IT & Information Security / Data Protection Officer (DPO) - PH
Quick Summary
Continuous control monitoring Evidence collection Audit preparation External auditor coordination Control remediation Oversee vulnerability management, penetration testing, disaster recovery,
ABOUT THE ROLE
We are seeking an experienced IT & Information Security Manager / Data Protection Officer (DPO) to lead our global IT operations, cybersecurity, compliance, and data privacy initiatives.
This hybrid leadership role combines strategic oversight with hands-on execution. The successful candidate will oversee IT infrastructure and service delivery while serving as the organization's internal leader for cybersecurity, data privacy, regulatory compliance, and information governance.
The role partners closely with executive leadership, external security consultants (vCISO), auditors, and business stakeholders to ensure the organization maintains a secure, scalable, and compliant technology environment, including ownership of SOC 2 Type 2, data privacy compliance, and enterprise security initiatives.
Responsibilities
~1 min read-
Lead the organization's overall IT strategy aligned with long-term business objectives.
-
Provide leadership, coaching, and performance management to the IT Manager and Helpdesk team.
-
Oversee IT operations, infrastructure, cloud services, endpoint management, and enterprise applications.
-
Manage relationships with software vendors, hardware suppliers, MSPs, and other technology partners.
-
Act as the final escalation point for major system outages, infrastructure incidents, and critical technical issues.
-
Lead capacity planning, hardware lifecycle management, software licensing, and asset management (company-owned and BYOD).
-
Drive continuous improvement of IT Service Management (ITSM) processes through Jira Service Management, workflow automation, SLA monitoring, and reporting.
-
Manage IT projects including infrastructure upgrades, system implementations, and technology transformation initiatives.
-
Develop departmental KPIs and manage the annual IT budget to maximize operational efficiency and ROI.
-
Partner with the external Virtual Chief Information Security Officer (vCISO) to develop and execute the organization's cybersecurity roadmap.
-
Lead enterprise security governance, risk management, and security operations.
-
Own the organization's SOC 2 Type 2 compliance program, including:
-
Continuous control monitoring
-
Evidence collection
-
Audit preparation
-
External auditor coordination
-
Control remediation
-
-
Oversee vulnerability management, penetration testing, disaster recovery, business continuity, and risk assessments.
-
Review and enforce enterprise security policies, standards, and procedures.
-
Ensure Identity & Access Management (IAM), Multi-Factor Authentication (MFA), endpoint protection, Mobile Device Management (MDM), Data Loss Prevention (DLP), and cloud security controls follow industry best practices.
-
Oversee incident response activities including security alerts, phishing incidents, CrowdStrike detections, and remediation efforts.
-
Coordinate enterprise-wide cybersecurity awareness and security training programs.
Serve as the organization's designated Data Protection Officer (DPO) in accordance with the Philippine Data Privacy Act of 2012 (RA 10173) and NPC Advisory No. 2017-01.
-
Ensure organizational compliance with the Data Privacy Act (RA 10173), its Implementing Rules and Regulations, National Privacy Commission (NPC) issuances, and other applicable privacy laws.
-
Maintain and monitor the organization's privacy management program.
-
Advise executive leadership on data privacy obligations and regulatory requirements.
-
Maintain records of personal data processing activities.
-
Conduct periodic compliance reviews across business units.
-
Develop, implement, and maintain data privacy policies, standards, and procedures.
-
Promote Privacy by Design across business processes and technology initiatives.
-
Lead Privacy Impact Assessments (PIAs) for new systems, projects, and business initiatives.
-
Review and recommend Data Sharing Agreements (DSAs) and privacy clauses in contracts involving personal data.
-
Lead the organization's data breach response process.
-
Coordinate investigation, containment, remediation, and reporting of personal data breaches.
-
Ensure timely notification to the National Privacy Commission (NPC) and affected data subjects where required.
-
Maintain documentation and reporting related to privacy incidents.
-
Serve as the primary contact for data subjects regarding privacy concerns and requests.
-
Manage requests involving:
-
Access
-
Correction
-
Deletion
-
Objection
-
Data portability
-
Other rights under applicable privacy laws
-
-
Develop and conduct organization-wide privacy awareness and compliance training.
-
Promote a culture of privacy, confidentiality, and responsible data handling across the organization.
-
Serve as the primary liaison with the National Privacy Commission (NPC), regulators, auditors, and external privacy consultants.
-
Coordinate privacy audits, regulatory inspections, and compliance reporting.
-
Establish and maintain enterprise risk management processes related to cybersecurity and privacy.
-
Develop security metrics, compliance dashboards, and executive reporting.
-
Monitor regulatory changes affecting cybersecurity, privacy, and information security.
-
Coordinate internal and external compliance audits.
-
Recommend risk mitigation strategies and track remediation activities.
Requirements
~1 min readNice to Have
~1 min read-
Google Workspace Administration
-
Jira & Jira Service Management
-
CrowdStrike (or equivalent EDR platforms)
-
Identity & Access Management (IAM)
-
Mobile Device Management (MDM)
-
Data Loss Prevention (DLP)
-
Endpoint Security
-
Cloud Security
-
Vulnerability Management
-
Disaster Recovery & Business Continuity
-
Security Incident Response
-
IT Service Management (ITIL)
-
CISSP
-
CISM
-
CISA
-
CRISC
-
ISO 27001 Lead Implementer or Lead Auditor
-
CompTIA Security+
-
Certified Data Privacy Professional (CDPP)
-
Certified Information Privacy Professional (CIPP)
-
Data Protection Officer (DPO) Certification or equivalent privacy certification
-
BPO or shared services environment
-
Global or multinational organizations
-
Remote workforce management
-
Enterprise SaaS environments
-
Client-facing professional services
-
Experience supporting multiple geographic regions and regulatory environments
-
SOC 2 Type 2
-
ISO 27001 (preferred)
-
Philippine Data Privacy Act (RA 10173)
-
NPC Circulars and Advisories
-
Privacy Impact Assessments (PIA)
-
Data Processing Agreements
-
Data Sharing Agreements
-
Data Breach Management
-
Enterprise Governance, Risk & Compliance (GRC)
-
Information Technology
-
Computer Science
-
Information Security
-
Cybersecurity
-
Computer Engineering
-
or a related discipline
Equivalent professional experience may be considered.
Location & Eligibility
Listing Details
- First seen
- September 1, 2026
- Last seen
- September 1, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 51%
- Scored at
- September 1, 2026
Signal breakdown
Please let compassexperiencelabs know you found this job on Jobera.
4 other jobs at compassexperiencelabs
View all →Explore open roles at compassexperiencelabs.
Similar Information Security jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.