Cyber Security & Information Governance Lead - Fully
Job Description
We are seeking a Cyber Security & Information Governance Lead to oversee our cybersecurity initiatives and ensure the integrity of our information assets. This role will be responsible for developing security strategies, managing risk assessments, and ensuring compliance with relevant regulations in the Southeast Asia region.
Key Responsibilities:
ISMS & Governance: Lead the design, implementation, and continuous monitoring of our Information Security Management System (ISMS) and corporate security policies.
Accreditations & Due Diligence: Direct audit preparation for ISO 27001 and CyberVadis. Act as the primary owner for completing and standardizing complex client cybersecurity questionnaires.
Data Privacy: Oversee corporate compliance with global data privacy regulations (GDPR, local privacy frameworks like the Philippine Data Privacy Act), conducting DPIAs and data mapping.
Development Liaison: Provide independent security oversight for application releases, cloud architecture changes, and API integrations in coordination with the Connect Development team.
Training & Compliance: Develop and execute company-wide cybersecurity awareness training and phishing simulations across international sites.
Skills and Qualifications
Bachelor's degree in Cyber Security, Information Technology, or a related field.
5-10 years of experience in cyber security and information governance roles.
Strong understanding of information security frameworks such as NIST, ISO 27001, and GDPR.
Experience with security tools and technologies, including firewalls, intrusion detection systems, and data loss prevention tools.
Knowledge of risk management principles and threat modeling.
Excellent problem-solving skills and the ability to work under pressure.
Strong communication skills to effectively convey security issues and solutions to non-technical stakeholders.
