Cybersecurity Architect

ORIX METRO Leasing and Finance

Makati

On-site

PHP 1,200,000 - 1,800,000

Full time

23 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

ORIX METRO Leasing and Finance seeks a Cybersecurity Architect to design and govern enterprise security architecture across on-prem, cloud, network, identity, and applications. You will lead MSOC technical oversight and align controls with ISO 27001:2022, NIST, BSP frameworks.

You will mentor ISD staff, drive risk assessments, review cloud configs, and ensure secure design across IT projects. The role requires 5–7 years in security architecture and relevant certifications such as CCNA, OSCP, or

Qualifications

  • Graduate degree in IT or computer science or equivalent.
  • 5–7 years of related work experience in security architecture.
  • Knowledge of ISO 27001, NIST, BSP frameworks and security controls.
  • CCNA, OSCP, CISSP certifications preferred.

Responsibilities

  • Design, document, and govern enterprise security architecture across domains.
  • Provide technical oversight to MSOC and validate detections.
  • Coordinate remediation with ITG for MSOC findings and gaps.
  • Develop incident response playbooks and escalation workflows.
  • Perform architecture risk assessments for systems and changes.
  • Review cloud configurations, identity governance, and controls.
  • Mentor ISD personnel and collaborate with business units.

Skills

Enterprise security architecture
Azure & cloud security
Network security
Windows & Linux security
SIEM / EDR / SOAR
Forensic investigations
Regulatory & standards mapping
Threat detection engineering

Education

BS Information Technology or Computer Science

Tools

Azure
AWS
GCP

Job description

The Cybersecurity Architect is responsible for designing and governing the organization’s security architecture across infrastructure, applications, cloud platforms, and identity environments.

The role provides technical leadership to the Managed Security Operations Center (MSOC), validates monitoring outputs, oversees remediation with ITG, and ensures that security controls are effectively implemented and aligned with ISO 27001:2022, NIST, and BSP regulatory frameworks.

The Architect serves as the technical arm of the Information Security Office, driving security engineering, technical governance, and architectural maturity across the enterprise.

  • Expertise in designing, validating, and governing enterprise security architecture across on-premises, cloud, network, identity, and application domains.
  • Strong knowledge of Azure, AWS, and Google Cloud security controls, baselines, and architecture best practices.
  • Network & Infrastructure Security – Deep understanding of network protocols (TCP/IP, DNS, HTTP/S), firewalls, WAF, VPN/SD-WAN, network segmentation, and Zero-Trust design.
  • Proficiency in Windows, Linux, Microsoft Defender, Intune, Entra ID, Conditional Access, MFA, PIM/JIT, and endpoint hardening.
  • Familiarity with SIEM, EDR, SOAR, IDS/IPS, MITRE ATT&CK, Cyber Kill Chain, and detection engineering.
  • Experience leading technical investigations, RCA, containment, recovery, and forensic evidence handling.
  • Knowledge of VMDR tools, CIS Benchmarks, misconfiguration analysis, and patch governance.
  • Ability to map technical risks to ISO 27001, NIST 800-53/CSF, and BSP requirements.
  • Knowledgeable in ISO/IEC 27001:2022, NIST 800-53, NIST CSF 2.0, BSP Circular 808, BSP Circular 982, and MORNBFI.
  • Security Documentation & Reporting – Ability to develop diagrams, standards, runbooks, and audit-ready evidence.

Job Responsibilities:

  • Design, document, and maintain the enterprise security architecture across network, cloud, identity, endpoint, and application domains.
  • Establish security baselines, hardening guides, and secure configuration standards for servers, endpoints, and cloud services.
  • Provide technical oversight to MSOC, validate detections, and ensure high-quality investigations.
  • Coordinate with ITG for remediation of MSOC findings, vulnerabilities, and configuration gaps.
  • Develop and enhance incident response playbooks, forensic procedures, and escalation workflows.
  • Lead technical root cause analysis for major incidents and recurring vulnerabilities.
  • Conduct architecture and technical risk assessments for systems, applications, and infrastructure changes.
  • Perform reviews of cloud configurations, identity governance, network segmentation, endpoint protection, and application controls.
  • Review technical controls in IT and business projects for compliance with Information Security Standards and ISD-approved MBSS.
  • Oversee vulnerability management for governance, validate findings, and prioritize remediation.
  • Maintain security documentation including diagrams, standards, runbooks, and audit evidence.
  • Provide technical expertise during internal/external audits and regulatory reviews.
  • Monitor emerging threats and recommend improvements to the organization’s security posture.
  • Mentor ISD personnel and provide technical guidance across the department.
  • Collaborate with ITG and business units to ensure the secure design, implementation, and operation of systems. Perform other duties that maybe assigned by the Head of Information Security Department

Qualifications:

  • Graduate of BS Information Technology, Computer Science or any 4-years business course or equivalent.
  • At least 5 to 7 years related work experience
  • Knowledgeable in Networking protocols as such as TCP/IP, DNS, https, and network devices (routers, switches, firewalls)
  • Preferably with certification in CCNA, OSCP, CISSP
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Architect
Cybersecurity Architect

ORIX METRO Leasing and Finance Corporation • Philippines

On-site
PHP 1,800,000 - 3,600,000
Information Security Architect (Hybrid)
Information Security Architect (Hybrid)

blaseek • Manila

On-site
Security Architect
Security Architect

Metrobank • Taguig

On-site
PHP 1,800,000 - 3,200,000
Senior Network Security Design Engineer
Senior Network Security Design Engineer

PM Consulting • Philippines

On-site
PHP 1,200,000 - 2,000,000
Security Architect Lead
Security Architect Lead

City Savings Bank • Pasig

On-site
PHP 2,500,000 - 4,000,000
Cloud Security Architect (Hybrid)
Cloud Security Architect (Hybrid)

blaseek • Metro Manila

On-site
PHP 1,200,000 - 2,000,000
Senior Security Consultant
Senior Security Consultant

Hunter's Hub Inc. • Taguig

On-site
IT Cybersecurity Administrator
IT Cybersecurity Administrator

Navitas Semiconductor • Muntinlupa

On-site
PHP 700,000 - 1,100,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Santo Niño 1st

On-site
PHP 1,200,000 - 1,800,000
Security Architect
Security Architect

Metrobank • Metro Manila

On-site
PHP 1,500,000 - 2,100,000