EXUS Manila, National Capital Region, Philippines
Head of Security (Fully Remote)
EXUS is an enterprise software company focused on simplifying risk management software and delivering the EXUS Financial Suite (EFS) to financial entities worldwide. Our team collaborates to innovate and provide secure, reliable software solutions. We offer a creative, fun, and inspiring working environment with a focus on growth and the greater good.
Our shared Values :
- We are transparent and direct
- We are positive and fun, never cynical or sarcastic
- We are eager to learn and explore
- We put the greater good first
- We are frugal and we do not waste resources
- We are disciplined and deliver on our promises
Role : EXUS is looking for a Head of Security to join us remotely. This role reports directly to the CTO and requires a strong focus on DevSecOps practices.
Overview : This position focuses on cloud security strategy and leadership for managed services, with emphasis on secure delivery and security integration across development and operations.
Main duties :
Lead Cloud Security Strategy for Managed ServicesLead a security team supporting cloud services, including DevSecOps engineers and cloud security architectsCollaborate with cloud operations, DevOps, compliance, and client success teams to ensure secure delivery of managed servicesSecure cloud and on-premises infrastructure, containerized workloads, and Kubernetes clustersImplement and monitor compliance with industry security benchmarks (e.g. CIS, NIST)Automate auditing and evidence collection for compliance certifications such as PCI-DSS and ISO 27001Implement a shift-left security strategy by integrating security controls and scanning tools into CI / CD pipelines (SAST, DAST, container image scanning)Design and implement threat detection, prevention, and response mechanisms (e.g. IDS, runtime security)Collaborate with IT teams to secure and automate internal systems, endpoints, and servicesEstablish and enforce Kubernetes security policies (RBAC, network policies, Pod Security Standards)Provide security guidance to development teams and enforce secure coding and deployment practicesQualifications :
BSc in Computer Science, Cybersecurity, or related field (MSc is a plus)8+ years in DevOps, Security Engineering, or DevSecOpsDeep expertise in cloud security (AWS, Azure, or GCP)Infrastructure as Code (Terraform, Ansible) and related tooling (e.g. Trivy, Checkov)CI / CD security practices and toolsIdentity and access management (IAM)Scripting proficiency (Python, Bash) for automationExperience with compliance frameworks (PCI-DSS, ISO 27001) and security monitoring / SIEM toolsPreferred Skills :
Certifications such as CISSP, GCPN, or CKSExperience with Zero Trust architecture and endpoint securityKnowledge of container security platforms and tools (Aqua, Prisma Cloud, Sysdig, Falco)Incident response leadership or participationGeneral skills :
Excellent English communication (verbal & written)Strong problem-solving and analytical thinkingTeam player, self-motivated, continuous learnerFulfilled military obligationsBenefits :
Fully remote work setupCompetitive salaryInclusive work environment & Well-being ProgramClear induction program & mentoring buddyPrivate health insurance allowanceUnlimited time offPrivacy Notice for Job Applications :
#J-18808-Ljbffr