- Location
- Manila, Manulife Business Processing Services, Philippines
- Type
- Full-time
- Department
- IT
- Seniority
- Manager
- Closing date
- Today
- Source
- Workday
Description
We are looking for an Information Technology (IT) Security Manager who will report to the Asia Regional Office Security Officer within the Asia Cybersecurity & Information Security Office (CISO). The role will serve as the Information Security Officer for the BUSO Center of Excellence (CoE), with primary responsibility for leading and performing information risk assessments across Asia markets.
The BUSO CoE supports market Business Unit Security Officers in executing the technology controls program and managing information and operational risks. It provides specialized services across risk assessments, high-risk service requests, security monitoring, BAU controls, and process improvement and automation.
As part of Line 1B, the team partners with business and technology leaders to identify and mitigate risks, strengthen the control environment, and provide a consistent view of key risks. It also works closely with Line 2 to align with enterprise policies and standards.
Position Responsibilities:
Lead and perform end-to-end Project Information Risk Assessments across Asia markets, from initial scoping and information criticality assessment through risk identification, control evaluation, risk treatment, remediation tracking, and business risk acceptance.
Review assessments completed by market or designated assessors to ensure the consistent application of risk methodologies, control requirements, documentation standards, and quality expectations.
Analyze project designs, architectures, data flows, technology components, third-party arrangements, and applicable security requirements to identify information security and operational risks.
Translate assessment findings into clear risk statements and practical recommendations; advise project, technology, and business stakeholders on appropriate mitigation strategies and compensating controls.
Monitor risk-treatment plans, commitments, exceptions, and risk acceptances; maintain assessment schedules and records, follow up on overdue actions, and escalate material or unresolved risks through the appropriate governance channels.
Develop and maintain the regional information risk assessment framework, including playbooks, templates, procedures, training materials, quality assurance plans, standardized reporting, performance measures, and mechanisms for sharing best practices.
Promote the information risk assessment program across Asia markets and provide guidance to market BUSOs, assessors, project teams, and other stakeholders to strengthen risk ownership and assessment quality.
Provide application and information security consultation to project teams, technology partners, and business stakeholders, including facilitating specialized security assessments when required.
Partner with market BUSOs and relevant control functions to identify operational security and risk-management activities suitable for centralization, standardization, automation, or transition to the CoE.
Establish and maintain effective governance for CoE services, including service scope, roles and responsibilities, onboarding and offboarding procedures, reporting, service measures, issue management, and escalation paths.
Deliver assigned centralized security and operational risk activities consistently and within agreed service expectations, including analysis of high-risk service requests and support for other BAU control processes.
Support the end-to-end management and timely resolution of security incidents, particularly Data Loss Prevention incidents, in coordination with market BUSOs and relevant response teams.
Provide regular status, risk, and performance updates to market BUSOs and regional stakeholders, highlighting key findings, trends, overdue actions, emerging risks, and matters requiring decision or escalation.
Conduct knowledge transfer, coaching, and knowledge-sharing sessions for new team members, market assessors, and IT control and governance teams.
Contribute to continuous improvement initiatives that enhance the effectiveness, efficiency, scalability, and consistency of regional security and risk-management processes.
Required Qualifications:
University or college degree in information technology, cybersecurity, information systems, risk management, or a related field.
At least 3–5 years of progressive experience in information security management, technology risk, or IT controls, including experience performing responsibilities comparable to an Information Security Officer.
Hands-on experience conducting and reviewing information security risk assessments for projects and business-as-usual operations, including risk identification, control assessment, risk treatment, remediation tracking, and risk acceptance.
Practical knowledge of security and operational risk processes, including security incident management, access reviews, data loss prevention, vulnerability and patch management, business continuity, and disaster recovery.
Strong understanding of information risk management principles, the confidentiality, integrity, and availability triad, and zero-trust concepts.
Experience developing or applying standardized procedures, governance mechanisms, reporting, quality assurance, and escalation processes across multiple stakeholders or business units.
Ability to analyze complex issues and translate them into clear risk statements, reports, recommendations, and practical solutions.
Strong stakeholder-management and collaboration skills, with the ability to work effectively with business, technology, cybersecurity, risk, compliance, and other control functions.
Excellent written and verbal communication skills, including the ability to explain technical risks, options, and outcomes to both technical and non-technical audiences.
Self-driven and organized, with sound judgment, strong problem-solving skills, and the ability to manage multiple priorities with minimal supervision.
Commitment to continuous learning, knowledge sharing, adaptability, and process improvement.
Preferred Qualifications:
Professional certification in information security, technology risk, audit, or governance, such as CISM, CISSP, CRISC, CISA, or an equivalent credential.
Experience in the financial services or insurance industry, including familiarity with regulatory, privacy, and operational resilience expectations.
Knowledge of recognized security and governance frameworks, such as ISO/IEC 27001, the NIST Cybersecurity Framework, COBIT, or equivalent standards.
Experience supporting regional or multi-market security programs, a Center of Excellence, or a shared-services operating model.
Demonstrated experience standardizing, centralizing, automating, or improving information security and risk-management processes.
Working knowledge of relevant workflow, governance, monitoring, reporting, and collaboration platforms, such as ServiceNow, Jira, Power BI, ProcessUnity, Confluence, Archer, Devo, or BlueCat Address Manager.
Experience facilitating security assessments, consulting on application security risks, or coordinating remediation across technology and business teams.
When you join our team:
We’ll empower you to learn and grow the career you want.
We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
As part of our global team, we’ll support you in shaping the future you want to see.
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].
Working Arrangement