Skip to content

Open nowPosted 4 days ago

Head of IT Security

hubexo69 open roles

Where
Makati City, Metro Manila, Philippines
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowHead of IT Securityhubexo · Makati City, Metro Manila, Philippines
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on hubexo's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 4 days ago

The posting

About UsHubexo provides cutting-edge data, insights, and software solutions to the global construction industry. Founded in Sweden in 1936, Hubexo specializes in project information, eTendering, product information, market intelligence, and specification solutions.With operations in more than 20 countries and a workforce of 2,500 employees, Hubexo helps customers sell more efficiently, build sustainably, and shape the future of construction innovation.In the Philippines, Hubexo operates under the legal name BCI Central. The OpportunityWe are looking for an experienced and hands-on Head of IT Security to lead Hubexo's security posture end to end. This role is accountable for day-to-day IT operations, incident response, third-party risk, and our ISO 27001 and SOC 2 compliance programmes. You will be the single accountable leader for keeping Hubexo secure, audit-ready, and trusted by our customers.Hubexo is part-way through a major migration programme, consolidating systems, platforms, and ways of working into a single operating model. As we introduce new SaaS platforms, integrations, and vendors, security needs to keep pace with the transformation. You will play a key role in ensuring new and existing systems are appropriately secured, assessed, monitored, and brought into compliance scope. This is a hands-on leadership role. You will set the security strategy and lead the programme while remaining close enough to the detail to lead an incident, challenge a vendor's security position, review a penetration testing finding, or work directly with technical teams to resolve risk. Key Responsibilities Security leadership and strategy

Define and deliver Hubexo's information security strategy and roadmap, aligned to business and migration priorities. Own the security risk register and report risk, security posture, and compliance status to senior leadership. Build a security-aware culture through policies, training, and practical guidance for colleagues. Own and manage the IT security budget, tooling, and supplier contracts.

IT Operations

Lead the IT Operations function, including end-user computing, identity and access management, device management, and core infrastructure. Ensure secure-by-default configuration across Microsoft 365, endpoints, networks, and SaaS platforms. Set and track service levels for IT support, patching, backup, and recovery. Ensure systems introduced through the migration are onboarded, hardened, monitored, and decommissioned correctly.

Incident response

Own the incident response plan, playbooks, and escalation paths, and test them through regular tabletop exercises. Lead the response to security incidents, from triage and containment through to root cause analysis and lessons learned. Coordinate with Legal, Communications, and leadership on breach notification and regulatory obligations, including UK GDPR. Maintain business continuity and disaster recovery plans for critical systems.

Compliance: ISO 27001 and SOC 2

Lead Hubexo's ISO 27001 certification and SOC 2 attestation, including scope, control ownership, internal audits, and external audit cycles. Own and administer Vanta as the compliance platform, including integrations, control monitoring, evidence collection, policies, and remediation tracking. Keep the ISMS current as systems, vendors, and processes change through the migration. Support Sales and Customer Success with security questionnaires, trust documentation, and customer audits.

Vendor and third-party security

Run the vendor security assessment process for new and existing suppliers, proportionate to risk. Review vendor evidence, including SOC 2 reports, ISO certificates, and security questionnaires, and agree on remediation or risk acceptance. Work with Procurement and Legal to embed security and data protection requirements into contracts.

Penetration testing and vulnerability management

Own and drive the penetration testing roadmap in partnership with the Tech Delivery team, covering products, infrastructure, and new integrations. Select and manage penetration testing providers, scope engagements, and track findings through to resolution. Run vulnerability management across infrastructure and applications, with clear remediation SLAs based on severity.

External SOC partnership

Manage the relationship with our external SOC provider, including service levels, detection coverage, and escalation routes. Review SOC reporting, tune alerting, and ensure new systems feed into monitoring. Act as the internal escalation point for SOC-raised alerts and incidents.

What Success Looks LikeFirst 90 days

Security risk register and roadmap agreed with leadership. Vanta control gaps reviewed and a remediation plan underway. Incident response plan tested through at least one tabletop exercise. SOC service levels and escalation routes reviewed and confirmed.

Within 12 months

ISO 27001 and SOC 2 audits completed with no major non-conformities. Penetration testing roadmap delivered for the year, with critical and high findings remediated within agreed SLAs. All critical vendors assessed and tracked through a single third-party risk management process. Migrated systems fully incorporated into compliance scope and monitored by the SOC.

Qualifications & ExperienceEssential

8+ years of experience in IT security or IT operations, including at least 3 years leading a security or IT function. Proven experience delivering ISO 27001 certification and/or SOC 2 attestation, including ownership of external audits. Hands-on experience running a compliance automation platform, ideally Vanta. Experience with Drata or Secureframe is also relevant. Experience leading security incidents end to end and building or managing an incident response programme. Experience establishing and running a vendor / third-party security assessment process. Experience scoping and managing penetration tests and driving remediation with engineering teams. Experience managing an outsourced SOC or MDR provider and holding them accountable to agreed service levels. Strong working knowledge of Microsoft 365 / Entra ID security, endpoint management, and cloud environments such as AWS or Azure. Clear communicator who can explain security risks to non-technical leaders and influence without direct authority. Must be willing to work on a mid-shift schedule with a hybrid work setup in Makati City.

Nice to Have

Security experience in a SaaS or data business, ideally through a merger, integration, or platform migration. Familiarity with securing SaaS platforms and integrations such as HubSpot, NetSuite, Chargebee, and Make.com. Knowledge of UK GDPR and data protection obligations across multiple jurisdictions. Certifications such as CISSP, CISM, ISO 27001 Lead Implementer, or Lead Auditor. Experience with Cyber Essentials Plus or other customer-driven security frameworks.

Why Join Hubexo?

Be part of a global organization driving innovation in the construction technology industry. Work closely with international teams and enterprise transformation initiatives. Hybrid work setup with a collaborative and flexible work environment. Opportunity to lead security, governance, and transformation initiatives with global impact. Gain exposure to large-scale global IT, security, and business systems projects. Play a key leadership role in strengthening Hubexo's security posture as the organization continues its global transformation.

If you are a hands-on security leader who can balance strategic direction with operational execution, compliance, and technical risk management, we'd love to hear from you.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against hubexo's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on hubexo's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    hubexo's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.