Manager, Business Security

Posted Yesterday
Be an Early Applicant
Horizon, UT, USA
In-Office
Senior level
Aerospace • Transportation • Travel
The Role
Lead in-country cybersecurity for Philippines AirAsia: align security strategy with business, operationalise GRC and controls (ISO27001/PCI DSS), manage incidents, coordinate audits, drive security adoption, and support BCDR and data protection activities.
Summary Generated by Built In


Job Description

OVERVIEW:

  • Location: Pasay City, Manila

  • Entity: Philippines AirAsia Inc.

  • Status: Full-time

JOB DESCRIPTION:

YOUR ROLE AS A:

As a Business Security Manager at Philippines AirAsia, you will report directly to the Group CISO to provide advice, consultation, and awareness of the Group Information Security requirements to technical teams and other employees, and ensure their implementation. You will be responsible for ensuring internal systems and processes in Indonesia are compliant with information security standards (e.g, ISO 27001, PCI DSS, CIS, NIST CSF, etc); monitoring, managing, and closing information security compliance issues. Other responsibilities include identification, evaluation, and interpretation of standards, regulatory, statutory, and member security requirements, control deficiencies, and information security risks. You are the primary point of contact during information security incidents and are responsible for managing the incident.
 

WHAT YOU’LL CHAMPION:

Stakeholder Collaboration and Management

  • Acts as the primary cybersecurity leader across the business for Philippines, aligning enterprise cybersecurity strategy and roadmap with business objectives.

  • Drive and prioritise implementation and integration/adoption of security capabilities within the BU, including embedding security into business digital projects and operations.

  • Ensure the business-specific threat landscape, risks, and regulatory drivers are clearly articulated to the CISO teams and validate cyber architecture decisions that meet the business’s operational and compliance needs.

  • Provide Strategic Threat Briefings to Business Leadership.

Cyber Governance Risk Compliance(In-Country)

  • Operationalise Cyber Security Risk Management capabilities such as Business Impact Assessment of the Business unit’s digital portfolio of services and applications to identify Crown jewels to be protected in line with Risk appetite. 

  • Deployment of relevant cybersecurity controls, including required local regulatory compliance, to ensure digital solutions, both applications and services, are developed with a secure-by-design principle. 

  • Drives Cyber Risk acceptance, risk mitigation, finding management processes, and risk reporting consistently to ensure Cyber Risks are managed and residual risks understood by the leadership.

  • Represent cybersecurity in external audits, customer security reviews, and regulatory submissions.

  • Actively involved and drive preparations in ​​Business Continuity and Disaster Recovery drills for critical business processes and crown jewels.

  • Work with the in-country Data Protection Officer(s) of AirAsia Aviation on data security requirements.

Cyber Defence (In-Country)

  • Work with Enterprise Cyber Defence to ensure business assets (e.g., endpoints, network devices, applications, business users, etc.)are updated for purposes of security monitoring and vulnerability management

  • Coordinate business communication, impact analysis, business post-incident review, and remediation with the business teams and in compliance with local regulations

Change Management

  • Champion Cyber Security Change program activities to drive awareness, behaviours among the business unit, and increase the Cyber Resilience 

  • Drive implementation and integration/adoption of security capabilities and change management to ensure business alignment and effectiveness.

  • Business-level security KPIs/KRIs (e.g., patch compliance, phishing click rates, third-party risk ratings) dashboards, reports to business leaders, and the enterprise CISO.

WHO YOU ARE:

  • Bachelor's Degree in Information Technology, or Business with IT, Computer Science, or equivalent

  • Minimum 5 years experience in managing Information Security Operation/Governance, Risk Management, and Compliance, or related fields

  • Relevant industry certification is an advantage (ISO 27001, CISA, CISSP, CGEIT, etc)

  • Working knowledge in common IT/information security-related regulations or standards, especially ISO 27001 and PCI-DSS

  • Working knowledge of local information and cybersecurity-related regulations and requirements is a huge advantage

  • Ability to develop, review and maintain documentation in a timely manner

  • Strong communication (spoken and written), interpersonal, and conflict resolution skills. The ability to establish and maintain rapport with stakeholders is highly desired.

  • Strong analytical and critical thinking skills

  • Result-oriented, high level of attention to detail, self-starter and motivator, ability to multitask and adjust to shifting priorities.

WHAT YOU’LL ENJOY:

  •  Physical Wellbeing: Key medical and insurance benefits, maternity expenses, flexible work arrangement, and health and fitness amenities.

  • Emotional Wellbeing: Paid time off, wellness programmes, and childcare amenities. 

  • Financial Wellbeing: Resources relating to financial, personal skills and career growth programmes.

  • Allstars Specials: Free flights, unlimited discounted flights, and exclusive discounts with partners. 

  • A unique Allstar culture like no other

 

OUR HIRING PROCESS:

  • Application Review

  • Application Review and Skills Match

  • Interview & Assessments

  • Background Verification

  • Offer Process

GET TO KNOW AIRASIA:

AirAsia

AirAsia has been the World's Best Low-Cost Airline for 16 consecutive years with over 800 million guests flown. We continue to champion dreams, serve the underserved and connect the world and Asean like no other so Now Everyone Can Fly.

GET TO KNOW US:

Our story begins in 2001 with a dream, two planes and a 40 million ringgit debt. You’ll know us as the ‘Now Everyone Can Fly’ airline (if you don’t, we’re definitely older than you).

Today, we’re more than just an airline. We’re Capital A - a world-class brand that wears many hats. Our mission is to connect people and transform lives in Asean.

Above all, we’re Allstars. We believe in the unbelievable and we dare to dream. We also believe in celebrating all individuals. So no matter your culture and background or if you prefer aisle seat to window seat, we’re excited to have you onboard.

Skills Required

  • Bachelor's degree in Information Technology, Computer Science, Business with IT, or equivalent
  • Minimum 5 years' experience in Information Security operations, governance, risk management, and compliance
  • Working knowledge of ISO 27001 and PCI DSS
  • Working knowledge of local information and cybersecurity-related regulations
  • Ability to develop, review, and maintain security documentation in a timely manner
  • Experience managing security incidents and coordinating post-incident reviews and remediation
  • Strong spoken and written communication, interpersonal, and conflict-resolution skills
  • Strong analytical and critical thinking skills
  • Result-oriented, attention to detail, self-starter, ability to multitask and adapt to priorities
  • Relevant industry certifications (ISO 27001, CISA, CISSP, CGEIT, etc.)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sepang, Selangor Darul Ehsan
13,132 Employees
Year Founded: 2001

What We Do

It all starts here. 23 years ago, a dream took flight - shaping and forever changing the travel industry in Asia. The idea was simple: Make flying affordable for everyone. We made that dream happen. We started an airline in 2001. Today, we’ve evolved to become something much bigger. We’re now a world-class brand, a leading Asean airline, a digital travel and lifestyle platform; and we’re not stopping. If you’re passionate about connecting people and transforming lives, we want you onboard. When it comes to your career, your Allstar journey will be an adventure. Find your dream career destination with us

Similar Jobs

Identity Digital Logo Identity Digital

Staff Devops Engineer

Consumer Web • eCommerce • Internet of Things
Remote or Hybrid
United States
240 Employees
175K-220K Annually

MetLife Logo MetLife

Senior Consultant

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
121K-149K Annually

MetLife Logo MetLife

Software Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
210K-210K Annually

PwC Logo PwC

Architect

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
53 Locations
370000 Employees
99K-232K Annually

Similar Companies Hiring

Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees
PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account