overall organizational risks.
- Oversee policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies.
- Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals.
- Continuously validate the organization against policies, guidelines, procedures, regulations, laws to ensure compliance.
- Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
- Identify alternative information security strategies to address organizational security objective.
- Ensure that cybersecurity requirements are integrated into the continuity planning for systems and/or organization(s).
- Prepare, distribute, and maintain plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations.
- Ensure that cybersecurity inspections, tests, and reviews are coordinated for the network environment.
- Participate in the development or modification of the computer environment cybersecurity program plans and requirements.
- Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs).
- Recognize a possible security violation and take appropriate action to report the incident, as required.
- Supervise or manage protective or corrective measures when a cybersecurity incident or vulnerability is discovered.
- Collect and maintain data needed to meet system cybersecurity reporting.
- Identify information technology (IT) security program implications of new technologies or technology upgrades.
- Identify security requirements specific to an information technology (IT) system in all phases of the system life cycle.
- Lead information security risk assessment during the Security Assessment and Authorization process.
- Evaluate and approve development efforts to ensure that baseline security safeguards are appropriately installed.
- Provide system-related input on cybersecurity requirements to be included in statements of work and other appropriate procurement documents.
- Promote awareness of security issues among management and ensure sound security principles are reflected in the organization's vision and goals.
- Communicate the value of information technology (IT) security throughout all levels of the organization stakeholders.
- Oversee the information security training and awareness program.
- Manage the monitoring of information security data sources to maintain organizational situational awareness.
- Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
- Track audit findings and recommendations to ensure that appropriate mitigation actions are taken.
Core Competencies:
- Business Continuity
- Computer Network Defense
- Database Administration
- Encryption
- Enterprise Architecture
- Information Systems/Network Security
- Network Management
- Operating Systems
- Policy Management
- Risk Management
- Technology Awareness
- Threat Analysis
- Vulnerabilities Assessment
Additional Knowledge Areas:
- ISO 27000 – NIST – CIS – Data Privacy
Qualifications:
- Bachelor's degree in Information Security, Computer Science, or related field.
- Proven experience (5+ years) in information security management, IT risk management, or similar roles.
- Strong understanding of current IT threats, security protocols, and industry best practices.
- Professional certifications such as CISSP, CISM, or equivalent is an advantage.
- Excellent leadership, communication, and project management skills.
About DAVI
Data Analytics Ventures Inc. (DAVI) is the Gokongwei Group's loyalty and data analytics company, specializing in deep-dive data analysis to enhance business processes and customer experiences. Leveraging rich data, DAVI helps businesses understand brand and category performance, identify growth opportunities, and optimize decisions. With a team of industry leaders and innovators, DAVI fosters a culture of excellence, continuous learning, and mentorship, empowering employees to shape their careers and contribute to the rapidly evolving data industry.
-
Information Security Risk Manager
2 weeks ago
Makati City, National Capital Region, Philippines 1881b99f-5d2c-4da9-ac26-25cafe743eb4 Full time ₱1,500,000 - ₱3,000,000 per yearAbout the RoleAs an Information Security Risk Manager you are responsible for helping ensure that SBC's Information Security policies and procedures align with all relevant regulation and company values. S/He helps to facilitate the wider team's understanding of their compliance responsibilities under the relevant regulations and company values and how to...
-
Information Security Manager
2 weeks ago
Quezon City, National Capital Region, Philippines Manulife Full time ₱1,500,000 - ₱3,000,000 per yearTheInformation Security Managerevaluates technology environments through control testing, compliance assessments, identifies key gaps and recommends actions for remediation. Partners with other teams for cybersecurity controls assessment and tests effectiveness of cybersecurity controls ensuring that systems and processes meet industry standards and...
-
Information Security Officer
2 weeks ago
Makati City, National Capital Region, Philippines PSBank Official Full time ₱1,200,000 - ₱2,400,000 per yearJob PurposeResponsible for coordinating walkthroughs and obtaining supporting documents from relevant departments, necessary to assist both internal and external auditors/reviewers. The Information Security Compliance Officer shall, keep track of ISG related outstanding issues to support the Manager in ensuring timely resolution. Information Security...
-
Information Security Manager, IAM
2 weeks ago
Quezon City, National Capital Region, Philippines Manulife Full time ₱1,200,000 - ₱2,400,000 per yearWe're looking for an Information Security Manager, Identity Access Management (IAM) Consultant to join our Group Functions IT Information Security and Business Resilience Team at MBPS. In this role, you are expected to apply identity access security risk knowledge and expertise to assist with IT information security First Line of Defense activities to help...
-
Information Security Lead
2 weeks ago
Quezon City, National Capital Region, Philippines Asticom Technology Inc. Full timeJob Roles and ResponsibilitiesI. Strategic Leadership and Governance:Develop and Execute Security Strategy: Lead the formulation, implementation, and continuous improvement of the BPO's information security strategy, aligning it with business objectives, client requirements, and regulatory compliance.Policy and Procedure Development: Create, maintain, and...
-
Information Security Analyst
2 weeks ago
Quezon City, National Capital Region, Philippines Manulife Full time ₱250,000 - ₱500,000 per yearWe're seeking an Information Security Analyst to join our Group Functions IT – Information Security Management and Business Resilience (GFT ISM & BR) team at MBPS. In this role, you will play a key part in delivering BUSO services and driving continuous security monitoring across the organization. Your responsibilities will include managing security...
-
Information Security Consultant
2 weeks ago
Quezon City, National Capital Region, Philippines Manulife Full time ₱1,500,000 - ₱3,000,000 per yearAs a Business Unit Security Officer (BUSO) within the Information Risk Management team under Global Wealth Asset Management (GWAM) Information Technology First Line of Defense, you will play a critical role in safeguarding the organization's IT environment. This role involves conducting risk assessments for new and existing applications, infrastructure, and...
-
Information Security Manager, RCSA
2 weeks ago
Quezon City, National Capital Region, Philippines Manulife Full time ₱1,200,000 - ₱2,400,000 per yearWe're looking for an Information Risk Manager (RCSA) to join our Group Functions IT Information Security and Business Resilience Team at MBPS. In this role, you will be responsible for planning, executing, leading, and completing Risk and Control Self-Assessments (RCSA) and continuous monitoring activities. This includes RCSA, Integrated RCSA for Critical...
-
Security Operations Manager
2 weeks ago
Mandaluyong City, National Capital Region, Philippines The Dairy Farm Company, Limited- ROHQ Full time ₱2,000,000 - ₱2,500,000 per yearDFI Team BriefThis role will assist the IT organization to implement on enhance network security system from Group requirements and collaborate with 1st line of response team to handle network and cyber security issues. The incumbent will also assist in building necessary capabilities in security governance and technology enablement, collaborate with country...
-
Information Security Analyst
1 week ago
Makati City, National Capital Region, Philippines Smart Communications, Inc. Full timeResponsibilities:Actively monitor, detect, and respond to security alerts and incidents per defined SLA.Incidents are acknowledged and responded to within the agreed response SLOPerform alert triage and analysis including asset and custodian identification, reputational checking, and alert validationPerform containment and eradication within the agreed...