Turn this role into an interview — a resume and cover letter built around what this employer wants.
TerraBarn Inc. seeks an experienced Information Security Manager to lead security strategy, governance, risk, incident response, and operations from its Makati base.
You will strengthen the security posture, ensure compliance with standards, monitor threats, and drive initiatives protecting information, systems, and assets; collaborate with senior management, IT, vendors, and business units.
We are looking for an experienced Information Security Manager to lead the organization’s information security strategy, governance, risk management, incident response, and security operations.
The role will be responsible for strengthening the company’s security posture, ensuring compliance with security standards, monitoring emerging threats, and leading initiatives that protect company information, systems, and assets.
Develop and implement the organization’s information security strategy, policies, standards, and procedures.
Ensure local security initiatives are aligned with Group security standards and strategic plans.
Monitor emerging cybersecurity threats and assess their potential business impact.
Lead the organization’s security incident detection, response, investigation, and recovery activities.
Conduct root‑cause analysis and implement corrective and preventive measures following security incidents.
Promote information security awareness and training across the organization, including senior management and the Board.
Identify and assess security risks associated with new projects, systems, initiatives, and third‑party providers.
Ensure appropriate security controls are implemented, including endpoint protection, patch management, vulnerability assessment, penetration testing, and encryption.
Support disaster recovery, crisis management, and security‑related business continuity activities.
Establish safeguards against fraud and other activities that may expose the organization to security risks.
Manage and develop the Information Security team, including performance management, coaching, training, and succession planning.
Work closely with business units, IT, senior management, vendors, and other stakeholders on security‑related matters.
Prepare and present security updates, risks, incidents, and recommendations to senior management.
Manage security vendors, contracts, and managed service providers.
Perform other security‑related projects and responsibilities as assigned.
Bachelor’s degree in Information Technology, Computer Science, Business Management, or a related field.
7–10 years of experience in Information Security, IT Risk Management, Cybersecurity, or related IT functions.
Proven experience in developing and implementing security policies, standards, procedures, and controls.
Hands‑on experience with security measures such as:
Vulnerability Assessment
Penetration Testing
Patch Management
Endpoint / Antivirus Security
Encryption
Security Monitoring
Incident Response
Strong knowledge of information security frameworks such as ISO/IEC 27001 and NIST.
Knowledge of disaster recovery, computer forensics, and security incident management.
Strong leadership, communication, analytical, and problem‑solving skills.
Experience leading cross‑functional and interdisciplinary teams.
Experience in vendor management, contract negotiation, and managed security services.
Experience with cloud computing and virtualized environments is an advantage.
Experience in the insurance or HMO industry is an advantage.
Strong integrity and ability to handle confidential information.
Experience presenting security matters to C‑level executives or senior management is an advantage.
CISSP – Certified Information Systems Security Professional
CISM – Certified Information Security Manager
CompTIA Security+
CompTIA CASP+
Join a team where you can lead enterprise information security initiatives, strengthen cybersecurity governance, and contribute directly to protecting critical business information and technology assets.