Information Security Manager (M6)

TerraBarn Inc

Makati

Hybrid

PHP 1,500,000 - 2,300,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

TerraBarn Inc. seeks an experienced Information Security Manager to lead security strategy, governance, risk, incident response, and operations from its Makati base.

You will strengthen the security posture, ensure compliance with standards, monitor threats, and drive initiatives protecting information, systems, and assets; collaborate with senior management, IT, vendors, and business units.

Qualifications

  • Bachelor’s degree in Information Technology, Computer Science, Business Management, or related field.
  • 7–10 years in Information Security, IT Risk Management, or cybersecurity roles.
  • Proven ability to develop and implement security policies, standards, controls.
  • Hands-on experience with vulnerability assessment, pen testing, patch mgmt, encryption, monitoring, incident response.
  • Familiarity with ISO/IEC 27001 and NIST frameworks; disaster recovery experience advantageous.
  • Strong leadership, communication, and cross-functional collaboration skills.

Responsibilities

  • Develop and implement the organization’s information security strategy, policies, standards, and procedures.
  • Ensure local security initiatives align with Group standards and plans.
  • Monitor emerging cybersecurity threats and assess business impact.
  • Lead incident detection, response, investigation, and recovery activities.
  • Conduct root-cause analysis and implement corrective measures after incidents.
  • Promote information security awareness across the organization, including senior management.
  • Identify security risks for new projects and third-party providers; implement controls.
  • Implement controls including endpoint protection, patch management, vulnerability assessment, encryption.
  • Support disaster recovery, crisis management, and security-related business continuity.
  • Establish safeguards against fraud and other security risks; manage information security team.

Skills

Security strategy
Policy development
Incident response
Leadership
Vendor management
Cloud security
CISSP/CISM

Education

Bachelor’s degree in IT/CS/Business

Tools

Vulnerability Scanning
Penetration Testing
Encryption technologies
Security Monitoring

Job description

We are looking for an experienced Information Security Manager to lead the organization’s information security strategy, governance, risk management, incident response, and security operations.

The role will be responsible for strengthening the company’s security posture, ensuring compliance with security standards, monitoring emerging threats, and leading initiatives that protect company information, systems, and assets.

Key Responsibilities
  • Develop and implement the organization’s information security strategy, policies, standards, and procedures.

  • Ensure local security initiatives are aligned with Group security standards and strategic plans.

  • Monitor emerging cybersecurity threats and assess their potential business impact.

  • Lead the organization’s security incident detection, response, investigation, and recovery activities.

  • Conduct root‑cause analysis and implement corrective and preventive measures following security incidents.

  • Promote information security awareness and training across the organization, including senior management and the Board.

  • Identify and assess security risks associated with new projects, systems, initiatives, and third‑party providers.

  • Ensure appropriate security controls are implemented, including endpoint protection, patch management, vulnerability assessment, penetration testing, and encryption.

  • Support disaster recovery, crisis management, and security‑related business continuity activities.

  • Establish safeguards against fraud and other activities that may expose the organization to security risks.

  • Manage and develop the Information Security team, including performance management, coaching, training, and succession planning.

  • Work closely with business units, IT, senior management, vendors, and other stakeholders on security‑related matters.

  • Prepare and present security updates, risks, incidents, and recommendations to senior management.

  • Manage security vendors, contracts, and managed service providers.

  • Perform other security‑related projects and responsibilities as assigned.

Qualifications
  • Bachelor’s degree in Information Technology, Computer Science, Business Management, or a related field.

  • 7–10 years of experience in Information Security, IT Risk Management, Cybersecurity, or related IT functions.

  • Proven experience in developing and implementing security policies, standards, procedures, and controls.

  • Hands‑on experience with security measures such as:

    • Vulnerability Assessment

    • Penetration Testing

    • Patch Management

    • Endpoint / Antivirus Security

    • Encryption

    • Security Monitoring

    • Incident Response

  • Strong knowledge of information security frameworks such as ISO/IEC 27001 and NIST.

  • Knowledge of disaster recovery, computer forensics, and security incident management.

  • Strong leadership, communication, analytical, and problem‑solving skills.

  • Experience leading cross‑functional and interdisciplinary teams.

  • Experience in vendor management, contract negotiation, and managed security services.

  • Experience with cloud computing and virtualized environments is an advantage.

  • Experience in the insurance or HMO industry is an advantage.

  • Strong integrity and ability to handle confidential information.

  • Experience presenting security matters to C‑level executives or senior management is an advantage.

Preferred Certifications
  • CISSP – Certified Information Systems Security Professional

  • CISM – Certified Information Security Manager

  • CompTIA Security+

  • CompTIA CASP+

Why Join Us?

Join a team where you can lead enterprise information security initiatives, strengthen cybersecurity governance, and contribute directly to protecting critical business information and technology assets.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

InLife Benefits Insurance Company, Inc. • Makati

On-site
PHP 1,800,000 - 2,700,000
Information Security & Compliance Senior Specialist
Information Security & Compliance Senior Specialist

CITADEL PACIFIC, LTD. - ROHQ • Taguig

On-site
PHP 600,000 - 900,000
Information Security Project Manager
Information Security Project Manager

Maya • Mandaluyong

On-site
PHP 900,000 - 1,300,000
IT Information Security Manager
IT Information Security Manager

Manila Water Philippine Ventures • Philippines

On-site
PHP 1,200,000 - 1,800,000
Information Security Analyst Subject Matter Expert (SME) - Project-based
Information Security Analyst Subject Matter Expert (SME) - Project-based

Umpisa Inc. • Philippines

On-site
PHP 1,200,000 - 2,400,000
IT Security and Compliance Manager
IT Security and Compliance Manager

Hammerjack Pty Ltd • Quezon City

On-site
PHP 1,200,000 - 2,100,000
Information Security Manager
Information Security Manager

Dempsey Resource Management Inc. • Makati

On-site
PHP 558,000 - 1,116,000
Information Security & Compliance Lead
Information Security & Compliance Lead

Asticom Technology Inc • Taguig

Hybrid
PHP 2,500,000 - 4,000,000
Information Security Analyst Subject Matter Expert (SME) - Project-based
Information Security Analyst Subject Matter Expert (SME) - Project-based

Umpisa Inc. • Hinoba-an

On-site
PHP 700,000 - 1,200,000
Security Architect
Security Architect

Metropolitan Bank & Trust Company • Metro Manila

On-site
PHP 1,400,000 - 2,400,000