Search Jobs

Search by job, company or skills

Information Security Officer

Information Security Officer

troka group inc.
5-7 Years
  • Posted 6 hours ago
  • Be among the first 10 applicants

Job Description

Company Description Troka Group, Inc. is a Makati-based holding company focused on serving people and businesses with genuine care throughout their journeys. Through Trago Procurement Sourcing Corp., the group helps organizations across the Philippines and beyond efficiently secure essential goods and services. Troka Group is also expanding into fintech, bringing its commitment to trusted and forward-looking service into new sectors. Across all ventures, the company emphasizes dependable support, sincere relationships, and warm, community-centered service. Applicants can expect to join an organization that values care, reliability, and long-term partnership.

Role Description

This is a senior, hands-on role and the most senior information security position in the Company. You will own the security stack end to end — access management, vulnerability and patch management, logging and monitoring, endpoint and network defense, encryption and key management — and you will be the technical and governance backbone behind the Company's compliance with the Bangko Sentral ng Pilipinas (BSP) IT Risk Management framework, the Anti-Financial Account Scamming Act (AFASA) account protection requirements, and the security obligations of the Data Privacy Act.

The role carries a defined progression path. The Company intends that the successful candidate will, on demonstrated performance, be endorsed to the Board of Directors for formal designation as the Company's Information Security Officer, and thereafter progress toward Head of Information Security or Chief Information Security Officer as the function grows. We are hiring a practitioner who is ready to lead, not to be led.

Qualifications

·      Bachelor's degree in Information Technology, Computer Science, Information Systems, Computer Engineering or a related field.

·      At least five (5) years of hands-on information security experience, including meaningful exposure to banking, payments, remittance, e-money, fintech or another regulated financial services environment.

·      Demonstrated ability to operate as the most senior security practitioner in an organization — setting direction and standards, and carrying the work personally, without a large team to delegate to.

·      Working knowledge of the BSP IT Risk Management framework and information security guidelines, the AFASA account protection requirements, and the security obligations of the Data Privacy Act of 2012 and NPC issuances.

·      Practical, hands-on capability across most of the following: SIEM and log management, vulnerability scanning and management, endpoint detection and response, identity and access management, multi-factor authentication, encryption and key management, network security, and cloud security in AWS, Azure or Google Cloud.

·      Familiarity with recognised frameworks such as ISO/IEC 27001, the NIST Cybersecurity Framework, and PCI DSS where card data is processed.

·      Professional certification is strongly preferred — for example CISSP, CISM, CISA, CCSP, CEH, OSCP, GIAC certifications, or a cloud security certification.

·      Experience engaging directly with regulators, examiners, external auditors or partner institutions on information security matters is a significant advantage.

·      Ability to write clearly for non-technical readers — incident reports, board papers and regulatory submissions are part of the job, not an afterthought.

·      Sound judgment and integrity in handling privileged access and confidential customer data, and the discipline to document what was done and why.

·      The independence of mind to raise an uncomfortable finding, and the composure to hold it under pressure.

·      Willing to work on-site in Makati City and to be on call for security incidents outside business hours.

How to Apply

Apply through this posting or send your CV and a short cover note to [Confidential Information], with the subject line Information Security Officer.

Troka Group, Inc. is an equal opportunity employer. We evaluate all applicants on merit and do not discriminate on the basis of age, sex, gender, civil status, religion, disability, ethnicity, or health status.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

endpoint and network defense

encryption and key management

vulnerability scanning and management

endpoint detection and response

cloud security in AWS

multi-factor authentication

vulnerability and patch management

SIEM and log management

ISO IEC 27001

logging and monitoring

NIST Cybersecurity Framework

About Company

Similar Jobs

3-5 yrs
Philippines, Quezon City
Skills:
information security governance Operating SystemsBusiness continuity and recovery strategiesInformation security management systemsSecurity Administrationnetwork systemsIncident handling conceptsInformation risk management
4-6 yrs
Philippines, Taguig
Skills:
Iso 27001CismGdprCisspPCI-DSSIntune PoliciesMicrosoft Azure Entra