IT & Compliance Manager

BullSwipe

Makati

On-site

PHP 2,400,000 - 3,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BullSwipe seeks a senior security and compliance leader to own the certification program across ISO 27001, SOC 2, GDPR, and PCI DSS. You will coordinate gap assessments, remediation, and evidence management while interfacing with QSAs and auditors.

You will drive a culture of continuous compliance, automate evidence collection, and align with evolving standards to protect payment services and customer data in a fast-paced fintech environment.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field.
  • 5–8 years of progressive experience in IT, cybersecurity, or information security roles.
  • At least 2–3 years in a compliance, security management, or audit-facing capacity — ideally within fintech/payments.

Responsibilities

  • Own and drive the end-to-end certification roadmap for ISO 27001, SOC 2, GDPR accountability, and PCI DSS Level 1.
  • Conduct gap assessments, identify missing controls, and lead remediation prior to audits.
  • Build and maintain evidence library, risk register, and control mapping across frameworks.
  • Engage QSAs and external auditors for PCI DSS and ISO/SOC examinations.
  • Act as liaison with auditors, certification bodies, and regulators throughout cycles.
  • Embed continuous compliance with automated evidence collection and policy-as-code.
  • Stay aligned with updates (PCI DSS 4.0, ISO 27001:2022) and adjust programs.

Skills

ISO 27001
SOC 2
PCI DSS
GDPR
Cloud security
Zero-trust
Audits & QSA
Vendor management
IAM
EDR

Education

Bachelor's degree in Computer Science, Information Systems, Cybersecurity

Tools

Okta
Microsoft Entra ID
Bitwarden
Jamf Pro
Intune
Splunk
Microsoft Sentinel
Datadog

