IT & Information Security / Data Protection Officer (DPO) - PH

Compass Experience Labs

Manila

On-site

PHP 1,800,000 - 3,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Compass Experience Labs seeks an experienced IT & Information Security Manager / Data Protection Officer (DPO) to lead global IT operations, cybersecurity, and privacy compliance. This hybrid leadership role balances strategic oversight with hands-on execution, coordinating with external vCISO, auditors, and business stakeholders.

The DPO will own SOC 2 Type 2, implement privacy governance, and drive incident response, IAM, MFA, DLP, and cloud security controls across the enterprise.

Qualifications

  • 5-7+ years of progressive IT/cybersecurity experience.
  • Minimum 3 years in a leadership role.
  • Hands-on experience with SOC 2 Type 2 audits.
  • Experience working with external auditors, vCISO, MSSPs, or regulators.
  • Privacy compliance experience (DPO) is highly preferred.

Responsibilities

  • Define and drive IT strategy aligned with business objectives.
  • Provide leadership to IT teams and manage budgets.
  • Oversee IT operations, cloud services, and enterprise apps.
  • Lead cybersecurity governance, risk management, and awareness programs.
  • Own SOC 2 Type 2 program, audits, and remediation.
  • Develop privacy policies, PIAs, and data sharing agreements.
  • Coordinate governance, risk, and compliance (GRC) activities.

Skills

Identity & Access Management (IAM)
CrowdStrike
Vulnerability Management
Security Incident Response
ITIL
Disaster Recovery
SOC 2 Type 2
Data Privacy Act knowledge

Education

Bachelor's degree in Information Technology or related field

Tools

Jira Service Management

Job description

Career Opportunities with Compass Experience Labs

A great place to work.

Careers At Compass Experience Labs

Current job opportunities are posted here as they become available.

IT & Information Security / Data Protection Officer (DPO) - PH

We are seeking an experienced IT & Information Security Manager / Data Protection Officer (DPO) to lead our global IT operations, cybersecurity, compliance, and data privacy initiatives.

This hybrid leadership role combines strategic oversight with hands-on execution. The successful candidate will oversee IT infrastructure and service delivery while serving as the organization's internal leader for cybersecurity, data privacy, regulatory compliance, and information governance.

The role partners closely with executive leadership, external security consultants (vCISO), auditors, and business stakeholders to ensure the organization maintains a secure, scalable, and compliant technology environment, including ownership of SOC 2 Type 2, data privacy compliance, and enterprise security initiatives.

Key Responsibilities
1. IT Leadership & Operational Management

Lead the organization's overall IT strategy aligned with long-term business objectives.

Provide leadership, coaching, and performance management to the IT Manager and Helpdesk team.

Oversee IT operations, infrastructure, cloud services, endpoint management, and enterprise applications.

Manage relationships with software vendors, hardware suppliers, MSPs, and other technology partners.

Act as the final escalation point for major system outages, infrastructure incidents, and critical technical issues.

Lead capacity planning, hardware lifecycle management, software licensing, and asset management (company-owned and BYOD).

Drive continuous improvement of IT Service Management (ITSM) processes through Jira Service Management, workflow automation, SLA monitoring, and reporting.

Manage IT projects including infrastructure upgrades, system implementations, and technology transformation initiatives.

Develop departmental KPIs and manage the annual IT budget to maximize operational efficiency and ROI.

2. Cybersecurity & Information Security

Partner with the external Virtual Chief Information Security Officer (vCISO) to develop and execute the organization's cybersecurity roadmap.

Lead enterprise security governance, risk management, and security operations.

Own the organization's SOC 2 Type 2 compliance program, including:

Evidence collection

External auditor coordination

Control remediation

Oversee vulnerability management, penetration testing, disaster recovery, business continuity, and risk assessments.

Review and enforce enterprise security policies, standards, and procedures.

Ensure Identity & Access Management (IAM), Multi-Factor Authentication (MFA), endpoint protection, Mobile Device Management (MDM), Data Loss Prevention (DLP), and cloud security controls follow industry best practices.

Oversee incident response activities including security alerts, phishing incidents, CrowdStrike detections, and remediation efforts.

Coordinate enterprise-wide cybersecurity awareness and security training programs.

3. Data Privacy & Data Protection Officer (DPO)

Serve as the organization's designated Data Protection Officer (DPO) in accordance with the Philippine Data Privacy Act of 2012 (RA 10173) and NPC Advisory No. 2017-01.

Responsibilities include:

Privacy Compliance

Ensure organizational compliance with the Data Privacy Act (RA 10173), its Implementing Rules and Regulations, National Privacy Commission (NPC) issuances, and other applicable privacy laws.

Maintain and monitor the organization's privacy management program.

Advise executive leadership on data privacy obligations and regulatory requirements.

Maintain records of personal data processing activities.

Conduct periodic compliance reviews across business units.

