Cyber Security Specialist

Sterling Global Call Center, Inc.

Pasig

On-site

PHP 900,000 - 1,300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A prominent outsourcing firm in the Philippines is looking for a Security Governance Lead. The ideal candidate will design and oversee the organization's security governance framework, ensuring compliance with key regulations and frameworks including ISO 27001 and SOC 2. This executive-level role requires extensive experience in information security and governance leadership, as well as strong communication and stakeholder management skills. The position offers a full-time employment opportunity.

Qualifications

  • Over 600 years of information security, risk, or audit experience.
  • Expertise in ISO 27001, SOC 2, PCI DSS, NIST regulations.
  • Proven track record in policy frameworks and control assurance.
  • Strong communication, stakeholder management, and documentation skills.

Responsibilities

  • Designs and oversees security governance framework.
  • Leads compliance with key security standards and regulations.
  • Fosters risk-based decision‑making across the enterprise.
  • Policy, Standards & Awareness: Manage the full lifecycle of policies and standards: drafting, approval, communication, and retirement.
  • Risk Management & Control Assurance: Operate the enterprise security risk process: identify, assess, and track risks and exceptions.
  • Compliance & Audit Readiness: Ensure readiness for ISO 27001, SOC 2, PCI DSS, and client/regulatory audits.
  • Third‑Party & Supply Chain Governance: Lead Third‑Party Risk Management (TPRM): due diligence, assessments, and contract compliance.
  • Metrics, Reporting & Stakeholder Engagement: Produce dashboards on risks, control health, and audit status.
  • Incident, Change & Continuity Governance: Integrate governance with Incident Response, BCP/DR, and Change Management.
  • People Leadership & Operating Model: Lead a small team or governance champions network; provide coaching and quality reviews.

Skills

Information security
Risk management
Stakeholder management
Communication skills
GRC

Education

Experience in governance leadership
Deep understanding of security frameworks

Tools

ServiceNow GRC
Archer
Jira
Drata
Tugboat

Job description

Role Summary

The Security Governance Lead designs, implements, and oversees the organization’s security governance framework ensuring policies, standards, and controls are effective, measurable, and continuously improved. This role drives compliance with frameworks like ISO/IEC 27001:2022, SOC 2, PCI DSS, NIST CSF/800-53, and local privacy laws (e.g., PH Data Privacy Act). Working closely with IT, Legal, HR, and Business Units, the Security Governance Lead fosters risk-based decision‑making, audit readiness, and consistent control adoption across the enterprise.

Key Responsibilities
  • Governance Framework & Strategy
  • Define and maintain the Information Security Governance model, charters, and decision rights.
  • Translate regulatory and business needs into security policies, standards, and baselines.
  • Establish OKRs/KPIs and continuous‑improvement roadmaps aligned to risk appetite.
  • Policy, Standards & Awareness
  • Manage the full lifecycle of policies and standards: drafting, approval, communication, and retirement.
  • Ensure acknowledgment, awareness, and compliance through training and campaigns.
  • Maintain secure configuration baselines across systems, networks, and cloud environments.
  • Risk Management & Control Assurance
  • Operate the enterprise security risk process: identify, assess, and track risks and exceptions.
  • Conduct control testing and self‑assessments for design and operating effectiveness.
  • Oversee risk acceptance and compensating control procedures.
  • Compliance & Audit Readiness
  • Ensure readiness for ISO 27001, SOC 2, PCI DSS, and client/regulatory audits.
  • Manage evidence collection, corrective actions, and the Statement of Applicability (SoA).
  • Coordinate external surveillance and recertification audits.
  • Third‑Party & Supply Chain Governance
  • Lead Third‑Party Risk Management (TPRM): due diligence, assessments, and contract compliance.
  • Maintain supply chain risk registers, vendor access governance, and compliance checks (SSO/MFA, ZTNA, PAM).
  • Metrics, Reporting & Stakeholder Engagement
  • Produce dashboards on risks, control health, and audit status.
  • Present reports to leadership; facilitate decisions and remediation tracking.
  • Maintain documentation integrity and traceability across governance elements.
  • Incident, Change & Continuity Governance
  • Integrate governance with Incident Response, BCP/DR, and Change Management.
  • Review root cause analyses (RCA) and drive systemic improvements.
  • People Leadership & Operating Model
  • Lead a small team or governance champions network; provide coaching and quality reviews.
  • Foster a service‑oriented culture with clear SLAs and efficient intake processes.
Qualifications
  • 600+ years in information security, risk, audit, or GRC; 3+ years in governance leadership.
  • Deep understanding of ISO 27001, SOC 2, PCI DSS, NIST CSF/800-53, and privacy regulations.
  • Proven experience in policy frameworks, risk registers, and control assurance.
  • Strong communication, stakeholder management, and documentation skills.
Preferred
  • Certifications: ISO 27001 LI/LA, CISA, CISM, CRISC, CISSP, PCIP/ISA, ITIL.
  • Experience in BPO, fintech, or regulated industries.
  • Familiarity with cloud governance (AWS/Azure/GCP) and SaaS environments.
Tools & Technologies
  • GRC/IRM: ServiceNow GRC, Archer, OneTrust, Drata, Tugboat.
  • Collaboration: SharePoint, Confluence, Jira, ServiceNow.
  • Security Ops Interface: SIEM tools.
Seniority level

Executive

Employment type

Full‑time

Job function

Information Technology

Industries

Outsourcing and Offshoring, Consulting, Telephone Call Centers

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance and Information Security Analyst
Governance and Information Security Analyst

InnovaThink Corporation • Metro Manila

On-site
PHP 800,000 - 1,200,000
Cyber Governance, Risk and Compliance Specialist
Cyber Governance, Risk and Compliance Specialist

Virtual Business Partners Pty. Ltd. • Cebu City

On-site
PHP 800,000 - 1,200,000
HMO + Dental/Optical
Christmas vacation
Electricity & Data subsidies
+3
Cyber Security Compliance Officer
Cyber Security Compliance Officer

PJ Lhuillier Group of Companies • Makati

Hybrid
PHP 900,000 - 1,300,000
Security Governance Specialist for Service Lines
Security Governance Specialist for Service Lines

CBTW APAC • Manila

On-site
Head of Security GRC (Governance, Risk & Compliance)
Head of Security GRC (Governance, Risk & Compliance)

Capacita Human Resource Management Consultancy • Philippines

On-site
PHP 1,800,000 - 3,500,000
Security Delivery Governance Specialist
Security Delivery Governance Specialist

CBTW APAC • Manila

On-site
Head of Information Security & Enterprise Risk Management
Head of Information Security & Enterprise Risk Management

Corporate Technologies Inc • Manila

On-site
PHP 3,500,000 - 7,500,000
Security GRC Supervisor
Security GRC Supervisor

Aboitiz Power • Makati

On-site
PHP 1,200,000 - 1,800,000
Cyber Security & Compliance Director
Cyber Security & Compliance Director

ContactPoint360 • Cebu City

On-site
PHP 3,000,000 - 5,400,000
Specialist - Governance Risk and Compliance
Specialist - Governance Risk and Compliance

Concentrix • Morong

On-site
PHP 600,000 - 1,000,000