Job description

  • Own and drive the end-to-end certification roadmap for ISO 27001, SOC 2 Type II, GDPR accountability framework, and PCI DSS Level 1, sequencing each programme to minimise organisational disruption and maximise control reuse across frameworks.
  • Conduct thorough gap assessments for each framework — identifying missing controls, policies, and technical measures — and lead remediation to closure before each audit cycle.
  • Build and maintain a living evidence library, risk register, and control mapping documentation aligned to each framework's requirements.
  • Select, engage, and manage Qualified Security Assessors (QSAs) for PCI DSS, and external auditors and certification bodies for ISO 27001 and SOC 2.
  • Act as the primary liaison between the organisation and all external auditors, certification bodies, and regulatory contacts throughout each certification cycle.
  • Embed a culture of continuous compliance — establishing automated evidence collection, policy-as-code where appropriate, and recurring control validation cycles rather than point-in-time audit preparation.
  • Maintain organisational awareness of framework updates (e.g. PCI DSS 4.0 requirements, ISO 27001:2022 controls) and adapt the programme accordingly.
2. Network, Infrastructure & API Security
  • Develop and maintain physical and logical network diagrams, server topologies, and high-availability / disaster recovery solutions.
  • Design and maintain a secure, segmented corporate network architecture aligned with zero-trust principles — including firewall rule-sets, VPN configurations, VLAN segmentation, and perimeter security controls.
  • Liaise with the CTO on infrastructure dependencies between corporate IT and cloud environments.
  • Own and govern the security standards for all API integrations with the card issuing partner and other payment infrastructure vendors, including authentication (OAuth 2.0 / mTLS), rate limiting, logging, and webhook validation.
  • Ensure all payment-related API flows are logged, monitored, and covered by anomaly detection — in compliance with PCI DSS 4.0 API security requirements.
  • Maintain the organisation's card program scope documentation — defining what cardholder data flows through internal systems and ensuring appropriate controls are applied.
  • Verify that the card issuing partner's (e.g. Rain) PCI DSS attestation of compliance is current, documented, and reviewed on a defined schedule as part of the vendor assurance programme.
3. Observability & Monitoring
  • Implement and maintain a SIEM (Security Information and Event Management) platform to provide centralised log aggregation, anomaly detection, and audit trail management — a core PCI DSS and ISO 27001 control.
  • Define alerting thresholds, on-call escalation paths, and incident response runbooks for corporate IT systems.
  • Ensure log retention meets the requirements of each certification framework (e.g. 12-month retention, 3 months immediately accessible for PCI DSS).
4. Endpoint Security & Device Management
  • Deploy, configure, and maintain a Mobile Device Management (MDM) platform covering both Apple (iOS, macOS) and non-Apple (Windows, Android) devices using tools such as Jamf and Microsoft Intune.
  • Enforce device compliance policies, remote wipe capabilities, app deployment, and OS update management.
  • Own the full device lifecycle: procurement standards, enrolment, ongoing compliance monitoring, and decommissioning.
  • Deploy and manage an Endpoint Detection & Response (EDR) solution across all endpoints — reviewing alerts, driving threat remediation, and maintaining coverage reporting as audit evidence for PCI DSS and ISO 27001.
  • Ensure device security posture is documented and evidenced as a control within the ISO 27001 and PCI DSS certification programmes.
5. Identity, Access & Credential Management
  • Administer the organisation's IAM platform (e.g. Okta or Microsoft Entra ID), including SSO, SCIM provisioning, and access workflow automation.
  • Own automated joiner-mover-leaver (JML) workflows to ensure timely and evidenced onboarding and offboarding.
  • Conduct semi-annual access reviews and enforce least-privilege principles — a mandatory control under ISO 27001, SOC 2, and PCI DSS.
  • Enforce MFA across all users and integrate all SaaS applications via SSO/SCIM.
  • Administer the organisation's password manager (Bitwarden) — including vault structure, collection permissions, user provisioning, and emergency access procedures — and enforce strong credential hygiene policies across all teams.
  • Own the annual IT software budget — including forecasting, optimisation, and reporting to leadership.
  • Manage the full SaaS licence lifecycle: procurement, renewal, consolidation, and cancellation across all business tools.
  • Lead vendor evaluation, RFP processes, and contract negotiations to drive value and minimise risk.
  • Maintain a tiered vendor risk register — with critical payment infrastructure vendors (e.g. card issuing partner, stablecoin settlement provider) subject to enhanced due diligence, ongoing SLA oversight, and annual compliance attestation reviews.
  • Coordinate legal and finance teams on IT contract reviews and procurement approvals, ensuring all SaaS applications are integrated with SSO/SCIM for consistent access governance.
  • Maintain awareness of the stablecoin and digital asset regulatory landscape (e.g. MiCA, FinCEN guidance) as it relates to vendor obligations and the card programme's compliance posture.
7. IT Operations, Planning & Administration
  • Formulate the corporate IT and compliance certification roadmap, aligned to cost constraints, certification timelines, and business objectives.
  • Own the IT cost centre — tracking spend, identifying savings, and presenting monthly reporting to leadership; define IT KPIs and report on infrastructure health, security posture, and certification progress.
  • Day-to-day IT administration including user onboarding/offboarding, helpdesk escalation, hardware inventory management, and software licence tracking.
  • Own and operate AV and conference room technology across office locations.
  • Create and maintain detailed technical documentation covering infrastructure, runbooks, network diagrams, security policies, vendor contracts, and certification evidence artefacts.
Education
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field — or equivalent practical experience in lieu of a formal qualification.
Years of Experience
  • 5–8 years of progressive experience in IT, cybersecurity, or information security roles.
  • At least 2–3 years in a compliance, security management, or audit-facing capacity — ideally within a regulated industry (fintech, payments, financial services, or similar).
  • Demonstrable experience owning or materially contributing to at least one compliance certification project (ISO 27001, SOC 2, PCI DSS, or equivalent).
Certifications (Desirable — not mandatory)
  • CISM — Certified Information Security Manager (most directly relevant to this role).
  • ISO 27001 Lead Implementer or Lead Auditor.
  • PCI ISA — Internal Security Assessor (payments-specific; strong signal for PCI DSS ownership).
  • CISSP — Certified Information Systems Security Professional.
  • CISA — Certified Information Systems Auditor.

