Janrenz R.

CSO | GRC Advisor | Security Consultant

Metro Manila

About

Certified Payment Industry Security Implementer (CPISI) of PCI DSS. I am a cybersecurity and compliance professional with leadership experience as a CSO for a US-based FinTech company and previously as Head of Cybersecurity Training and Certification Services, where I actively engage with clients and organizations to help them build capability, upskill teams, and achieve certifications such as ISO 27001, ISO/IEC 42001 (AI Management Systems – AIMS), and other PECB cybersecurity training and certification programs. I also previously served as an IT Security Manager for a global BPO organization. I am a Certified Payment Industry Security Implementer (CPISI) with extensive experience working with international clients to help organizations achieve their security and compliance objectives, including SOC 2, ISO 27001, NIST Cybersecurity Framework (CSF), GDPR, PCI DSS, BSP Circular 982, and other regulatory and industry standards. I strongly believe that organizations should aim not only for regulatory compliance, but also for a sustainable and mature security posture that effectively manages risk. Opinions expressed here are my own and do not necessarily reflect my employer's views or strategy.

Experience

  • Confidential (8 yrs 4 mos)
    • Security Consultant/Independent Contractor
      Apr 2018 - Present · 8 yrs 4 mos

      I am an independent cybersecurity consultant with experience working with global clients to design and implement cybersecurity programs from the ground up. I help organizations strengthen their security posture, establish governance and compliance processes, and achieve certifications and compliance requirements such as SOC 2, ISO/IEC 27001, HIPAA and PCI DSS. I also bring hands-on experience implementing cybersecurity technologies, vulnerability management programs, and penetration testing initiatives to help organizations identify and reduce security risks. Throughout my career, I have held leadership positions including CSO for a US-based fintech company, Head of Cybersecurity Training for an Ireland-based cybersecurity consulting company, and IT Security Manager for a global BPO organization. My background includes security program development, risk management, policy implementation, security assessments, compliance readiness, and cybersecurity operations across growing and international organizations.

    • Head of Cybersecurity Training and Certification Services
      Feb 2025 - Jan 2026 · 1 yr

      Leads the development and delivery of the company’s cybersecurity training and certification programs (ISO 27001), ensuring alignment with industry standards and client needs. Oversees project management and business development to expand training services and partnerships. Provides cybersecurity consultancy support to clients, strengthening their security capabilities and compliance readiness.

    • Information Technology Security Manager II
      Aug 2021 - Aug 2024 · 3 yrs 1 mo

      IT Security Manager II for a global BPO leading enterprise security and compliance across nationwide offices and client environments. Designed and implemented a unified Information Security Program aligned with SOC 2, ISO/IEC 27001, and PCI DSS, enabling consistent control mapping across multiple regulatory requirements and reducing audit preparation effort by ~40%. Led end-to-end SOC 2, ISO 27001, and PCI DSS implementations for multiple clients, achieving successful audits and ongoing compliance.

  • IT Specialist - Intern at Confidential
    Apr 2016 - Jun 2016 · 3 mos

    After my Internship with an Electronics Company wherein I've learned how to secure Enterprises by deploying "Physical Controls" I've decided to pursue an internship in the IT Realm. Literally acquired new knowledge about Active Directory and Computer Networking during my stay in this Organization. Also, learned how to communicate effectively with different people and how to work in a fast paced environment. This was the start of me pursuing a career in IT specifically within Security Domain.

  • Electronics Engineer - Intern at Confidential
    Apr 2015 - May 2015 · 2 mos

    Learned the Physical Aspect of Securing Enterprises. Had a great experience of designing and implementing Intrusion Detection & Alarms, Physical Access Systems, Access Control & Biometrics, Closed Circuit Televisions, Public Address & BGM System and Wireless Broadband Solutions.