
Information Security Manager
- Taguig City, Metro Manila
- ₱150,000 per year
- Permanent
- Full-time
- Develop, implement, and maintain security policies, standards, and procedures.
- Align security initiatives with business objectives and regulatory requirements.
- Support internal and external audits and ensure compliance with frameworks (e.g., ISO 27001, NIST, GDPR).
- Risk Management
- Conduct regular risk assessments and vulnerability scans.
- Maintain and update the enterprise risk register.
- Recommend and oversee remediation plans for identified risks.
- Security Operations
- Monitor and manage security tools (e.g., SIEM, firewalls, antivirus, DLP).
- Lead incident response efforts and forensic investigations
- Coordinate with IT teams to ensure timely patching and system hardening.
- Identity & Access Management
- Oversee user access controls and privilege management.
- Ensure proper implementation of multi-factor authentication (MFA) and role-based access.
- Security Awareness & Training
- Develop and deliver security awareness programs for employees.
- Promote best practices and ensure ongoing education on emerging threats. 6. Project & Vendor Security
- Provide security oversight for IT and business projects.
- Review third-party vendor contracts and solutions for security compliance.
- A Bachelor's Degree is required with a Master's Degree in cybersecurity, risk management, or IT governance being preferred
- Must possess a strong understanding of security frameworks (ISO 27001, NIST, COBIT)
- Experience with security operations tools and incident response
- Knowledge of cloud security (Azure, AWS, M365)
- Excellent communication and leadership skills
- Ability to manage cross-functional teams and influence stakeholders
- Analytical thinking and decision-making under pressure
- The following certifications are preferred:
- CISM (Certified Information Security Manager) – by ISACA Ideal for managing enterprise security programs.
- CISSP (Certified Information Systems Security Professional) – by (ISC)² Broad coverage of security domains.
- ISO/IEC 27001 Lead Implementer or Auditor – for governance and compliance
- CompTIA Security+ or CySA+ – for foundational and operational security
- CEH (Certified Ethical Hacker) – for threat analysis and penetration testing