Information Security and Data Protection Specialist
SyCip Salazar Hernandez & Gatmaitan · Makati, Philippines ·
- Category
- Security
This specialist builds and maintains the law firm's information security program: writing and enforcing security policies, running business continuity/disaster recovery plans, annual internal audits, incident investigations, and security training, while serving as the firm's point person for compliance with the Philippine Data Privacy Act of 2012.
Information Security and Data Protection Specialist
Responsibilities:
- Handle the establishment, documentation, communication and maintenance of information security policies, processes and procedures, including a business continuity and disaster recovery plan.
- Create and update policies and procedures in all information security systems related documents.
- Coordinate with all teams to ensure the implementation of information security programs.
- Coordinate the review of service level agreements of all suppliers / providers relating to information security.
- Coordinate with business process owners in identifying and updating of information security assets and risks.
- Facilitate the information security training and awareness programs and campaigns in coordination with IT and HR departments.
- Conduct information security internal audit at least once a year.
- Investigate and evaluate incident reports and monitor the effectiveness of corrective actions.
- Respond to audit questionnaires, risk assessments and other client assessments on information security.
- Monitor the firm’s compliance with the Data Privacy Act (DPA) of 2012.
- Design and implement programs/policies/activities to ensure compliance to the law (in coordination with lawyers handling DPA).
- Act as the firm’s point person on matters relating to the DPA.
Requirements:
- Graduate of Computer Science, Computer Engineering, Information Technology, or a related field; Certified Information Systems Security Professional (CISSP) certification is preferred.
- With at least 3 years of relevant experience in information security management and/or the implementation and management of business continuity and disaster recovery programs.