Metro Manila, National Capital Region, Philippines
As the Chief Information Security Officer and Data Protection Officer at Yuanta Savings Bank, I lead our organization’s strategic efforts to safeguard critical information assets, ensure the confidentiality, integrity, and availability of systems and data, strengthen cybersecurity governance, manage technology and information security risks, and support regulatory compliance. My work focuses on cybersecurity governance, information security management, technology risk management, data privacy, regulatory compliance, incident response, third-party risk, operational resilience, audit readiness, and Board-level cybersecurity reporting. I support the alignment of cybersecurity programs with recognized frameworks and regulatory expectations, including ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27005, NIST Cybersecurity Framework, BSP regulations, and the Philippine Data Privacy Act. Beyond my corporate role, I compile and publish practical cybersecurity, information security governance, GRC, data privacy, IT risk management, regulatory compliance, audit readiness, operational resilience, and Board oversight references for Philippine financial institutions. Practical CISO Handbook Series for Philippine Financial Institutions: https://azoresphere4.gumroad.com/
Established and maintain a comprehensive corporate information security and risk management program to ensure that the integrity, confidentiality and availability of information asset is manage against unauthorized access, use, alteration, disclosure, disruption, modification, inspection, recording or destruction.
• Created and ran the Information Security Department charged with creating and maintaining the security architecture for all technology platforms. • Responsible for the development of Information Security Management Systems based on Information Security Standard (ISO 27001 and ISO 27002). • Responsible for all aspects of security engineering, architecture, vulnerability and threat management for the organization with an emphasis on proactive and preventive controls that continually enhance the programs ability to identify, assess, and respond to Information Security threats. • Manages the overall conduct of Information Security Audit (Internal Audit, 3rd Party Audit and BSP Audit) • Responsible for the setting up of Security Operation Center (SOC) to monitor, assess and defend the Enterprise Information Systems (Applications, Database, Data Centers, Servers, Networks, Desktop and other end points) • Responsible for the Set-up implementation on Information Security Website and Information Security Groups. • Lead in the development of Security Procedures such as: Incident Management Procedures, Information Security Management Procedures, User Account Management Procedures and Change Management Procedures. • Lead in the development of Security Programs such as: Information Security Awareness Programs, Information Security Programs and Information Security Risk Management Program • Lead in the creation of Minimum Baseline Security Standard (MBSS) for the following technology: Windows 2003, SQL Server, Oracle Server, Secure Application Development Standards, Switch, Router, Firewall and Personal Computer Minimum Baseline Security Standard. • Lead in the IT Systems and Operations Audit based on the approved Minimum Baseline Security Standards, Policies and Procedures.
Responsible for the security deployment and implementations of the security technologies such as Security Information and Event Management Tools, Patch Management, Network Access Control and Network Management Systems