Privacy & Information Security Compliance Officer
Converge ICT Solutions Manila Full-time
Governance
- Control Adoption and Mapping. Design, establish, and map specific privacy and security controls (based on regulatory requirements).
- Culture and Awareness. Develop and deliver mandatory privacy and security compliance training programs to educate all employees on their roles in protecting information assets by adhering to policies, thereby building an & 'IAMSECURE' culture.
- Monitoring and Reporting. Continuously monitor the implemented privacy and security controls, reporting the organization's overall compliance and risk posture to senior leadership.
- Create, update, and govern the internal privacy and security policies and standards that translate external regulatory requirements into actionable rules for the business.
- Requirements Identification. Research and understand all applicable laws, regulations, and industry standards (ISO, NIST, GDPR, CIS, PCI DSS, etc.).
- Audit Management. Act as the primary liaison for internal and external auditors.
- Gap Analysis and Remediation. Conduct regular assessments to identify gaps between the current security controls and the required compliance standards and then oversee the effort to close those gaps.
- Mandatory Requirements. Establish and implement mandatory reporting and compliance requirements (DSAR, ASIR, DPO Registration, etc.)
- Risk Assessment. Perform systematic reviews to identify potential threats and vulnerabilities to the organization's critical assets through PIA/DPIAs.
- Risk Treatment. Propose and recommend privacy and security controls (both technical and procedural) to reduce identified risks to an acceptable level.
- Third-Party Risk. Assess the security and compliance posture of vendors and business partners who have access to the company's sensitive data.
- Privacy by Design and Security by Design. Integrate data privacy and security from the start of a product's development lifecycle.
- Incident Response. Develop and maintain the formal plans and procedures to respond, contain, and recover from a security incident or data breach.
- College Graduate of any course
- 2-3 years of hands-on or demonstrated experience in managing and implementing data privacy programs and information security standards or frameworks (GDPR, Data Privacy Act of 2012, ISO/IEC 27001:2022, NIST, CIS).
- Experience in leading or performing privacy and security risk assessments (Third- Party Risk Management, privacy impact assessments, Data Protection Impact Assessments) and handling security incidents or breaches.
- Professional knowledge in data privacy laws, rules and regulations, and information security standards or frameworks.
- Knowledgeable on data privacy and information security architecture and Control Frameworks (GDPR, ISO27001, NIST CSF, CIS, etc.)
Converge ICT SolutionsQuezon City, 10 km from Manila
programs to educate all employees on their roles in protecting information assets by adhering to policies, thereby building an & 'IAMSECURE' culture.
• Monitoring and Reporting. Continuously monitor the implemented privacy and security controls, reporting...
Our ClientsMakati, 6 km from Manila
Information Security Associate
Location: Makati City
Work Setup: Hybrid
Employment Type: Full-time
Job Summary
We are looking for an Information Security Associate to support consulting engagements focused on information security, cybersecurity...
Sert Technology IncGeneral Trias, 26 km from Manila
About the role
Sert Technology Inc. is seeking an Information Security Officer to join our growing team on a full-time basis in General Trias City, Cavite. This is a strategic position that plays a crucial role in protecting our organization's...