Career Opportunities with Compass Experience Labs

A great place to work.

 
Careers At Compass Experience Labs

Current job opportunities are posted here as they become available.

 

 

 

 

IT & Information Security / Data Protection Officer (DPO) - PH

Location: Manila, Philippines
Function:

ABOUT THE ROLE

We are seeking an experienced IT & Information Security Manager / Data Protection Officer (DPO) to lead our global IT operations, cybersecurity, compliance, and data privacy initiatives.

This hybrid leadership role combines strategic oversight with hands-on execution. The successful candidate will oversee IT infrastructure and service delivery while serving as the organization's internal leader for cybersecurity, data privacy, regulatory compliance, and information governance.

The role partners closely with executive leadership, external security consultants (vCISO), auditors, and business stakeholders to ensure the organization maintains a secure, scalable, and compliant technology environment, including ownership of SOC 2 Type 2, data privacy compliance, and enterprise security initiatives.

Key Responsibilities

1. IT Leadership & Operational Management

  • Lead the organization's overall IT strategy aligned with long-term business objectives.

  • Provide leadership, coaching, and performance management to the IT Manager and Helpdesk team.

  • Oversee IT operations, infrastructure, cloud services, endpoint management, and enterprise applications.

  • Manage relationships with software vendors, hardware suppliers, MSPs, and other technology partners.

  • Act as the final escalation point for major system outages, infrastructure incidents, and critical technical issues.

  • Lead capacity planning, hardware lifecycle management, software licensing, and asset management (company-owned and BYOD).

  • Drive continuous improvement of IT Service Management (ITSM) processes through Jira Service Management, workflow automation, SLA monitoring, and reporting.

  • Manage IT projects including infrastructure upgrades, system implementations, and technology transformation initiatives.

  • Develop departmental KPIs and manage the annual IT budget to maximize operational efficiency and ROI.

2. Cybersecurity & Information Security

  • Partner with the external Virtual Chief Information Security Officer (vCISO) to develop and execute the organization's cybersecurity roadmap.

  • Lead enterprise security governance, risk management, and security operations.

  • Own the organization's SOC 2 Type 2 compliance program, including:

    • Continuous control monitoring

    • Evidence collection

    • Audit preparation

    • External auditor coordination

    • Control remediation

  • Oversee vulnerability management, penetration testing, disaster recovery, business continuity, and risk assessments.

  • Review and enforce enterprise security policies, standards, and procedures.

  • Ensure Identity & Access Management (IAM), Multi-Factor Authentication (MFA), endpoint protection, Mobile Device Management (MDM), Data Loss Prevention (DLP), and cloud security controls follow industry best practices.

  • Oversee incident response activities including security alerts, phishing incidents, CrowdStrike detections, and remediation efforts.

  • Coordinate enterprise-wide cybersecurity awareness and security training programs.

3. Data Privacy & Data Protection Officer (DPO)

Serve as the organization's designated Data Protection Officer (DPO) in accordance with the Philippine Data Privacy Act of 2012 (RA 10173) and NPC Advisory No. 2017-01.

Responsibilities include:

Privacy Compliance

  • Ensure organizational compliance with the Data Privacy Act (RA 10173), its Implementing Rules and Regulations, National Privacy Commission (NPC) issuances, and other applicable privacy laws.

  • Maintain and monitor the organization's privacy management program.

  • Advise executive leadership on data privacy obligations and regulatory requirements.

  • Maintain records of personal data processing activities.

  • Conduct periodic compliance reviews across business units.

Privacy Governance

  • Develop, implement, and maintain data privacy policies, standards, and procedures.

  • Promote Privacy by Design across business processes and technology initiatives.

  • Lead Privacy Impact Assessments (PIAs) for new systems, projects, and business initiatives.

  • Review and recommend Data Sharing Agreements (DSAs) and privacy clauses in contracts involving personal data.

Incident & Breach Management

  • Lead the organization's data breach response process.

  • Coordinate investigation, containment, remediation, and reporting of personal data breaches.

  • Ensure timely notification to the National Privacy Commission (NPC) and affected data subjects where required.

  • Maintain documentation and reporting related to privacy incidents.

Data Subject Rights

  • Serve as the primary contact for data subjects regarding privacy concerns and requests.

  • Manage requests involving:

    • Access

    • Correction

    • Deletion

    • Objection

    • Data portability

    • Other rights under applicable privacy laws

Privacy Awareness

  • Develop and conduct organization-wide privacy awareness and compliance training.

  • Promote a culture of privacy, confidentiality, and responsible data handling across the organization.

Regulatory Liaison

  • Serve as the primary liaison with the National Privacy Commission (NPC), regulators, auditors, and external privacy consultants.

  • Coordinate privacy audits, regulatory inspections, and compliance reporting.

4. Governance, Risk & Compliance (GRC)

  • Establish and maintain enterprise risk management processes related to cybersecurity and privacy.

  • Develop security metrics, compliance dashboards, and executive reporting.

  • Monitor regulatory changes affecting cybersecurity, privacy, and information security.

  • Coordinate internal and external compliance audits.

  • Recommend risk mitigation strategies and track remediation activities.

Qualifications

Required Experience

  • 5-7+ years of progressive experience in IT operations, cybersecurity, information security, or infrastructure management.

  • Minimum 3 years in a leadership or management role overseeing IT teams.

  • Demonstrated experience leading enterprise security and compliance programs.

  • Hands-on experience managing SOC 2 Type 2 audits and ongoing compliance.

  • Experience serving as or supporting a Data Protection Officer (DPO) or privacy compliance function is highly preferred.

  • Experience working with external auditors, vCISOs, Managed Security Service Providers (MSSPs), or regulatory agencies.

Technical Skills

Strong knowledge of:

  • Google Workspace Administration

  • Jira & Jira Service Management

  • CrowdStrike (or equivalent EDR platforms)

  • Identity & Access Management (IAM)

  • Mobile Device Management (MDM)

  • Data Loss Prevention (DLP)

  • Endpoint Security

  • Cloud Security

  • Vulnerability Management

  • Disaster Recovery & Business Continuity

  • Security Incident Response

  • IT Service Management (ITIL)

Privacy & Compliance Knowledge

Working knowledge of:

  • SOC 2 Type 2

  • ISO 27001 (preferred)

  • Philippine Data Privacy Act (RA 10173)

  • NPC Circulars and Advisories

  • Privacy Impact Assessments (PIA)

  • Data Processing Agreements

  • Data Sharing Agreements

  • Data Breach Management

  • Enterprise Governance, Risk & Compliance (GRC)

Education

Bachelor's degree in:

  • Information Technology

  • Computer Science

  • Information Security

  • Cybersecurity

  • Computer Engineering

  • or a related discipline

Equivalent professional experience may be considered.

Preferred Certifications

  • CISSP

  • CISM

  • CISA

  • CRISC

  • ISO 27001 Lead Implementer or Lead Auditor

  • CompTIA Security+

  • Certified Data Privacy Professional (CDPP)

  • Certified Information Privacy Professional (CIPP)

  • Data Protection Officer (DPO) Certification or equivalent privacy certification

Preferred Experience

  • BPO or shared services environment

  • Global or multinational organizations

  • Remote workforce management

  • Enterprise SaaS environments

  • Client-facing professional services

  • Experience supporting multiple geographic regions and regulatory environments

 

 

 

 

Applicant Tracking System Powered by ClearCompany HRM Applicant Tracking System