Senior Manager, Security Operations And Assurance, Information Technology

City Developments Limited

Santo Niño 1st

On-site

PHP 1,800,000 - 2,400,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

City Developments Limited (CDL) is seeking a senior cybersecurity leader to drive policy development, oversee the SOC and coordinate risk assessments across the group and its subsidiaries. The role requires hands-on expertise in security engineering, incident response and vendor risk management, with a focus on safeguarding cloud, data and network environments.

The ideal candidate has extensive experience in SIEM, vulnerability management and application security testing, plus familiarity with

Qualifications

  • Degree in Cybersecurity, Information Security, Computer Science, IT or related field.
  • At least 8–12 years in cybersecurity, security operations, security engineering, security assessment or IT risk.
  • At least three years leading security analysts, managed security providers or technical security vendors.
  • Experience leading internal security analysts and managing an external SOC, MSSP or security-testing partner.
  • Strong knowledge of SIEM, incident response, vulnerability management, cloud security, IAM, endpoint, email, network and data security controls.
  • Experience scoping and managing vulnerability assessments and penetration testing engagements, and validating findings and remediation plans.
  • Exposure to application security testing (SAST/DAST, SCA) for web/mobile apps.
  • Familiarity with ISO/IEC 27001, NIST CSF, PDPA, Cybersecurity Act, PCI DSS, SWIFT CSCF.
  • CISSP, CISM, CRISC, CCSP or GIAC certifications preferred.

Responsibilities

  • Develop, implement and review cybersecurity policies, standards and guidelines across the organisation and subsidiaries.
  • Lead internal security analysts and manage the external Security Operations Centre provider for continuous monitoring and incident response.
  • Operate, maintain and improve the group's security technology stack across endpoints, cloud, network and data environments.
  • Lead vulnerability management, security assessments and risk reviews for critical systems and cloud services.
  • Conduct due diligence for critical vendors and external partnerships, defining security assurance requirements.
  • Provide technical security advice for new solutions and AI use cases, assessing data, access and integration risks.
  • Support cybersecurity awareness training and phishing simulations across the organisation.

Skills

SIEM expertise
Incident response
Vulnerability management
Security monitoring
Threat detection
Cloud security
Identity management
Network security
Data security
Penetration testing
SAST/DAST
ISO 27001
NIST CSF
PCI DSS
CISSP/CISM/CRISC/CCSP

Education

Degree in Cybersecurity

Tools

SOC management tools

Job description

Job Responsibilities:

  • Support the development,implementationand review of cybersecurity policies, standards,proceduresand technical guidelines across theorganisationand subsidiaries. Monitor compliance, support audits and assurance activities, prepare technical risk updates, and escalat material control gaps through the Group governance process.
  • Lead internal security analysts and manage the external Security Operations Centre provider to deliver continuous monitoring, threat detection, incidentinvestigationand response. Review significant alerts,incidentsand service performance, and escalat material risksin accordance withthe Cyber Incident Response Plan.
  • Operate,maintainand improvethe Group's security technologiesstackacross endpoint, identity, email, cloud, network, web, privileged access, dataprotectionand digital environments. Work with IT teams and service providers to ensure security controls are effectively implemented and monitored.
  • Lead vulnerability management, security assessments and technical risk reviews for critical systems, applications, cloudservicesand subsidiaries. Scope and coordinate external vulnerability assessments, penetrationtestsand red-team exercises;validatefindings, provideremediationadviceand track actions to closure.
  • Conduct technical security due diligence for critical vendors, outsourced IT services, cloudprovidersand digital solutions. Define security assurance requirements for external partners and assess and report on compliance with agreed security obligations.
  • Providetechnical security advice for new solutions, majorchangesand AI use cases. Assess security risks relating to data, access, integration, third-partyservicesand monitoring, and escalat material risks through the established security and AI governance process.
  • Support cybersecurity awareness training and phishing simulations byprovidingrelevant threat insights, technicalcontentand follow-up advice. Help improve security awareness and safe practices across theorganisationand subsidiaries.

Job Requirements:

  • Degree in Cybersecurity, Information Security, Computer Science, Information Technology or a related discipline; equivalent relevant experience may be considered.
  • At least 8-12 years of experience in cybersecurity, security operations, security engineering, securityassessmentor IT risk.
  • At least three years' experience leading security analysts, managed securityprovidersor technical security vendors.
  • Experience leading internal security analysts and managing an external SOC, managed security serviceprovideror security-testing partner.
  • Strong technical knowledge of SIEM and security monitoring, incident response, vulnerability management, cloud security, identity and access management, endpoint, email,networkanddata-securitycontrols.
  • Experience scoping and managing vulnerability assessments and penetration-testingengagements, and validating findings and remediation plans.
  • Exposure to application security testing, including static and dynamic analysis (SAST/DAST), software composition analysis (SCA), and penetration testing of web and mobile applications.
  • Working knowledge of security standards and applicable requirements, including ISO/IEC 27001, NIST Cybersecurity Framework, PDPA, Cybersecurity Act, PCI DSS and SWIFT Customer Security Controls Framework, where applicable.
  • Working knowledge of AI security risks and security assessment requirements for AI solutions and third-party AI services.
  • CISSP, CISM, CRISC,CCSPor relevant GIAC certifications are preferred.

Requirements

City Developments Limited (CDL) is committed to fostering an inclusive culture that respects the diversity of its employees and stakeholders. As a signatory of the Employers Pledge for Fair Employment with TAFEP since 2008, CDL's recruitment process adheres to strict guidelines on non-discrimination and fairness, regardless of gender, ethnicity, religion, or age.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations & Assurance Leader
Senior Security Operations & Assurance Leader

City Developments Limited • Santo Niño 1st

On-site
PHP 1,800,000 - 2,400,000
IT Security Lead
IT Security Lead

We Search Searchers Staffers Corp • Pasig

On-site
PHP 1,500,000 - 3,000,000
Senior Delivery Director - Cyber and Enterprise Security
Senior Delivery Director - Cyber and Enterprise Security

Michael Page International Pte Ltd • Santo Niño 1st

On-site
PHP 2,000,000 - 4,000,000
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Santo Niño 1st

On-site
PHP 1,200,000 - 1,800,000
Cybersecurity Analyst
Cybersecurity Analyst

ContactPoint360 • Cebu City

On-site
PHP 900,000 - 1,300,000
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

Willis Towers Watson • Pateros

On-site
PHP 600,000 - 900,000
Information Security Analyst
Information Security Analyst

Satellite Office • Pasig

Hybrid
PHP 1,000,000 - 2,000,000
Senior Security Engineer – SOC
Senior Security Engineer – SOC

42 Gears Mobility Systems • Hinoba-an

On-site
PHP 995,000 - 1,592,000
Information Security Manager New Bengaluru, Karnataka, India
Information Security Manager New Bengaluru, Karnataka, India

Sigmoid • Hinoba-an

On-site
PHP 1,200,000 - 2,400,000
Security Analyst (Remote)
Security Analyst (Remote)

Prime System Solutions • Philippines

On-site
PHP 1,200,000 - 1,600,000
HMO coverage
Paid time off
Career development and certification
+2