Director Information Security Risk Management

Optum Philippines

Philippines

On-site

PHP 2,500,000 - 4,200,000

Full time

34 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Optum Philippines is seeking a senior information security risk & governance leader to drive an enterprise-wide risk framework. The role partners with business and security teams to enable risk-aware decisions and enforce controls across global offices.

The successful candidate will report to senior security leadership and collaborate to balance risk, regulatory needs and business priorities in a dynamic, multi-geography environment.

Qualifications

  • Bachelor's degree.
  • 13+ years of mix of experience in Information Security Risk & Governance.
  • Exposure to Cloud-based applications/security governance.
  • Experience with senior business stakeholders.
  • Balance between business stakeholders and Enterprise Security (ESRO).
  • Solid understanding of Information Risk Management, compliance and governance.
  • Broad understanding of security technology and operating principles.
  • Ability to navigate a matrix organization and collaborate with multiple stakeholders.

Responsibilities

  • Design, manage and deliver an Information Risk Governance framework.
  • Collaborate with Cybersecurity Governance, Risk, and Compliance to map controls.
  • Lead lean improvements and data-driven decision making.
  • Oversee alignment of security services with business processes.
  • Advise stakeholders on controls and risk mitigation.
  • Document and communicate processes for international audiences.
  • Manage divisional security incidents and security initiatives.

Skills

Information governance
Risk management
Cloud security
Security architecture
Stakeholder management

Education

Bachelor's degree

Tools

SIEM tools
GRC tools
Cloud platforms

Job description

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.

As BISO, you will be a key member of the Enterprise Security Office; leading a team responsible for overall security governance in global offices. This role will be the focal point for effective engagement between business areas and the Enterprise Security office. This role will be a trusted adviser to senior business and technology stakeholders and provide broad knowledge of security strategies, policies, processes, architecture, and road maps to enable divisions/business to understand and meet security requirements.

The successful candidate will be reporting to the VP & CISO in India and work closely with the business, supporting to operate within information security risk appetite across the enterprise. This role will be an essential business partner and will take responsibility for the assessing and managing information security risk for the business.

Primary Responsibilities
  • Key expectations:
    • Design, manage and deliver an Information Risk Governance framework to ensure proper enforcement of enterprise security, collaborating with Global Cybersecurity Governance, Risk, and Compliance to develop a library of security controls that map industry and company standards to operational procedures, and accurately measures control effectiveness
    • Continuously improves end outcomes by defining, measuring, and optimizing end-to-end value streams utilizing Lean practices and leveraging data to make decisions
    • Leads aligned team in adopting effective agile practices and partners closely with ESRO and other Enterprise teams to govern technical solutions that most effectively enable the business processes
    • Initiates and fosters relationships with stakeholders across Technology Group and our business units that promote trust and increase responsiveness; balances individual stakeholder needs with business priorities assuring alignment with Global Cybersecurity strategies and objectives related to Information Risk Management
  • Functional Attributes:
    • Build and maintain effective relationship with division's Business and Technology stakeholders. Be the voice of ESRO in the division/business area and the voice of the business within ESRO
    • Raise the profile of security within the organization by being pro-actively engaged with stakeholders and customers
    • Align information security responsibilities and working practices of ESRO and security teams Identify and resolve risks and issues
    • Facilitate planning, introduction, delivery of information security services and initiatives e.g. security capability / maturity improvement
    • Delivery of point services such as Compliance assessments (ISMS, HITRUST, Project risk assessments, Vendor assessments or any other compliances required for the local geography etc.)
    • Collate demand for security and collaborate across the security team to balance supply and demand of security resources
    • Contribution to development and implementation of security architecture, and the design of security service and processes as appropriate
    • Ensure that policy compliance is appropriate to the organization's level of risk acceptance
    • Demonstrate to stakeholders that appropriate security controls are in place and own/create actions plans to manage improvement or change where necessary
    • Advise stakeholders on how to achieve the relevant controls and assist with solutions to support them
    • Where necessary ensure that processes are documented and communicated in language that is relevant and understandable to international and /or non-technical audiences
    • Support and deliver security initiatives as needed and be able to demonstrate and track progress to stakeholders
    • Manage divisional security incidents, working closely with group and divisional stakeholders
    • Any other duties relating to the remit of a role of this standing as required by the needs of the business
  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
Required Qualifications
  • Bachelor's degree
  • 13+ years of mix of experience in Information Security Risk & Governance
  • Exposure to Cloud-based applications/security governance
  • Working with senior business stakeholders
  • Experience in a role balanced between business stakeholders and Enterprise Security (ESRO)
  • Solid understanding of Information Risk Management, compliance and security governance
  • Technical: Broad understanding of security technology
  • Business: High level understanding of utility/energy sector business model, service offerings, and business operating environment as it pertains to the firm's threat landscape Ability to frame threats and exposures in a business context recognized by non-technical staff and executives
  • Domain landscape: Knowledge of technical security operating principles
  • Demonstrated ability in navigating a multifaceted, matrix organization; and
  • Demonstrated ability in collaborating with multiple stakeholders across functional and technical skillsets
  • Proven analytical: Inquisitive nature and intuition regarding what questions to ask, when, and their relative significance
  • Communication: Demonstrated ability to leverage business communication skills to inform, persuade, and teach stakeholders across a global network of member firms' staff and leadership to enable effective information security activities and processes in line with the cyber readiness program
Preferred Qualifications
  • Hands-on in designing policies, procedures and standards, Risk Assessment etc.
  • Experience working successfully in a high matrix organization
  • In-depth understanding of competitor, financials and industry dynamics
  • Proven solid analytical, problem solving and decision-making skills
  • Demonstrated ability to work collaboratively in a global team with a positive team spirit

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.

Optum is a drug-free workplace. © 2026 Optum Global Solutions (Philippines) Inc. All rights reserved.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Risk Analyst
Senior Information Security Risk Analyst

Optum Philippines • Manila

On-site
PHP 600,000 - 1,000,000
Director Information Security
Director Information Security

Optum Philippines • Philippines

On-site
PHP 1,800,000 - 2,400,000
Information Security Engineer Analyst
Information Security Engineer Analyst

Optum Philippines • Muntinlupa

On-site
PHP 480,000 - 720,000
Senior Info Security Risk Analyst - NCR and Cebu
Senior Info Security Risk Analyst - NCR and Cebu

Optum • Cebu City

On-site
PHP 1,200,000 - 2,100,000
Patient Scheduling Advocate with BPO Experience | Medical Allied | Alabang
Patient Scheduling Advocate with BPO Experience | Medical Allied | Alabang

Optum • Metro Manila

Hybrid
PHP 900,000 - 1,300,000
Hybrid
Laptop Provided
Medical Plan
+11
CSOC Manager - Country Security Operations Center - Quezon City
CSOC Manager - Country Security Operations Center - Quezon City

Optum Philippines • Manila

On-site
PHP 1,800,000 - 3,200,000
Information Security Engineer Analyst - SOC Analyst
Information Security Engineer Analyst - SOC Analyst

Optum Philippines • Muntinlupa

On-site
PHP 300,000 - 520,000
Global Head, Information Security & Risk Governance
Global Head, Information Security & Risk Governance

Optum Philippines • Philippines

On-site
PHP 1,800,000 - 2,400,000
Director, Information Risk & Security Governance
Director, Information Risk & Security Governance

Optum Philippines • Philippines

On-site
PHP 2,500,000 - 4,200,000
CSOC Manager - Country Security Operations Center - Quezon City
CSOC Manager - Country Security Operations Center - Quezon City

Optum • Philippines

On-site
PHP 2,200,000 - 3,800,000