Overview

Head of Cybersecurity Jobs in Mandaluyong, National Capital Region, Philippines at Jardine Service Centre

Title: Head of Cybersecurity

Company: Jardine Service Centre

Location: Mandaluyong, National Capital Region, Philippines

About Jardine Service Centre (JSC)

Jardine Service Centre Philippines is an organization fully owned by Jardine Matheson Group which is a diversified Asian-based group with unsurpassed experience in the region, having been founded in 1832. JSC is responsible for providing back-office support to the business units of Jardine Group by administrating transactional and rule-based activities. We aim to deliver world class services to our internal customers in a cost-efficient manner via process harmonization, application of state-of-the-art technologies, automation and process simplification.

At JSC we are scaling our technology capabilities in a broad array of different leading platforms. Our team is responsible for both application maintenance and development; delivering the technology and business solutions that will revolutionize how our various business units operate.

Role Summary

  • Reporting to the Head of Technology Services of the Jardine Matheson Group, the focus of this role is to manage and enhance the cyber ops services provided by the Group’s shared services center (SSC) to its portfolio companies for securing their operations.
  • This position requires an individual with in-depth experience in both a managed security services environment as well as in an in-house security operations role consuming such services. The ideal candidate will be experienced in security architecture, engineering, operations and response and have experience in a regional role.
  • The candidate will need to work with the companies to develop, implement and operate services to implement new security controls, mature existing services, and in conjunction with the companies reengineer their security processes to incorporate the SSC into their security and IT processes.

Key Responsibilities

1) Security Architecture (Security by Design)

  • Develop services to help companies define, document and improve their security architecture covering systems, networks and cloud environments and to map the security controls across their IT landscape.
  • Develop and implement a risk and threat assessment service to help companies assess their threats and security controls to identify gaps. Enhance current SSC services or design and implement new ones to address identified gaps, including to manage new security controls.

2) Security Engineering (Tooling, Hardening, Reliability)

  • Develop services to help companies deploy, configure, and maintain cybersecurity tools (e.g., SIEM, SOAR, EDR/XDR, SEG, NGFW, DLP, SASE, IAM, vulnerability scanning, cloud security platforms), ensuring secure configuration and operational reliability.
  • Improve the quality and maturity of current processes for managing security tools to maximize effectiveness of the controls they provide through monitoring, testing and regular tuning to improve performance and accuracy and reduce false positives.
  • Ensure security processes managed by the SSC are fully integrated from threat intel monitoring through to tuning of security configurations or operations to address new threats to ensure that the SSC fully owns and manages all security tools and operational processes it provides.
  • Handle operational engineering tasks such as alert triage support, rule tuning, use-case updates, security tool health checks (agents, connectors, data ingestion) and troubleshooting.
  • Ensure controls and processes align with security standards, compliance requirements, and architectural principles.
  • Document security controls, configurations, operational procedures, and runbooks/playbooks for repeatable operations.
  • Customize playbooks and operational processes for each company to fit its IT landscape and operations.

3) Security Operations (Incident Response Leadership & Coordination)

  • Support companies in investigating alerts and managing security incidents in accordance with their playbooks and IR plan.
  • Execute containment, eradication and recovery activities in conjunction with the company’s security team.
  • Contribute to post-incident reviews: document timelines, root causes, lessons learned and drive corrective actions to prevent recurrence.
  • Support companies’ IR plan testing and improvement activities.

4) Governance, Risk & Compliance

  • Develop a risk assessment framework and service to help companies document, quantify priorities and mitigate cyber risks.
  • Improve maturity of current processes and strengthen capabilities for assessing vendor risk, the security of technology tools and services they provide, and how these fit within the controls and security architecture.
  • Support security awareness training and validation.
  • Maintain metrics and measurements to help companies understand their security posture, both operationally and from a Board level perspective.

5) Business and Team Management

  • Work with the Group’s companies to understand and influence their security strategies and adapting the shared services center to address their needs, especially when adopting new security technologies across multiple companies.
  • Manage a team of security professionals and success managers to deliver a growing set of managed security services, as described above, to protect the business operations of the Group’s companies.
  • Continually raise the maturity of the services provided and enhancing the service catalogue to address evolving cyber threats and the needs of the Group’s companies.
  • Manage the P&L of the team to achieve a zero-bottom line by apportioning costs based on service consumption.

Requirements

  • University graduate in Cybersecurity or IT, with 10+ years' work experience in the information security field, with technical, operational and GRC experience in MSP and in-house environments.
  • Demonstrated hands-on experience designing and implementing security controls across enterprise infrastructure (Windows/Linux, AD, networking) and cloud environments (Azure/AWS/GCP).
  • Strong experience with security tooling operations and detection engineering (log onboarding, correlation/detections, tuning, and response actions).
  • Proven incident response experience including containment, eradication, and recovery coordination across multiple teams.
  • Strong documentation skills: ability to create clear runbooks, playbooks, standards, and technical guidance for engineers and operators.
  • Strong hands-on experience deploying, operating, and improving security tooling and detection capabilities.
  • Hands-on experience reviewing, assessing, and maintaining network security controls, including firewall and network security policy reviews, rule-base optimization, risk-based access validation, and remediation recommendations.
  • Experience with SOAR automation and scripting (Python/PowerShell) to improve response and operational efficiency.
  • Familiarity with security and control frameworks (e.g., NIST CSF/800-53, ISO 27001, CIS Benchmarks) and threat frameworks (MITRE ATT&CK).
  • Certified in information security disciplines such as CISSP, CISM, CCSP, or GIAC (e.g., GCIH, GCIA, GCED); cloud security certifications (Azure/AWS/GCP)
  • Ability to communicate with various stakeholders, including technical and executive level staff.
  • Experience in working in a regional or global role.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

At JSC, you can play a role in our business success. We understand that key to our success is our people, which is our foundation and priority. We invest in our people to ensure we have the right talent with the leadership and strategic skills the company needs for the future.

We are an equal opportunity employer and do not discriminate on the grounds of sex, race, disability, family status or any other factors.

Come and explore with us!

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.