Information Security Manager
Reed Elsevier Philippines- Posted 50 minutes ago
- Be among the first 10 applicants
Job Description
Join us and enjoy benefits designed to help you thrive:
- Flexible hybrid work setup (1-2 days/month onsite reporting)
- IT Equipment provided
- HMO coverage starting from Day 1 for you and FOUR FREE dependents
- Attractive retirement package with company matching
- Life and Accident Insurance starting Day 1
- 24 Annual PTOs, additional 6 once you reach your 5th year with us
- Competitive benefits with annual merit increase and incentives
- Continuous improvement for our employees (workshops, certification programs, learning sessions, etc.)
Work Arrangement:
- Set-Up: Hybrid (1-2/month onsite reporting)
- Location: UP AyalaLand Technohub, Commonwealth, Quezon City
Job Description:
Reporting to the RELX CISO and VP, Cybersecurity GRC, the Information Security Manager provides oversight, coordination, and day-to-day management of security resources while also serving as a senior contributor to customer trust and engagement. The role is dual-faceted: internally, you will manage a team of security professionals supporting RELX/ELS/REPH business units, driving governance, risk, and operational security programs. Externally, you will shape and deliver Elsevier's customer engagement strategy, resolving security inquiries, coordinating customer-initiated audits, and ensuring customers have the confidence they need to adopt and rely on our products.
The ideal candidate embraces AI, builds strong cross-functional relationships, communicates effectively in high-stakes customer engagements, and has the technical expertise to assess and explain complex security risks clearly.
KEY RESPONSIBILITIES
People & Team Leadership (25%)
- Directly manage security resources aligned to RELX/ELS/ REPH/RETS, clarifying roles, responsibilities, and priorities.
- Recruit, on-board, coach, and develop team members; manage performance and career growth plans.
- Communicate vision, set standards for excellence, and motivate the team to high performance.
- Manage resource allocation, prioritization, and planning to meet business and security objectives.
Customer Trust & Engagement (25%)
- Respond to customer security inquiries using knowledge bases, generative AI tooling, and subject matter expertise.
- Lead customer-initiated audits by coordinating across GRC, security engineering, and product teams.
- Build product security narratives and complete RFPs and customer assessments with accuracy and clarity.
- Maintain and continuously improve Elsevier's public Trust Centre and related customer-facing resources.
- Liaise with Sales, Sales Operations, and Product to streamline the intake and resolution of customer trust requests.
Risk Management & Governance (25%)
- Utilize security domain expertise to assess risks associated with third-party service providers, implementation, and operational activities.
- Monitor, identify, and facilitate mitigation of information security risks across third-party service providers.
- Define and publish KPIs that measure the effectiveness of the team, processes, and controls.
- Promote a security culture across technology and business stakeholders.
Security Implementation & Operations (25%)
- Oversee day-to-day security operations: incident management, vulnerability management, change management, and compliance monitoring.
- Review change requests with a security lens; monitor KPIs to ensure controls continuously meet business needs.
- Maintain internally developed security solutions and ensure service continuity.
- Stay current on information security technologies and commercially reasonable practices.
QUALIFICATIONS
- Information Security: Strong understanding of security principles, frameworks (ISO 27001/2 including 27017/18, ISO 22301, ISO 42001), and regulatory requirements (SOX). Able to translate risk findings into clear, actionable guidance for technical and non-technical audiences.
- Customer Engagement: Proven background managing customer security inquiries, questionnaires, Trust Centre operations, client calls, customer audits, and security-related contract language.
- Communication Skills: Exceptional written, verbal, and presentation abilities; demonstrable ability to influence, collaborate, and build trust with both customers and internal stakeholders.
- People Management: 3+ years direct people management experience; skilled at coaching, performance management, and developing high-performing teams.
- Analytical Thinking: Ability to assess complex security scenarios, interpret customer requirements, and provide tailored, well-reasoned responses.
- Project Management: Proven capability to manage multiple concurrent engagements and strategic initiatives, delivering on time with effective prioritization.
- Growth Mindset: Approaches challenges as learning opportunities; adapts to evolving industry trends and stakeholder expectations.
EXPERIENCE & EDUCATION
- 8+ years of IT experience, including 4+ years in information security.
- 3+ years of people management in a security or technology environment.
- Bachelor's degree in a related field preferred.
- CISSP, CISM, or equivalent certification preferred.
