We’re Hiring: Data Protection Officer & Cyber Security Lead
Looking for a role that fosters collaboration, creativity and career growth in a vibrant office environment? We got you covered! Join our team at Cloudstaff, the #1 workplace everywhere! Think you qualify for the role?
Role: Data Protection Officer & Cyber Security Lead
Work Arrangement: Work from Office
Location: Philippines - Makati/Ortigas/Pampanga/Cebu
Schedule: Any shift - Morning/Mid/Night
Job Description
Purpose of the role
- The organization provides surgical and non-surgical medical aesthetic treatments through a growing network of clinics. Its patients include high-profile individuals and international patients.
- This role has two accountabilities: data protection and cyber security. You are the Data Protection Officer and the accountable lead for cyber security. Both accountabilities protect the same assets: patient health and treatment data, patient confidentiality, and the clinical and business systems that the clinics depend on.
- The role covers operation and assurance. You do the work, and you check that controls and processes work as intended.
Regulatory commitment
- The organization complies with the Data Privacy Act of 2012, its Implementing Rules and Regulations and issuances of the National Privacy Commission. This covers DPO designation, registration of data processing systems, security of personal data and personal data breach management. You are accountable for maintaining this compliance.
- As in the rest of the business, the organization leads rather than lags. You will go beyond minimum compliance and set the standard for data protection and cyber security in medical aesthetics in the Philippines.
Accountability 1: Data protection
- DPO registration and the registration of all data processing systems with the NPC are complete and current. You are the contact point for data subjects and the NPC.
- The record of processing activities is accurate, including systems, data flows and where data is hosted. Transfers of personal data outside the Philippines are controlled.
- New and changed systems, services, suppliers and clinics are assessed through Privacy Impact Assessments and built with privacy by design.
- Every processing activity has a lawful basis, a clear purpose, valid consent where required, and uses only the data it needs.
- Data subject requests and complaints are handled from receipt to closure within the required timeframes.
- Third parties that process personal data are covered by suitable data sharing or outsourcing agreements and comply before and during the contract.
- Personal data breaches are assessed, notification decisions are made, and reports reach the NPC and affected data subjects within the required timeframes.
- The privacy manual, privacy notices, retention rules and policies are current. Compliance is monitored and audited, corrective actions are closed, staff are trained, and Compliance Officers for Privacy are supervised where appointed.
Accountability 2: Cyber security
- Cyber security risk is known, assessed and treated through the cyber risk register and the security roadmap.
- Security policies and standards are current and aligned to a recognised framework such as ISO/IEC 27001 or the NIST Cybersecurity Framework. The information asset register is complete.
- Systems, cloud, network, endpoints, email, backup and logging meet the organisation's security requirements, including new systems, major changes and new clinics before go-live.
- Access to systems and data is controlled, including privileged access, joiners, movers and leavers, and regular access reviews.
- Vulnerabilities are controlled through patching, vulnerability assessments and penetration tests, with remediation tracked to closure.
- Security incidents are detected, contained and recovered from quickly, using tested response plans, so that clinical and business systems stay available.
- Suppliers meet the organisation's security requirements before contract, in contract terms and at each review.
- Security controls are tested to confirm they work as intended, and staff security awareness is built through training and phishing exercises.
Operating model
- Data protection
- You lead data protection directly. You work with business owners, IT and legal counsel, and supervise Compliance Officers for Privacy where appointed.
- Cyber security
- The organization has a strategic engagement with a qualified third party that provides cyber security resources, expertise and oversight. In the long term, this engagement will provide around 50% of cyber security resources. In the interim, additional cyber security capacity is likely to be agentic. You remain accountable for cyber security and work with the third party and IT.
- Ways of working
- Across both accountabilities, you improve processes and apply AI-enabled tools and automation where they add value.
- Reporting
- You report on data protection and cyber security risk and performance to the Office of the CEO, and on cyber security operations to IT.
- Growth and learning
- The medical aesthetics field is growing, and the organization is growing with it. You will learn and grow with the business.
- AI brings new challenges for both data protection and cyber security. You will build capability in this area and keep a good understanding of new technology trends. Beginning to understand medical technology would be very helpful.
Qualifications and requirements
Desirable
- Healthcare industry experience.
- Cyber security responsibility in a previous role.
Education
- A bachelor’s degree in information technology, computer science, computer engineering or a related field.
Soft skills
- Customer service: you are helpful and respond quickly to clinic staff and colleagues.
- Communication: you speak and write clearly, and explain technical issues in simple language.
- Teamwork: you work well with people from different teams and backgrounds, and share information.
- Tact and courtesy: you stay calm and polite, especially when staff are under pressure.
- Initiative: you plan and do your work without detailed instructions, and suggest improvements.
- Organization: you manage several tasks at once and set the right priorities.
- Flexibility: you are open to change and adjust quickly when the business needs it.
Non-negotiable skills and requirements
- At least 10 years' working experience in a regulated industry.
- Experience in a role where you were accountable for data protection. You can give examples of compliance you maintained, assessments you led, and breaches or requests you handled.
- A recognised data protection qualification, for example NPC DPO ACE, IAPP CIPP/A, CIPM or CIPT.
- You can apply the Data Privacy Act of 2012, its IRR and NPC issuances to practical cases.
- You can explain common cyber security controls and how you would respond to a security incident.
- You can show hands‑on work you did yourself, not only work you managed. This is not a hands‑off role.
- You can give examples of explaining data protection and cyber security risk to business executives and influencing their decisions.
- You can give examples of using AI tools, automation or AI-enabled processes to improve and operate processes.
Perks & Benefits (Work From Office/Hybrid)
- Comprehensive health and life insurance on your 16th day of employment, covering 1 free dependent on the 16th day of employment
- Up to 24 leave credits per year
- Flexible leave credits which may be used for vacation, emergency and sick leaves
- Endless opportunities for career advancement
- Exclusive ATM inside the office for employee's convenience
- Annual Performance Review with Salary Increase
- We set you up for success with a company-provided PC/Laptop and fiber internet connection
- Look forward to weekly office perks for work from office staff – Free Coffee, Meals and Beer Fridays!
- Top notch workplace with first class VIP lounge and game rooms
- Child friendly spaces to cater to the needs of employees with children, enhancing work-life balance
- Participate and join our CS Social Clubs and Special Interest Groups to connect with colleagues
- Mental Wellness Employee Assistance program through Lifeworks
- In-house psychiatrist available to support employees' well-being
- Become part of the Employee Share Units program
- Cloudstaff Dream Points - To be used for bidding useful items like appliances, kitchenettes etc.
Cloudstaff : Build Your Career, Anywhere
Established in 2005, Cloudstaff is a leading outsourcing company that empowers businesses to thrive through smarter talent solutions. We're passionate about creating a work environment that fosters your professional growth and overall well-being.
Why Cloudstaff is the #1 Workplace
- Award-winning Culture: We're committed to building the #1 Workplace Everywhere, with a proven track record of staff engagement initiatives and industry recognition
- Invest in You: We support your development through comprehensive training programs, mentoring and opportunities for career advancement
- Thrive as an Individual: We offer a strong work-life balance with flexible schedules, meaningful perks and a collaborative team environment.