A complete application in a minute — tailored resume and cover letter, ready to send.
Smartrecruitment is seeking a Cyber Security Manager to lead the design, implementation, and continuous improvement of the cyber security program protecting the online gaming platform, player data, and corporate systems. You will oversee threat monitoring, incident response, and vulnerability management.
The role requires 8+ years in information security with at least 3 years in management, strong knowledge of ISO 27001 and NIST CSF, PAGCOR/regulatory compliance, and the ability to drive
Location: Onsite, Philippines
About the Hiring Company:
The Cyber Security Manager leads the design, implementation, and continuous improvement of the cyber security program protecting the online gaming platform, player data, and corporate systems, ensuring resilience against evolving threats and compliance with PAGCOR and other regulatory requirements.
Job Responsibilities:
Develop, implement, and maintain the cyber security strategy, policies, and standards covering the online gaming platform and corporate environments.
Lead security operations, including threat monitoring, detection, incident response, and forensic investigation, ensuring incidents are contained and resolved within agreed timelines.
Manage the vulnerability management program, including scanning, penetration testing, and remediation tracking across applications and infrastructure.
Oversee security architecture reviews for new systems, platform integrations, and third-party service providers, including PAGCOR-mandated integrations.
Operate and optimize security technologies such as SIEM, EDR, WAF, IDS/IPS, and DLP, evaluating new tools as the threat landscape evolves.
Ensure compliance with regulatory and industry requirements, including PAGCOR, the Data Privacy Act, PCI DSS, and ISO 27001, supporting audits and certification activities.
Design and deliver security awareness programs to strengthen the organization's security culture.
Lead, mentor, and develop the security engineering and operations team, managing performance and capability development.
Coordinate with GRC, IAM, network, server, and DevOps teams to embed security controls across systems and processes.
Manage third-party security providers, including SOC, penetration testing, and threat intelligence vendors, against defined SLAs.
Maintain and regularly test the incident response plan and supporting playbooks, including tabletop and simulation exercises.
Report security posture, key risks, and incident metrics to senior management and recommend risk treatment actions.
Key Performance Indicators:
Mean time to detect and mean time to respond to security incidents.
Percentage of critical and high vulnerabilities remediated within SLA.
Closure rate of audit and compliance findings within committed dates.
Security awareness training completion rate and phishing simulation results.
Availability and coverage of security monitoring tools across critical systems.
The Successful Candidate:
Education: Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field.
Experience: 8+ years in information or cyber security, with at least 3 years in a managerial or team lead role, ideally in online gaming, fintech, or other regulated, transaction-heavy industries.
Skills & Knowledge: Deep knowledge of security frameworks (ISO 27001, NIST CSF), security operations (SIEM, EDR, WAF, IDS/IPS), cloud and network security, incident response, vulnerability management, and regulatory compliance (PAGCOR, Data Privacy Act, PCI DSS); strong leadership, vendor management, and stakeholder communication skills.
Certifications (good to have): CISSP, CISM, CEH, or GIAC certifications preferred.