Position Overview
We are looking for an experienced Cyber Security & Information Governance Lead to manage and strengthen the organisation's cybersecurity, information security, and compliance practices in the Philippines.
Reporting to the Head of IT, you will provide independent security and governance oversight across IT functions, including Infrastructure, Systems, Network, Support, and Development.
Key Responsibilities
Cybersecurity & IT Governance
- Manage and continuously improve the organisation's Information Security Management System (ISMS).
- Develop and maintain IT security policies, standards, and procedures.
- Conduct security reviews and risk assessments across IT systems and infrastructure.
- Review major IT changes, cloud migrations, and system integrations from a security perspective.
- Ensure appropriate controls are in place for access management, endpoint security, patching, and other key security areas.
Audits & Compliance
- Lead preparation for ISO 27001 and CyberVadis assessments.
- Coordinate internal and external security audits and follow up on audit findings.
- Manage cybersecurity questionnaires and due diligence requests from clients.
- Maintain security documentation and evidence required for audits and compliance.
Data Privacy
- Support compliance with GDPR and the Philippine Data Privacy Act.
- Conduct data mapping and Data Protection Impact Assessments (DPIAs) where required.
- Identify and help address data privacy and security risks.
Application & Technology Security
- Provide security oversight for application releases, cloud changes, and API integrations.
- Review technical designs and changes to identify potential security risks.
- Work with development and IT teams to promote secure technology practices.
Security Awareness
- Develop and deliver cybersecurity awareness training.
- Coordinate phishing simulations and other security awareness activities.
- Promote a strong culture of security and compliance across the organisation.
Key Requirements
- 5+ years of experience in cybersecurity, information security, IT risk, or security governance.
- Experience with ISO 27001 implementation or maintenance.
- Experience with CyberVadis, SOC 2, or similar security assessments.
- Good knowledge of GDPR, the Philippine Data Privacy Act, and security frameworks such as NIST and CIS.
- Certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Implementer/Auditor are an advantage.
- Strong analytical, communication, and problem-solving skills.
- Excellent written and spoken English.
- Ability to work independently and collaborate with international and cross-functional teams.
Employment Details
Work Schedule
- 11:00 AM – 8:00 PM (Manila Time), or
- 12:00 NN – 9:00 PM (Manila Time), supporting UK business hours.
Work Setup
- Remote for candidates residing outside Pampanga.
- Onsite for candidates based in Pampanga.
- Office location: Angeles City, Pampanga.
- Successful hires are required to report onsite in Pampanga for onboarding and laptop/equipment collection after joining.