Job Description:
Information Security Specialist
Location:
Taguig City, Metro Manila, Philippines
Secure Our Business. Protect Our Future.
We are seeking an experienced and highly motivated Information Security Specialist to join our global IT team. This role plays a critical part in strengthening our cybersecurity governance framework, supporting security risk management activities, ensuring compliance with international standards, and safeguarding our organization's digital assets.
As a key member of the Information Security function, you will work closely with global stakeholders, IT teams, business leaders, and external auditors to drive security compliance, risk remediation, audit readiness, and security awareness initiatives across the organization.
Key Responsibilities
- Monitor and report on the effectiveness of global information security controls and elevate identified issues.
- Coordinate and track remediation activities for vulnerabilities, audit findings, compliance gaps, and security risks.
- Support and coordinate internal and external security audits, including evidence gathering and follow-up action management.
- Operate and maintain the Information Security Management System (ISMS), including ISO 27001-related activities.
- Monitor compliance with information security policies, standards, regulatory requirements, and contractual obligations.
- Analyze threat intelligence and provide actionable security insights to stakeholders.
- Conduct security risk assessments and monitor risk treatment plans through completion.
- Support mergers, acquisitions, and other business initiatives through security due diligence and assessments.
- Develop and deliver security awareness programs and promote cybersecurity best practices across the organization.
Qualifications
Education
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related field.
Experience
- Minimum of 3 years' experience in Information Security, Cybersecurity, IT Risk Management, or related disciplines.
- Experience supporting security audits, regulatory compliance, and risk management initiatives.
- Hands-on experience with security control monitoring, ISMS operations, and cybersecurity governance activities.
- Background working in multinational or global environments is highly preferred.
Certifications
Candidates with one or more of the following certifications are highly encouraged to apply:
- CISSP
- CISM
- CISA
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
Required Knowledge & Skills
- Strong knowledge of information security frameworks such as ISO 27001, NIST, and CIS Controls.
- Understanding of regulatory and compliance requirements, including GDPR, NIS2, SOX, and data privacy regulations.
- Experience with information security risk management, threat intelligence, and security governance.
- Strong analytical, organizational, and problem-solving skills.
- Excellent communication and stakeholder management capabilities.
- Ability to communicate effectively with both technical and non-technical audiences.
- English proficiency is a must
- Experience using governance, risk, compliance, and reporting tools is an advantage.
Why Join Us?
- Opportunity to work in a global organization with international exposure.
- Collaborate with security leaders and stakeholders across multiple regions.
- Drive meaningful cybersecurity initiatives that directly impact business resilience.
- Professional development, training, and certification opportunities.
- Competitive compensation and benefits package.
We appreciate all applications; however, only shortlisted candidates will be contacted.