Manager, Information Security - Metro Manila - ABSI

    ABSI
    ABSI Metro Manila

    16 oras ang nakalipas

    Paglalarawan

    Job Roles and Responsibilities

    The Manager, Information Security & Data Privacy Engineering is a senior security leadership role responsible for architecting and operationalizing a "Trust by Design" culture across the Asticom ETG ecosystem. This role shifts the security function from a reactive checkpoint to a proactive enablement engine — embedding security and privacy upfront into every process, product, and platform. The Manager leads the Cyber Defense, Identity & Access Management (IAM), Data Privacy, and Threat Intelligence functions, with a mandate to protect Asticom's digital infrastructure while enabling business velocity.

    90-Day Success Mandate:

    • Achieve 100% MFA compliance across all public-facing tools and critical business systems
    • Establish a structured, proactive threat-hunting cadence within the first 60 days
    • Complete the DPA technical compliance baseline assessment and publish the remediation roadmap

    II. Key Responsibilities

    A. Security Engineering & Architecture

    • Lead the design and implementation of enterprise security architecture, ensuring all systems are built with "Security by Design" principles from inception
    • Own the organization's security roadmap, aligning technical security initiatives with the Asticom ETG's business and revenue objectives (₱3.75B GSR targets)
    • Architect and govern Identity & Access Management (IAM) frameworks, including MFA deployment, privileged access management, and user access reviews (UAR) across all platforms
    • Drive endpoint security hardening, including patch management, vulnerability remediation, and Zero Trust adoption across all Asticom sites

    B. Data Privacy & Compliance Engineering

    • Serve as the technical arm of the Data Privacy Office (DPO), operationalizing "Privacy by Design" in all product and infrastructure development lifecycles
    • Ensure technical compliance with the Philippine Data Privacy Act (DPA), maintaining data residency standards and data minimization controls across all platforms
    • Lead Privacy Impact Assessments (PIAs) and provide technical recommendations for data handling, storage, and cross-border transfer compliance
    • Maintain and mature the organization's GRC framework, including risk register management, policy exception reviews, and security awareness programs

    C. Threat Intelligence & Incident Leadership

    • Serve as the APAC-level Incident Commander for all high-severity cybersecurity incidents, coordinating cross-functional response, resolution, and post-incident reviews
    • Establish a proactive threat-hunting function, utilizing threat intelligence feeds and security tooling to detect and neutralize advanced persistent threats (APTs) before impact
    • Lead the development and testing of the Cyber Incident Response Plan (CIRP) and Business Continuity Plan (BCP) for all security-critical systems

    D. Third-Party Risk & Vendor Governance

    • Own the Third-Party Risk Management (TPRM) program, conducting vendor risk assessments, SOC 2 analysis, and ongoing due diligence for all technology suppliers and managed service partners
    • Collaborate with Legal and Procurement on vendor contracts, ensuring appropriate security SLAs, data processing agreements (DPAs), and contract language that reflect Asticom's risk posture
    • Manage and optimize the organization's GRC tooling platforms (e.g., OneTrust, Archer, ServiceNow) to ensure continuous risk visibility and audit trail integrity

    E. Security Leadership & Stakeholder Management

    • Translate complex security threats and technical risk data into Executive Brief formats for ManCom and Board-level reporting, enabling informed strategic decisions
    • Build, mentor, and develop the team, fostering a security-first culture across all ETG towers
    • Partner with Tower 1 (Digital Workplace), Tower 2 (Infrastructure), and Tower 4 (Tech Strategy) leads to embed security controls without impeding operational velocity

    Job Qualifications

    A. Experience

    • Minimum 8–10 years of progressive experience in Information Technology, Information Security, IT Governance, Risk, and Compliance (GRC), or a related discipline within enterprise or multinational environments
    • Demonstrated experience leading cybersecurity incident response at a regional (APAC) scale, including coordination of cross-functional teams and executive-level stakeholder communication
    • Proven track record in Third-Party Risk Management (TPRM), including vendor risk assessments, SOC report reviews, and risk remediation programs
    • Experience in data-intensive, regulated industries (logistics, healthcare, financial services) is a strong advantage, demonstrating adaptability to high-compliance environments
    • Background in IT Infrastructure, endpoint management, and systems administration provides a strong operational foundation for this role

    B. Education

    • Bachelor's Degree in Information Technology, Computer Science, Information Systems, or a related field
    • Relevant post-graduate study or advanced certifications may be considered instead of formal advanced degrees

