Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)

Sutherland
Philippines
Workplace: OnsiteFull timeFunction: Legal, Risk & ComplianceExperience: 8+ yearsSkills: ["Analytical thinking","Problem-solving","Organizational leadership","Stakeholder management","Attention to detail"]

Lead the development and execution of information security risk and compliance programs, aligning strategy with organizational objectives and regulatory requirements. Design and maintain compliance frameworks and policies across standards such as ISO 27001, SOC 2, and GDPR. Own risk assessments, audit management, vendor risk oversight, security awareness training, and reporting to senior leadership and the board while building and mentoring a high-performing GRC/risk team.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Sutherland
Sutherland
1 day ago

Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Lead the development and execution of information security risk and compliance programs, aligning strategy with organizational objectives and regulatory requirements. Design and maintain compliance frameworks and policies across standards such as ISO 27001, SOC 2, and GDPR. Own risk assessments, audit management, vendor risk oversight, security awareness training, and reporting to senior leadership and the board while building and mentoring a high-performing GRC/risk team.
Location: Philippines
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Sr. Manager level

Key Responsibilities

  • •Develop and execute information security risk management strategies aligned to organizational objectives and regulatory requirements.
  • •Design, implement, and maintain compliance frameworks and policies in line with applicable standards (ISO 27001, SOC 2, GDPR, and others).
  • •Conduct risk assessments and vulnerability analyses to identify, evaluate, and prioritize security risks.
  • •Lead cross-functional remediation of security risks and compliance gaps within established timelines, including audit coordination and follow-up.
  • •Establish and oversee vendor risk management, deliver security awareness and compliance training, and prepare risk/compliance reports for senior leadership and the board.

Key Requirements

  • •8+ years of progressive experience in information security, risk management, or compliance, including 5+ years in senior leadership overseeing security and compliance programs.
  • •Expertise in risk assessment methodologies and frameworks such as NIST, ISO 27001, and COBIT.
  • •Strong knowledge of regulatory requirements and compliance standards including GDPR, SOC 2, HIPAA, and PCI-DSS.
  • •Ability to develop and implement security policies, procedures, and governance frameworks.
  • •Experience conducting security risk assessments and managing audit activities, including coordinating remediation for findings.
Experience:8+ years
Skills:Analytical thinkingProblem-solvingOrganizational leadershipStakeholder managementAttention to detail
Certifications:CISSPCISMCCSK
Languages:English
Tech Stack:Information securityRisk managementCompliance frameworksISO 27001SOC 2GDPRNISTCOBITHIPAAPCI-DSSGRCVendor risk managementAudit managementIncident responseSecurity awareness training

Company Brief

Sutherland
Global digital transformation and business process services firm offering AI, automation, cloud engineering, analytics and customer experience solutions to enterprises across industries.
Industry: Professional Services
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Pittsford (Rochester), NY, United States
Founded: 1986
Glassdoor
Glassdoor: 3.5
WebsiteLinkedInGlassdoor