Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)

Sutherland

Mabalacat

On-site

PHP 1,500,000 - 2,300,000

Full time

13 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Sutherland in Angeles, Philippines, invites an experienced Senior Manager - InfoSec Risk and Compliance to lead the development, implementation, and management of comprehensive information security risk and compliance programs onsite in Clark. You will drive regulatory alignment, manage risk assessments, and ensure adherence to industry standards.

You will build a high-performing team, oversee audits, and collaborate with IT, Legal, and business units to embed security and compliance into

Qualifications

  • 8+ years in information security, risk management, or compliance functions.
  • 5+ years in a senior management overseeing security and compliance programs.
  • Expertise in risk assessment methodologies (NIST, ISO 27001, COBIT).
  • Knowledge of regulatory requirements and compliance standards (GDPR, SOC 2, HIPAA, PCI-DSS, or equivalent).
  • Proven ability to develop and implement security policies, procedures, and governance frameworks.
  • Excellent analytical and problem-solving skills with the ability to translate complex security concepts for diverse audiences.
  • Strong organizational and project management capabilities with demonstrated ability to manage multiple initiatives simultaneously.
  • Experience conducting security risk assessments and audit management.

Responsibilities

  • Develop and execute information security risk management strategies aligned with organizational objectives and regulatory requirements.
  • Design, implement, and maintain compliance frameworks and policies in accordance with applicable standards (ISO 27001, SOC 2, GDPR, and other relevant regulations).
  • Conduct comprehensive risk assessments and vulnerability analyses to identify, evaluate, and prioritize security risks across the organization.
  • Lead cross-functional teams to remediate identified risks and compliance gaps within established timelines.
  • Manage audit activities, including internal and external audits, and coordinate remediation efforts to address findings.
  • Establish and oversee vendor risk management programs to ensure third-party security compliance.
  • Develop and deliver security awareness and compliance training programs to all organizational levels.
  • Prepare and present risk and compliance reports to senior leadership and the board of directors.
  • Stay current with evolving regulatory landscapes and emerging security threats to ensure organizational preparedness.
  • Collaborate with IT, Legal, and Business units to integrate security and compliance into organizational processes.
  • Manage compliance calendars and ensure timely submission of regulatory documentation and certifications.
  • Build and mentor a high-performing compliance and risk management team.

Skills

Information security
Risk management
Compliance management
Governance
Policy development
Audit management
Stakeholder communication
Project management
Regulatory knowledge

Tools

GRC tools

Job description

Senior Manager - InfoSec Risk and Compliance (Clark/ Onsite)
  • Full-time

Artificial Intelligence. Automation. Cloud engineering. Advanced analytics. For business leaders, these are key factors of success. For us, they're our core expertise.
We work with iconic brands worldwide. We bring them a unique value proposition through market-leading technology and business process excellence.

We've created over 200 unique inventions under several patents across AI and other critical technologies. Leveraging our advanced products and platforms, we drive digital transformation, optimize critical business operations, reinvent experiences, and pioneer new solutions, all provided through a seamless "as a service" model.

For each company, we provide new keys for their businesses, the people they work with, and the customers they serve. We tailor proven and rapid formulas, to fit their unique DNA. We bring together human expertise and artificial intelligence to develop digital chemistry. This unlocks new possibilities, transformative outcomes and enduring relationships.

We're looking for an experienced Senior Manager - InfoSec Risk and Compliance to join our organization in Angeles, Philippines. In this strategic leadership role, you will oversee the development, implementation, and management of comprehensive information security risk and compliance programs. You will drive organizational alignment with regulatory requirements, manage security risk assessments, and ensure adherence to industry standards and best practices. This position requires a decisive leader with strong analytical capabilities and meticulous attention to detail.

