Information Security Manager, SecOps

sagi hr • Philippines
Remote
Apply
AI Summary

Manage customer security programs, lead control monitoring, and develop risk strategies to enhance client security postures. Serve as the primary written communicator for findings, progress, and next steps. Requires asynchronous collaboration and expertise in various security frameworks.

Key Highlights
Manage a portfolio of customer security programs through asynchronous collaboration.
Lead continuous control monitoring and risk management strategies.
Serve as the primary written voice for customer communications on security findings and progress.
Key Responsibilities
Manage a portfolio of customer security programs with continuous oversight via async channels.
Serve as the primary point of accountability for program health, milestone tracking, and escalation.
Coordinate with assigned Security Consultants to align monitoring with each client's overall strategy.
Participate in internal syncs and contribute to broader SecOps objectives.
Lead ongoing assessments of security controls against ISO 27001, SOC 2, NIST CSF, and other applicable frameworks.
Monitor and evaluate control effectiveness, maturity levels, and residual risk exposure.
Identify, track, and support remediation of control weaknesses and compliance gaps.
Maintain current records of risk assessments, audit findings, and corrective action plans.
Review evidence and documentation to validate compliance posture across multiple frameworks.
Support audit readiness for SOC 2, HIPAA, ISO 27001, PCI DSS, CMMC, and related engagements.
Perform Third Party Risk Management (TPRM) assessments for new and existing vendors.
Respond to security questionnaires on behalf of clients within a 5-business-day SLA.
Prepare accurate, professional, and actionable written reports and customer updates.
Deliver data-driven insights and recommendations with clarity and specificity.
Ensure transparency across all customer-facing communications regarding monitoring, findings, and remediation status.
Continuously improve reporting standards, evidence management, and monitoring methodologies.
Technical Skills Required
ISO 27001 SOC 2 NIST CSF HIPAA PCI DSS CMMC TPRM GRC
Benefits & Perks
HMO coverage
Gym membership
Paid training and professional development
Work from home — fully remote setup

Job Description


About the Role

As an Information Security Manager on our SecOps Team, you'll manage a portfolio of customer security programs through asynchronous collaboration, lead continuous control monitoring, assess maturity, and develop risk management strategies that strengthen client security postures.

You'll work closely with Security Consultants, Offensive Security, and other SecOps functions — and serve as the primary written voice keeping customers informed on findings, progress, and next steps.


Key Responsibilities


Portfolio Management

  • Manage a portfolio of customer security programs with continuous oversight via async channels
  • Serve as the primary point of accountability for program health, milestone tracking, and escalation
  • Coordinate with assigned Security Consultants to align monitoring with each client's overall strategy
  • Participate in internal syncs and contribute to broader SecOps objectives

Control Monitoring & Risk

  • Lead ongoing assessments of security controls against ISO 27001, SOC 2, NIST CSF, and other applicable frameworks
  • Monitor and evaluate control effectiveness, maturity levels, and residual risk exposure
  • Identify, track, and support remediation of control weaknesses and compliance gaps
  • Maintain current records of risk assessments, audit findings, and corrective action plans

Audit & Compliance Readiness

  • Review evidence and documentation to validate compliance posture across multiple frameworks
  • Support audit readiness for SOC 2, HIPAA, ISO 27001, PCI DSS, CMMC, and related engagements
  • Perform Third Party Risk Management (TPRM) assessments for new and existing vendors
  • Respond to security questionnaires on behalf of clients within a 5-business-day SLA

Reporting & Communication

  • Prepare accurate, professional, and actionable written reports and customer updates
  • Deliver data-driven insights and recommendations with clarity and specificity
  • Ensure transparency across all customer-facing communications regarding monitoring, findings, and remediation status
  • Continuously improve reporting standards, evidence management, and monitoring methodologies


Employment Type

  • Local employment — you'll be hired under your country's local labor laws and employment standards
  • Fully remote position — work from anywhere within your jurisdiction


Salary

  • Php 100,000-180,000


Benefits

  • HMO coverage
  • Gym membership
  • Paid training and professional development
  • Work from home — fully remote setup


Frameworks & Standards

ISO 27001

SOC 2

NIST CSF

HIPAA

PCI DSS

CMMC

TPRM

GRC


Similar Jobs

Explore other opportunities that match your interests

IT Security Engineer

Cyber Security
•
1w ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

twin signal

Philippines
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

AbroadWorks

Philippines

Senior Staff Engineer - AI Security

Cyber Security
•
3h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

GEICO

United State

Subscribe our newsletter

New Things Will Always Update Regularly