Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development.
With Metrobank, a meaningful life is within your reach!
Security Governance Officer Serve as a key contributor to the Bank's information security governance framework by formulating and implementing security policies, ensuring alignment with regulatory and business requirements, monitoring the delivery of security initiatives, and championing security awareness programs that foster a culture of cybersecurity across the organization.
Key Responsibilities
- Develop, review, and recommend information security policies, standards, and procedures to support the Bank's information security objectives and regulatory requirements.
- Identify and address policy gaps related to physical security, environmental security, personnel security, business continuity, and secure software development lifecycle (SDLC) practices.
- Design, implement, and continuously enhance the Bank's Information Security Awareness, Training, and Advocacy Program, ensuring employees are informed of emerging threats, industry best practices, security standards, and regulatory advisories.
- Create and manage security awareness materials and content for publication and organization-wide communication.
- Evaluate the effectiveness of security awareness initiatives, analyze program results, and recommend improvements to strengthen employee security knowledge and engagement.
- Collaborate with business units and support functions to ensure alignment with information security governance, risk management, and compliance requirements.
- Serve as the primary liaison for information security-related regulatory and compliance requirements, including those mandated by regulatory bodies such as the BSP.
- Monitor and track the progress of departmental plans, programs, and strategic initiatives to ensure timely and successful execution.
- Partner with Information Security teams and stakeholders to facilitate the timely remediation and closure of audit findings, compliance gaps, and security-related issues.
- Support the Department Head in overseeing the delivery of key initiatives, monitoring milestones, and ensuring the completion of assigned tasks and deliverables.
- Provide guidance and support on information security governance, risk, compliance, and policy-related matters across the organization.
- Perform other information security governance and compliance responsibilities as assigned by the Department Head.
Qualifications
- Experience in Information Security Governance, Risk Management, Compliance, Audit, and Policy Management.
- Strong knowledge of security frameworks, risk assessment, and regulatory requirements (BSP, DPA, PCI-DSS, etc.).
- Familiarity with banking operations, IT processes, access controls, data security, and risk management practices.
- Proven experience in designing and implementing security awareness, training, and advocacy programs.
- Excellent analytical, problem-solving, project management, and stakeholder management skills.
- Strong written and verbal communication skills, with the ability to explain complex security concepts to both technical and non-technical audiences.
- Relevant certifications such as CISM, CRISC, or equivalent are preferred.
- Proficient in Microsoft Office tools, including Word, Excel, PowerPoint, and Project.
- Self-motivated, detail-oriented, and able to manage multiple priorities in a fast-paced environment.