XTN-9A12830 | INFORMATION SECURITY AND DATA PRIVACY OFFICER

KMC Careers


Date: 2 days ago
City: Cebu City
Contract type: Full time
The Information Security and Data Privacy O:icer (ISDPO) is responsible for ensuring the confidentiality, integrity, and availability of sensitive information and data within the organization. The ISDPO will develop, implement, and maintain information security and data privacy policies, procedures, and controls to ensure compliance with relevant regulations, standards, and industry best practices. The ISDPO will also serve as a subject matter expert on HIPAA, SOC II, GDPR, and other compliance requirements.

  • Health Insurance/HMO
  • Enjoy unlimited MadMax Coffee
  • Diverse learning & growth opportunities
  • Accessible Cloud HR platform (Sprout)
  • Above standard leaves
  • Miscellaneous allowance
  • Loans
  • Compliance and Risk Management:
    • Develop and maintain a comprehensive information security and data privacy program that ensures compliance with HIPAA, SOC II, GDPR, and other relevant regulations and standards.
    • Identify and assess information security and data privacy risks, and develop strategies to mitigate or remediate those risks.
    • Conduct regular risk assessments and vulnerability assessments to identify potential security threats and weaknesses.
  • Policy and Procedure Development:
    • Develop, implement, and maintain information security and data privacy policies, procedures, and standards that align with industry best practices and regulatory requirements.
    • Ensure that all policies and procedures are reviewed, updated, and approved on a regular basis.
  • Incident Response and Management:
    • Develop and maintain an incident response plan that outlines procedures for responding to security breaches, data breaches, and other security incidents.
    • Coordinate incident response activities, including containment, eradication, recovery, and post-incident activities.
    • Conduct incident response training and awareness programs for employees.
  • Security Awareness and Training:
    • Develop and implement security awareness and training programs for employees, including phishing simulations, security training, and data privacy training.
    • Ensure that all employees understand their roles and responsibilities in maintaining information security and data privacy.
  • Audit and Compliance:
    • Conduct regular audits and assessments to ensure compliance with information security and data privacy policies, procedures, and regulations.
    • Identify and report any non-compliance issues to management and recommend corrective actions.
  • Vendor Management:
    • Develop and maintain vendor management policies and procedures that ensure vendors meet information security and
    • Conduct vendor risk assessments and due diligence to ensure vendors are compliant with relevant regulations and standards.
  • Data Privacy:
    • Develop and maintain data privacy policies and procedures that ensure compliance with GDPR, HIPAA, and other relevant regulations.
    • Conduct data privacy impact assessments and risk assessments to identify potential data privacy risks.
  • Communication and Collaboration:
    • Serve as a liaison between the IT department, business units, and other stakeholders to ensure e:ective communication and collaboration on information security and data privacy matters.
    • Provide guidance and support to employees on information security and data privacy best practices.
  • Staying Current with Industry Developments:
    • Stay up-to-date with the latest industry developments, trends, and best practices in information security and data privacy.
    • Participate in industry conferences, webinars, and training programs to stay current with emerging threats and technologies
    • Bachelor's degree in Computer Science, Information Assurance, or a related field.
    • Minimum 5 years of experience in information security, data privacy, or a related field.
    • Strong knowledge of HIPAA, SOC II, GDPR, and other relevant regulations and standards.
    • Experience with any information security and data privacy frameworks, such as NIST, ISO 27001, and COBIT.
    • Strong analytical and problem-solving skills.
    • Excellent communication and interpersonal skills.
    • Ability to work in a fast-paced environment and prioritize multiple tasks and projects.
    • Certification in information security or data privacy, such as CISSP, CISM, or CIPP, is preferred
    • BPO experience (and setting these compliances up), would be a plus!


    As previously mentioned.

    How to apply

    To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

    Post a resume

    Similar jobs

    Site Controller - Onsite Cebu

    Staff Outsourcing Solutions, Cebu City
    4 days ago
    This position is responsible for providing financial control, analysis, and support to our Corporate Controller. Responsible for the preparation and oversight of all Statutory reporting. Assist with month-end close & year-end close processes Oversee the purchase ledger and sales ledger function Prepare monthly account reconciliations for assigned Balance Sheet Accounts Prepare monthly financial statements in accordance with U.S. GAAP Prepare...

    Inventory Specialist

    AboitizPower, Cebu City
    1 week ago
    Job ID: 1801Location: BaniladCompany: Visayan Electric Co., Inc.Department: VECO Material Management DepartmentEmployment Type: RegularWork Arrangement: On-SiteThe position is responsible for providing support in the establishmentand enforcement of inventory controls to ensure the security,accuracy and availability of materials and supplies and its records.

    HR Generalist

    MedSpecialized, Inc., Cebu City
    1 week ago
    MedSpecialized, Inc. is looking for a HR Associate!General Description: The HR Associate will be responsible for monitoring and implementing the onboarding process for new hires until they are endorsed for nesting. This resource will also be responsible for keeping records updated and accurate at all times and as well as collecting requirements.Work Arrangement: Nightshift, 11AM - 8PM; Office-based SetupOffice Location:...