Candidates who have delivered compliance certifications without holding formal credentials are equally welcomed. Practical track record takes precedence over certification.

Skills & Experience Required
Compliance Certification Leadership
  • Demonstrable track record leading or significantly contributing to ISO 27001, SOC 2, GDPR, and/or PCI DSS Level 1 certification programmes — ideally from gap assessment through to successful certification.
  • Ability to run pre-audit readiness assessments, map controls across multiple frameworks, and manage auditor and QSA relationships.
  • Familiarity with control overlap across frameworks (e.g. ISO 27001 SOC 2 PCI DSS) to deliver an efficient, integrated certification programme.
Network, Infrastructure & API Security
  • Hands-on experience with network architecture design (physical, logical, HA/DR, zero-trust segmentation) and firewall, VPN, DNS, and VLAN management.
  • Working knowledge of API security best practices (OAuth 2.0, mTLS, rate limiting, webhook signing, audit logging) and PCI DSS 4.0 API security requirements.
  • SIEM platform experience (e.g. Splunk, Microsoft Sentinel, Datadog, or equivalent) — deployment, tuning, and alert management.
Endpoint Security & Device Management
  • Hands-on MDM administration for Apple devices (Jamf Pro / Apple Business Manager or equivalent) and non-Apple devices (Microsoft Intune or equivalent).
  • Experience with EDR solutions, endpoint compliance policies, conditional access, and zero-touch device provisioning.
Identity, Access & Credential Management
  • Practical experience administering Okta, Microsoft Entra ID, or equivalent IAM platform — SSO, SCIM, MFA, and automated JML workflows.
  • Experience conducting access reviews and enforcing least-privilege governance as an auditable compliance control.
  • Experience administering Bitwarden or comparable enterprise password manager at organisational scale.
  • Experience owning an IT or software budget — forecasting, optimisation, and executive reporting.
  • Track record managing SaaS licence lifecycles, vendor contract negotiations, and a tiered vendor risk framework with heightened oversight for critical or regulated third parties.
  • Experience reviewing PCI DSS attestations and managing compliance obligations for third-party payment infrastructure vendors.
Crypto / Stablecoin Awareness (Desirable)
  • Familiarity with stablecoin or blockchain-based payment infrastructure and awareness of emerging regulatory requirements (e.g. MiCA, FinCEN, FCA digital asset frameworks)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Manager
Compliance Manager

Quantrics Enterprises Inc. • Taytay

On-site
Sr. Security Analyst
Sr. Security Analyst

Concentrix • Manila

On-site
PHP 2,460,000 - 4,306,000
Data Security Analyst (Work from Home)
Data Security Analyst (Work from Home)

Quantrics Enterprises Inc. • Manila

On-site
PHP 600,000 - 1,100,000
InfoSec Framework & Compliance Lead (ISMS/PCI-DSS) | Hybrid
InfoSec Framework & Compliance Lead (ISMS/PCI-DSS) | Hybrid

GCash • Manila

On-site
PHP 1,800,000 - 3,000,000
Security Standards & Framework Manager
Security Standards & Framework Manager

GCash • Manila

On-site
PHP 1,800,000 - 3,000,000
Career growth opportunities
Competitive compensation package
Senior Compliance Officer
Senior Compliance Officer

BullSwipe • Philippines

On-site
PHP 1,200,000 - 2,000,000
Cyber Security Compliance Officer
Cyber Security Compliance Officer

PJ Lhuillier Group of Companies • Makati

Hybrid
PHP 900,000 - 1,300,000
Information Security Compliance Officer
Information Security Compliance Officer

DigiPlus Interactive Corp • Philippines

On-site
PHP 600,000 - 1,200,000
Level 1 Support Analyst
Level 1 Support Analyst

RippedBoxStation • Philippines

On-site
PHP 300,000 - 540,000
IT Security Lead
IT Security Lead

systemantech inc. • Philippines

On-site
PHP 1,800,000 - 2,400,000