Privacy Governance

Develop, implement, and maintain data privacy policies, standards, and procedures.

Promote Privacy by Design across business processes and technology initiatives.

Lead Privacy Impact Assessments (PIAs) for new systems, projects, and business initiatives.

Review and recommend Data Sharing Agreements (DSAs) and privacy clauses in contracts involving personal data.

Incident & Breach Management

Lead the organization's data breach response process.

Coordinate investigation, containment, remediation, and reporting of personal data breaches.

Ensure timely notification to the National Privacy Commission (NPC) and affected data subjects where required.

Maintain documentation and reporting related to privacy incidents.

Data Subject Rights

Serve as the primary contact for data subjects regarding privacy concerns and requests.

Manage requests involving:

Access

Correction

Deletion

Objection

Other rights under applicable privacy laws

Develop and conduct organization-wide privacy awareness and compliance training.

Promote a culture of privacy, confidentiality, and responsible data handling across the organization.

Serve as the primary liaison with the National Privacy Commission (NPC), regulators, auditors, and external privacy consultants.

Coordinate privacy audits, regulatory inspections, and compliance reporting.

4. Governance, Risk & Compliance (GRC)

Establish and maintain enterprise risk management processes related to cybersecurity and privacy.

Develop security metrics, compliance dashboards, and executive reporting.

Monitor regulatory changes affecting cybersecurity, privacy, and information security.

Coordinate internal and external compliance audits.

Recommend risk mitigation strategies and track remediation activities.

Qualifications
Required Experience

5-7+ years of progressive experience in IT operations, cybersecurity, information security, or infrastructure management.

Minimum 3 years in a leadership or management role overseeing IT teams.

Demonstrated experience leading enterprise security and compliance programs.

Hands-on experience managing SOC 2 Type 2 audits and ongoing compliance.

Experience serving as or supporting a Data Protection Officer (DPO) or privacy compliance function is highly preferred.

Experience working with external auditors, vCISOs, Managed Security Service Providers (MSSPs), or regulatory agencies.

Technical Skills

Strong knowledge of:

Google Workspace Administration

CrowdStrike (or equivalent EDR platforms)

Identity & Access Management (IAM)

Vulnerability Management

Disaster Recovery & Business Continuity

Security Incident Response

IT Service Management (ITIL)

Privacy & Compliance Knowledge

Working knowledge of:

SOC 2 Type 2

ISO 27001 (preferred)

Philippine Data Privacy Act (RA 10173)

NPC Circulars and Advisories

Privacy Impact Assessments (PIA)

Data Processing Agreements

Data Sharing Agreements

Enterprise Governance, Risk & Compliance (GRC)

Education

Bachelor's degree in:

Information Technology

Computer Science

Information Security

Cybersecurity

or a related discipline

Equivalent professional experience may be considered.

Preferred Certifications

CISSP

CISM

CISA

CRISC

ISO 27001 Lead Implementer or Lead Auditor

CompTIA Security+

Certified Data Privacy Professional (CDPP)

Certified Information Privacy Professional (CIPP)

Data Protection Officer (DPO) Certification or equivalent privacy certification

Preferred Experience

BPO or shared services environment

Global or multinational organizations

Enterprise SaaS environments

Client-facing professional services

Experience supporting multiple geographic regions and regulatory environments

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

Compass Experience Labs LLC • Manila

Hybrid
PHP 1,800,000 - 3,200,000
Data Privacy Officer (Midshift, Onsite)
Data Privacy Officer (Midshift, Onsite)

blaseek • Pasig

On-site
Data Privacy Officer
Data Privacy Officer

Risewave Consulting Inc. • Pasig

On-site
PHP 600,000 - 1,000,000
Global IT & Security Leader (DPO & Privacy)
Global IT & Security Leader (DPO & Privacy)

Compass Experience Labs LLC • Manila

Hybrid
PHP 1,800,000 - 3,200,000
IT & Security Leader | Data Protection Officer (DPO)
IT & Security Leader | Data Protection Officer (DPO)

Compass Experience Labs • Manila

Hybrid
PHP 1,800,000 - 3,200,000
General Manager Risk & Compliance
General Manager Risk & Compliance

Atain • Manila

On-site
PHP 3,000,000 - 5,000,000
General Manager - Risk & Compliance
General Manager - Risk & Compliance

Atain • Metro Manila

On-site
PHP 1,500,000 - 2,100,000
RCI: Data Privacy Officer
RCI: Data Privacy Officer

Reliance United • Manila

On-site
PHP 600,000 - 800,000
IT Operations & Infrastructure Manager
IT Operations & Infrastructure Manager

HRTX • Makati

On-site
PHP 1,800,000 - 3,000,000
Data Security Analyst (Work from Home)
Data Security Analyst (Work from Home)

Quantrics Enterprises Inc. • Manila

On-site
PHP 600,000 - 1,100,000