    C. Certifications

    • Required: ITIL Foundation (V3 or V4) — demonstrating foundational IT service management proficiency aligned with Asticom's Service Value System
    • Required: Certified in Cybersecurity (CC) by ISC2, or equivalent foundational cybersecurity credential
    • Required: Demonstrated proficiency or active training in GRC tooling platforms (e.g., OneTrust, Archer, or equivalent enterprise risk management systems)
    • Preferred: CISSP, CISM, or CISA — or active pursuit of such advanced certifications
    • Preferred: Extreme Networks, Cisco (CCNA level), or other network security credentials

    D. Competencies

    • Deep expertise in GRC frameworks, including SOC 2 analysis, User Access Reviews (UAR), security policy management, and continuous compliance monitoring
    • Proficiency in security platforms: identity management, endpoint detection and response (EDR), firewall management, and vulnerability assessment tools
    • Working knowledge of Microsoft 365, Power BI, ServiceNow, and workflow automation tools to support data-driven security reporting
    • Strong executive communication skills — ability to author Board-ready security briefings, incident post-mortems, and risk register summaries
    • Recognized excellence in project delivery and incident management (e.g., industry-standard awards for crisis response or service excellence) is a significant advantage

  • Trabaho sa kumpanya

    Information Security

    Para lamang sa mga rehistradong miyembro

    About Wrist is the world's leading ship and offshore supplier of marine provisions and stores. · ...

    Manila Buong oras

    1 buwan ang nakalipas

  • Trabaho sa kumpanya

    Information Security

    Para lamang sa mga rehistradong miyembro

    We continuously work on reducing our climate impact while at the same time proactively addressing our customers' growing demand and need for responsible solutions and services. · TBD · ...

    Manila

    1 buwan ang nakalipas

  • Trabaho sa kumpanya

    Information Security Analyst

    Para lamang sa mga rehistradong miyembro

    Job Summary: · We're looking to hire an expert to help us keep our network and systems safe from cyber attacks. You'll be responsible for keeping an eye on security issues, figuring out what needs to be done, coming up with solutions, and doing security audits and tests. Plus, yo ...

    Manila ₱480,000 - ₱1,200,000 (PHP) bawat taon

    3 araw ang nakalipas

  • Trabaho sa kumpanya

    Head of Information Security

    Para lamang sa mga rehistradong miyembro

    The Head of Information Security & Enterprise Risk Management is a senior executive responsible for designing, governing, and continuously strengthening an enterprise-wide cyber security, information risk, and technology risk framework across a complex, multi-business, multi-tech ...

    Manila, Metro Manila

    1 buwan ang nakalipas

  • Trabaho sa kumpanya

    Information Security

    Maya

    Join Maya's Information Security Governance team as a User Access Management (UAM) Intern and gain hands-on exposure to how access controls, identity governance, and security best practices are implemented in a fast-paced banking environment. This internship is designed for stude ...

    Mandaluyong ₱700,000 - ₱1,500,000 (PHP) bawat taon

    3 araw ang nakalipas

  • Trabaho sa kumpanya

    Specialist, Information Security

    Tap Growth ai

    We're Hiring: Specialist, Information Security (US) · We are looking for a dedicated and detail‑oriented Information Security Specialist to support our growing global security and compliance initiatives. This role is perfect for someone who thrives in a remote setup, collaborates ...

    Manila

    3 araw ang nakalipas

  • Trabaho sa kumpanya

    Information Security

    Para lamang sa mga rehistradong miyembro

    Join Maya's Information Security Governance team as a User Access Management (UAM) Intern and gain hands-on exposure to how access controls identity governance and security best practices are implemented in a fast-paced banking environment. This internship is designed for student ...

    Mandaluyong

    4 linggo ang nakalipas

  • Trabaho sa kumpanya

    Information Security Specialist

    Tap Growth ai

    We're Hiring: Information Security Specialist · We are looking for a detail‑oriented and driven Information Security Specialist to join our team. If you're passionate about compliance, documentation, and ensuring organizations meet global security standards, this role is perfect ...

    Manila ₱750,000 - ₱1,500,000 (PHP) bawat taon

    3 araw ang nakalipas

  • Trabaho sa kumpanya

    Information Security Specialist

    Para lamang sa mga rehistradong miyembro

    We're Hiring: Information Security Specialist · We are looking for a detail‑oriented and driven Information Security Specialist to join our team. If you're passionate about compliance, documentation, and ensuring organizations meet global security standards, this role is perfect ...