  • Develop and execute information security risk management strategies aligned with organizational objectives and regulatory requirements
  • Design, implement, and maintain compliance frameworks and policies in accordance with applicable standards (ISO 27001, SOC 2, GDPR, and other relevant regulations)
  • Conduct comprehensive risk assessments and vulnerability analyses to identify, evaluate, and prioritize security risks across the organization
  • Lead cross-functional teams to remediate identified risks and compliance gaps within established timelines
  • Manage audit activities, including internal and external audits, and coordinate remediation efforts to address findings
  • Establish and oversee vendor risk management programs to ensure third-party security compliance
  • Develop and deliver security awareness and compliance training programs to all organizational levels
  • Prepare and present risk and compliance reports to senior leadership and the board of directors
  • Stay current with evolving regulatory landscapes and emerging security threats to ensure organizational preparedness
  • Collaborate with IT, Legal, and Business units to integrate security and compliance into organizational processes
  • Manage compliance calendars and ensure timely submission of regulatory documentation and certifications
  • Build and mentor a high-performing compliance and risk management team
Required Qualifications:
  • 8+ years of progressive experience in information security, risk management, or compliance functions
  • 5+ years in a senior management or leadership role overseeing security and compliance programs
  • Demonstrated expertise in risk assessment methodologies and frameworks (NIST, ISO 27001, COBIT)
  • Strong knowledge of regulatory requirements and compliance standards (GDPR, SOC 2, HIPAA, PCI-DSS, or equivalent)
  • Proven ability to develop and implement security policies, procedures, and governance frameworks
  • Excellent analytical and problem-solving skills with the ability to translate complex security concepts for diverse audiences
  • Strong organizational and project management capabilities with demonstrated ability to manage multiple initiatives simultaneously
  • Exceptional communication and stakeholder management skills across all organizational levels
  • Experience conducting security risk assessments and audit management
Preferred Qualifications:
  • Professional certifications such as CISSP, CISM, or CCSK is added advantage
  • Experience with Governance, Risk, and Compliance (GRC) tools and platforms
  • Background in incident response management and security incident investigation
  • Familiarity with vendor risk management and third-party security assessments
  • Experience managing security budgets and resource allocation
  • Knowledge of emerging security threats and industry trends
  • Experience in regulated industries (financial services, healthcare, telecommunications)

Interestedcandidatesmust be willing to work onsite in Clark, Pampanga

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior InfoSec Risk & Compliance Manager – Onsite Clark
Senior InfoSec Risk & Compliance Manager – Onsite Clark

Sutherland • Mabalacat

On-site
PHP 1,500,000 - 2,300,000
General Manager - Risk & Compliance
General Manager - Risk & Compliance

Atain • Metro Manila

On-site
PHP 1,500,000 - 2,100,000
General Manager Risk & Compliance
General Manager Risk & Compliance

Atain • Manila

On-site
PHP 3,000,000 - 5,000,000
Senior Governance Risk and Compliance Analyst
Senior Governance Risk and Compliance Analyst

Permhunt • Metro Manila

On-site
Competitive salary
Benefit package
On-call support
IT Security QA
IT Security QA

Questronix Corporation • Pasig

On-site
PHP 800,000 - 1,200,000
Cyber Risk & Assurance Specialist
Cyber Risk & Assurance Specialist

Michael Page • Philippines

Hybrid
Hybrid work setup
Competitive salary and benefits
Professional development opportunities
IT Risk Assistant Manager (Bank)- Makati - up to 80K
IT Risk Assistant Manager (Bank)- Makati - up to 80K

weSource Management Consultancy Firm • Makati

On-site
Associate, Controls and Compliance
Associate, Controls and Compliance

CNX • Cagayan de Oro

On-site
PHP 600,000 - 900,000
Risk Compliance and Governance Analyst (Onsite: Cebu)
Risk Compliance and Governance Analyst (Onsite: Cebu)

TASQ Staffing Solutions • Cebu City

On-site
PHP 500,000 - 800,000
Regulatory Engagements Tech. and Cyber / Deputy ICS Practice Lead Manilla
Regulatory Engagements Tech. and Cyber / Deputy ICS Practice Lead Manilla

UpSkill MNL • Metro Manila

On-site
PHP 3,100,000 - 3,750,000