Turn this role into an interview — a resume and cover letter built around what this employer wants.
Compass Experience Labs in the Philippines seeks a hybrid IT leadership role to oversee global IT operations, cybersecurity, and data privacy, partnering with executives and external security experts to maintain a secure, scalable environment.
You will drive IT strategy, mentor teams, manage SOC 2 Type 2 program, and coordinate with auditors and vendors, ensuring compliance across cloud and on‑premises systems.
This hybrid leadership role combines strategic oversight with hands‑on execution. The successful candidate will lead the organization's global IT operations, cybersecurity, compliance, and data privacy initiatives. The role partners closely with executive leadership, external security consultants (vCISO), auditors, and business stakeholders to ensure the organization maintains a secure, scalable, and compliant technology environment, including ownership of SOC 2 Type 2, data privacy compliance, and enterprise security initiatives.
Lead the organization's overall IT strategy aligned with long-term business objectives
Provide leadership, coaching, and performance management to the IT Manager and Helpdesk team
Oversee IT operations, infrastructure, cloud services, endpoint management, and enterprise applications
Manage relationships with software vendors, hardware suppliers, MSPs, and other technology partners
Act as the final escalation point for major system outages, infrastructure incidents, and critical technical issues
Lead capacity planning, hardware lifecycle management, software licensing, and asset management
Drive continuous improvement of IT Service Management (ITSM) processes through Jira Service Management, workflow automation, SLA monitoring, and reporting
Manage IT projects including infrastructure upgrades, system implementations, and technology transformation initiatives
Partner with the external Virtual Chief Information Security Officer (vCISO) to develop and execute the organization's cybersecurity roadmap
Own the organization's SOC 2 Type 2 compliance program, including continuous control monitoring, evidence collection, audit preparation, external auditor coordination, and control remediation
5-7+ years of progressive experience in IT operations, cybersecurity, information security, or infrastructure management
Minimum 3 years in a leadership or management role overseeing IT teams
Demonstrated experience leading enterprise security and compliance programs
Hands‑on experience managing SOC 2 Type 2 audits and ongoing compliance
Experience serving as or supporting a Data Protection Officer (DPO) or privacy compliance function is highly preferred
Experience working with external auditors, vCISOs, Managed Security Service Providers (MSSPs), or regulatory agencies
Strong knowledge of Google Workspace Administration, Jira & Jira Service Management, CrowdStrike (or equivalent EDR platforms), Identity & Access Management (IAM), Mobile Device Management (MDM), Data Loss Prevention (DLP), Endpoint Security, Cloud Security, Vulnerability Management, Disaster Recovery & Business Continuity, Security Incident Response, and IT Service Management (ITIL)
Working knowledge of SOC 2 Type 2, ISO 27001 (preferred), Philippine Data Privacy Act (RA 10173), NPC Circulars and Advisories, Privacy Impact Assessments (PIA), Data Processing Agreements, Data Sharing Agreements, and Data Breach Management
Bachelor's degree in Information Technology, Computer Science, Information Security, Cybersecurity, Computer Engineering, or a related discipline; equivalent professional experience may be considered
Preferred certifications: CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, CompTIA Security+, Certified Data Privacy Professional (CDPP), Certified Information Privacy Professional (CIPP), or Data Protection Officer (DPO) Certification or equivalent privacy certification