Privacy & Information Security Compliance Officer

apartmentConverge ICT Solutions placeMuntinlupa scheduleFull-time calendar_month 
Governance
  • Control Adoption and Mapping. Design, establish, and map specific privacy and security controls (based on regulatory requirements).
  • Culture and Awareness. Develop and deliver mandatory privacy and security compliance training programs to educate all employees on their roles in protecting information assets by adhering to policies, thereby building an & 'IAMSECURE' culture.
  • Monitoring and Reporting. Continuously monitor the implemented privacy and security controls, reporting the organization's overall compliance and risk posture to senior leadership.
  • Create, update, and govern the internal privacy and security policies and standards that translate external regulatory requirements into actionable rules for the business.
Compliance (Regulatory Compliance Management)
  • Requirements Identification. Research and understand all applicable laws, regulations, and industry standards (ISO, NIST, GDPR, CIS, PCI DSS, etc.).
  • Audit Management. Act as the primary liaison for internal and external auditors.
  • Gap Analysis and Remediation. Conduct regular assessments to identify gaps between the current security controls and the required compliance standards and then oversee the effort to close those gaps.
  • Mandatory Requirements. Establish and implement mandatory reporting and compliance requirements (DSAR, ASIR, DPO Registration, etc.)
Risk
  • Risk Assessment. Perform systematic reviews to identify potential threats and vulnerabilities to the organization's critical assets through PIA/DPIAs.
  • Risk Treatment. Propose and recommend privacy and security controls (both technical and procedural) to reduce identified risks to an acceptable level.
  • Third-Party Risk. Assess the security and compliance posture of vendors and business partners who have access to the company's sensitive data.
  • Privacy by Design and Security by Design. Integrate data privacy and security from the start of a product's development lifecycle.
  • Incident Response. Develop and maintain the formal plans and procedures to respond, contain, and recover from a security incident or data breach.
Qualifications
  • College Graduate of any course
  • 2-3 years of hands-on or demonstrated experience in managing and implementing data privacy programs and information security standards or frameworks (GDPR, Data Privacy Act of 2012, ISO/IEC 27001:2022, NIST, CIS).
  • Experience in leading or performing privacy and security risk assessments (Third- Party Risk Management, privacy impact assessments, Data Protection Impact Assessments) and handling security incidents or breaches.
  • Professional knowledge in data privacy laws, rules and regulations, and information security standards or frameworks.
  • Knowledgeable on data privacy and information security architecture and Control Frameworks (GDPR, ISO27001, NIST CSF, CIS, etc.)
electric_boltImmediate start

Information Security Officer

apartmentSert Technology IncplaceGeneral Trias, 18 km from Muntinlupa
About the role Sert Technology Inc. is seeking an Information Security Officer to join our growing team on a full-time basis in General Trias City, Cavite. This is a strategic position that plays a crucial role in protecting our organization's...
business_centerHigh salary

Information Security Associate

apartmentOur ClientsplaceMakati, 20 km from Muntinlupa
Information Security Associate Location: Makati City Work Setup: Hybrid Employment Type: Full-time Job Summary We are looking for an Information Security Associate to support consulting engagements focused on information security, cybersecurity...
apartmentConverge ICT SolutionsplaceManila, 25 km from Muntinlupa
programs to educate all employees on their roles in protecting information assets by adhering to policies, thereby building an & 'IAMSECURE' culture.  •  Monitoring and Reporting. Continuously monitor the implemented privacy and security controls, reporting...