drjobs XTN-9A12830

Employer Active

1 Vacancy
The job posting is outdated and position may be filled
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Cebu - Philippines

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

The Information Security and Data Privacy O:icer (ISDPO) is responsible for ensuring the confidentiality integrity and availability of sensitive information and data within the organization. The ISDPO will develop implement and maintain information security and data privacy policies procedures and controls to ensure compliance with relevant regulations standards and industry best practices. The ISDPO will also serve as a subject matter expert on HIPAA SOC II GDPR and other compliance requirements.

  • Health Insurance/HMO
  • Enjoy unlimited MadMax Coffee
  • Diverse learning & growth opportunities
  • Accessible Cloud HR platform (Sprout)
  • Above standard leaves
  • Miscellaneous allowance
  • Loans
  • Compliance and Risk Management:
    • Develop and maintain a comprehensive information security and data privacy program that ensures compliance with HIPAA SOC II GDPR and other relevant regulations and standards.
    • Identify and assess information security and data privacy risks and develop strategies to mitigate or remediate those risks.
    • Conduct regular risk assessments and vulnerability assessments to identify potential security threats and weaknesses.
  • Policy and Procedure Development:
    • Develop implement and maintain information security and data privacy policies procedures and standards that align with industry best practices and regulatory requirements.
    • Ensure that all policies and procedures are reviewed updated and approved on a regular basis.
  • Incident Response and Management:
    • Develop and maintain an incident response plan that outlines procedures for responding to security breaches data breaches and other security incidents.
    • Coordinate incident response activities including containment eradication recovery and postincident activities.
    • Conduct incident response training and awareness programs for employees.
  • Security Awareness and Training:
    • Develop and implement security awareness and training programs for employees including phishing simulations security training and data privacy training.
    • Ensure that all employees understand their roles and responsibilities in maintaining information security and data privacy.
  • Audit and Compliance:
    • Conduct regular audits and assessments to ensure compliance with information security and data privacy policies procedures and regulations.
    • Identify and report any noncompliance issues to management and recommend corrective actions.
  • Vendor Management:
    • Develop and maintain vendor management policies and procedures that ensure vendors meet information security and
    • Conduct vendor risk assessments and due diligence to ensure vendors are compliant with relevant regulations and standards.
  • Data Privacy:
    • Develop and maintain data privacy policies and procedures that ensure compliance with GDPR HIPAA and other relevant regulations.
    • Conduct data privacy impact assessments and risk assessments to identify potential data privacy risks.
  • Communication and Collaboration:
    • Serve as a liaison between the IT department business units and other stakeholders to ensure e:ective communication and collaboration on information security and data privacy matters.
    • Provide guidance and support to employees on information security and data privacy best practices.
  • Staying Current with Industry Developments:
    • Stay uptodate with the latest industry developments trends and best practices in information security and data privacy.
    • Participate in industry conferences webinars and training programs to stay current with emerging threats and technologies
  • Bachelors degree in Computer Science Information Assurance or a related field.
  • Minimum 5 years of experience in information security data privacy or a related field.
  • Strong knowledge of HIPAA SOC II GDPR and other relevant regulations and standards.
  • Experience with any information security and data privacy frameworks such as NIST ISO 27001 and COBIT.
  • Strong analytical and problemsolving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work in a fastpaced environment and prioritize multiple tasks and projects.
  • Certification in information security or data privacy such as CISSP CISM or CIPP is preferred
  • BPO experience (and setting these compliances up) would be a plus!

As previously mentioned.

Employment Type

Full Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.