    Manila, National Capital Region ₱750,000 - ₱1,500,000 (PHP) bawat taon

    2 araw ang nakalipas

  • Trabaho sa kumpanya

    Information Security

    Para lamang sa mga rehistradong miyembro

    Join Maya's Information Security Governance team as a User Access Management (UAM) Intern and gain hands-on exposure to how access controls, identity governance and security best practices are implemented in a fast-paced banking environment. · ...

    Mandaluyong, National Capital Region

    4 linggo ang nakalipas

  • Trabaho sa kumpanya

    Information Security Specialist

    Para lamang sa mga rehistradong miyembro

    Job Title: Information Security Specialist (Compliance & Audit Focus) · Job Summary · We are seeking a detail-oriented · Information Security Specialist · to support compliance initiatives and certification audit projects. This role is primarily focused on · Information Security ...

    Manila, National Capital Region ₱750,000 - ₱1,500,000 (PHP) bawat taon

    1 araw ang nakalipas

  • Trabaho sa kumpanya

    Information Security Specialist

    Tap Growth ai

    We are seeking an Information Security Specialist to support compliance initiatives and certification audit projects.This role is focused on Information Security Governance, Risk, and Compliance (GRC) rather than hands-on IT or cybersecurity operations. · ...

    Manila ₱750,000 - ₱1,500,000 (PHP) bawat taon

    1 linggo ang nakalipas

  • Trabaho sa kumpanya

    Information Security

    Para lamang sa mga rehistradong miyembro

    About the role As an Information Security & Privacy Compliance Analyst at YONDU INC.', you will play a vital role in ensuring the company's information security and privacy compliance standards are met. · ...

    Bonifacio Global, Metro Manila

    4 linggo ang nakalipas

  • Trabaho sa kumpanya

    Information Security Specialist

    Para lamang sa mga rehistradong miyembro

    We're Hiring: Information Security Specialist · We are looking for a detail‑oriented and driven Information Security Specialist to join our team. If you're passionate about compliance, documentation, and ensuring organizations meet global security standards, this role is perfect ...

    Manila ₱750,000 - ₱1,500,000 (PHP) bawat taon

    3 araw ang nakalipas

  • Trabaho sa kumpanya

    Information Security Architect

    Para lamang sa mga rehistradong miyembro

    As a Security Architect, you will engage across various domains within information security, focusing on: · Evaluating and auditing existing security controls and solutions. · Designing and implementing new security measures. · Providing expert counsel within the department and b ...

    Manila

    1 buwan ang nakalipas

  • Trabaho sa kumpanya

    Information Security Analyst

    Para lamang sa mga rehistradong miyembro

    Support information security initiatives with a strong focus on ISO 27001 compliance. · ...

    Manila

    1 buwan ang nakalipas

  • Trabaho sa kumpanya

    Information Security Analyst

    Para lamang sa mga rehistradong miyembro

    +Job summary · We're looking for a detail-oriented Security & Compliance Analyst to own and manage customer security questionnaires, RFPs, and security reviews. · ...

    Manila

    2 linggo ang nakalipas

  • Trabaho sa kumpanya

    Information Security Analyst

    Para lamang sa mga rehistradong miyembro

    We're looking for a detail-oriented Security & Compliance Analyst to own and manage customer security questionnaires, RFPs, and security reviews. · ...

    Manila

    3 linggo ang nakalipas

  • Trabaho sa kumpanya

    Information Security Specialist

    Para lamang sa mga rehistradong miyembro

    We are seeking a detail-oriented Information Security Specialist to support compliance initiatives and certification audit projects. This role is primarily focused on Information Security Governance, Risk, and Compliance (GRC) rather than hands-on IT or cybersecurity operations. ...

    Manila

    1 linggo ang nakalipas

  • Trabaho sa kumpanya

    Manager, Information Security

    Para lamang sa mga rehistradong miyembro

    Job Roles and Responsibilities · The Manager, Information Security & Data Privacy Engineering is a senior security leadership role responsible for architecting and operationalizing a "Trust by Design" culture across the Asticom ETG ecosystem. This role shifts the security functio ...

    Manila

    1 araw ang nakalipas

  • Trabaho sa kumpanya

    Information Security Specialist

    Para lamang sa mga rehistradong miyembro

    We're Hiring: Information Security Specialist · We are seeking an Information Security Specialist to drive security and compliance initiatives across our global operations. · Location: Philippines · Work Mode: Work From Office | US Eastern Time · Role: Information Security Speci ...

    Manila ₱750,000 - ₱1,500,000 (PHP) bawat taon

    9 oras ang nakalipas

Trabaho
>
Manila