Search by job, company or skills

Information Security Officer

5-7 Years
  • Posted 4 hours ago
  • Be among the first 10 applicants

Job Description

Executive Recruitment Firm Monroe Consulting Group Philippinesis recruiting on behalf of a financial technology company in the Philippines, operating as an Electronic Money Issuer licensed by the Bangko Sentral ng Pilipinas. They provide financial services through their e-wallet and develop payment solutions for businesses nationwide.

Job Summary

Our client is seeking a hands-on Information Security Officer (ISO) who will drive information security governance in line with BSP regulations and will actively lead the technical implementation of security controls across platforms, which include AWS infrastructure and Java Spring Boot applications. This role requires a balance of compliance and deep technical execution, to design security policies and get into the code/configurations to harden systems.

The role will be based in Ortigas, Pasig City, with an Onsite work set-up.

Key Job Responsibilities:

Governance & Compliance

  • Lead the development, implementation, and enforcement of the company's Information Security Program in compliance with BSP regulations (Circulars 808, 982, 1019, etc.), ISO 27001, NIST, and the Data Privacy Act (RA 10173).
  • Monitor, Implement and Report on the company's security posture, risks, and incidents.
  • Perform security oversight while collaborating with engineering and DevOps teams.

Risk Management

  • Perform and document risk assessments specific to cloud-native fintech systems.
  • Conduct threat modeling, vulnerability scans, and penetration tests, particularly on web/mobile apps and cloud environments.
  • Recommend and implement security controls to address risks across infrastructure and application layers.

Technical Security Implementation (Hands-On)

  • AWS Cloud Security: Design and implement secure AWS architectures following best practices (IAM policies, VPC design, security groups, WAF, GuardDuty, Config, CloudTrail). Manage encryption (KMS), secrets management, and secure CI/CD pipelines. Monitor AWS environments using SIEM/SOC tools.
  • Java Spring Boot Application Security: Integrate secure coding practices and automated security checks in the SDLC. Implement authentication, authorization, and secure session management. Apply OWASP Top 10 protections (e.g., SQL injection, XSS, CSRF) in code reviews.Conduct static/dynamic code analysis (SAST/DAST) and oversee remediation.
  • DevSecOps & Monitoring: Embed security controls in CI/CD workflows. Automate vulnerability scanning, dependency checking, and container security. Lead incident response, forensic analysis, and root cause investigations.

Awareness & Training

  • Conduct technical training and secure coding workshops for developers.
  • Drive security awareness programs across the organization.

Key Job Qualifications:

  • Bachelor's degree in Computer Science, Information Technology, or related field.
  • 5+ years of combined experience in information security and hands-on technical security engineering.
  • Familiarity with BSP regulations for fintech/EMI/financial institutions.
  • Strong expertise in AWS cloud security architecture and implementation.
  • Solid experience in Java Spring Boot application security and secure coding practices.
  • Proficiency in vulnerability management tools, SIEM, IDS/IPS, and DevSecOps pipelines.
  • Relevant certifications preferred: CISSP, CISM, AWS Security Specialty, OSCP, CEH, CSSLP, or ISO 27001.

More Info

Job Type:
Industry:
Employment Type:

Job ID: 153735185

Similar Jobs

Philippines, Taguig

Skills:

Iso 27001SocDocumentation Record ManagementCompliance Framework DevelopmentCompliance Monitoring ChecksAudit Regulatory CoordinationTraining Awarenessitgc

Philippines, Taguig

Skills:

Iso 27001CismGdprCisspPCI-DSSIntune PoliciesMicrosoft Azure Entra

Beware of Scammers

We don’t charge money for job offers