About UsHubexo provides cutting-edge data, insights, and software solutions to the global construction industry. Founded in Sweden in 1936, Hubexo specializes in project information, eTendering, product information, market intelligence, and specification solutions.With operations in more than 20 countries and a workforce of 2,500 employees, Hubexo helps customers sell more efficiently, build sustainably, and shape the future of construction innovation.In the Philippines, Hubexo operates under the legal name BCI Central.
The OpportunityWe are looking for an experienced and hands-on Head of IT Security to lead Hubexo's security posture end to end. This role is accountable for day-to-day IT operations, incident response, third-party risk, and our ISO 27001 and SOC 2 compliance programmes.
You will be the single accountable leader for keeping Hubexo secure, audit-ready, and trusted by our customers.Hubexo is part-way through a major migration programme, consolidating systems, platforms, and ways of working into a single operating model. As we introduce new SaaS platforms, integrations, and vendors, security needs to keep pace with the transformation. You will play a key role in ensuring new and existing systems are appropriately secured, assessed, monitored, and brought into compliance scope.
This is a hands-on leadership role. You will set the security strategy and lead the programme while remaining close enough to the detail to lead an incident, challenge a vendor's security position, review a penetration testing finding, or work directly with technical teams to resolve risk.
Key Responsibilities
Security leadership and strategy
Define and deliver Hubexo's information security strategy and roadmap, aligned to business and migration priorities.
Own the security risk register and report risk, security posture, and compliance status to senior leadership.
Build a security-aware culture through policies, training, and practical guidance for colleagues.
Own and manage the IT security budget, tooling, and supplier contracts.
IT Operations
Lead the IT Operations function, including end-user computing, identity and access management, device management, and core infrastructure.
Ensure secure-by-default configuration across Microsoft 365, endpoints, networks, and SaaS platforms.
Set and track service levels for IT support, patching, backup, and recovery.
Ensure systems introduced through the migration are onboarded, hardened, monitored, and decommissioned correctly.
Incident response
Own the incident response plan, playbooks, and escalation paths, and test them through regular tabletop exercises.
Lead the response to security incidents, from triage and containment through to root cause analysis and lessons learned.
Coordinate with Legal, Communications, and leadership on breach notification and regulatory obligations, including UK GDPR.
Maintain business continuity and disaster recovery plans for critical systems.
Compliance: ISO 27001 and SOC 2
Lead Hubexo's ISO 27001 certification and SOC 2 attestation, including scope, control ownership, internal audits, and external audit cycles.
Own and administer Vanta as the compliance platform, including integrations, control monitoring, evidence collection, policies, and remediation tracking.
Keep the ISMS current as systems, vendors, and processes change through the migration.
Support Sales and Customer Success with security questionnaires, trust documentation, and customer audits.
Vendor and third-party security
Run the vendor security assessment process for new and existing suppliers, proportionate to risk.
Review vendor evidence, including SOC 2 reports, ISO certificates, and security questionnaires, and agree on remediation or risk acceptance.
Work with Procurement and Legal to embed security and data protection requirements into contracts.
Penetration testing and vulnerability management
Own and drive the penetration testing roadmap in partnership with the Tech Delivery team, covering products, infrastructure, and new integrations.
Select and manage penetration testing providers, scope engagements, and track findings through to resolution.
Run vulnerability management across infrastructure and applications, with clear remediation SLAs based on severity.
External SOC partnership
Manage the relationship with our external SOC provider, including service levels, detection coverage, and escalation routes.
Review SOC reporting, tune alerting, and ensure new systems feed into monitoring.
Act as the internal escalation point for SOC-raised alerts and incidents.
What Success Looks LikeFirst 90 days
Security risk register and roadmap agreed with leadership.
Vanta control gaps reviewed and a remediation plan underway.
Incident response plan tested through at least one tabletop exercise.
SOC service levels and escalation routes reviewed and confirmed.
Within 12 months
ISO 27001 and SOC 2 audits completed with no major non-conformities.
Penetration testing roadmap delivered for the year, with critical and high findings remediated within agreed SLAs.
All critical vendors assessed and tracked through a single third-party risk management process.
Migrated systems fully incorporated into compliance scope and monitored by the SOC.
Qualifications & ExperienceEssential
8+ years of experience in IT security or IT operations, including at least 3 years leading a security or IT function.
Proven experience delivering ISO 27001 certification and/or SOC 2 attestation, including ownership of external audits.
Hands-on experience running a compliance automation platform, ideally Vanta. Experience with Drata or Secureframe is also relevant.
Experience leading security incidents end to end and building or managing an incident response programme.
Experience establishing and running a vendor / third-party security assessment process.
Experience scoping and managing penetration tests and driving remediation with engineering teams.
Experience managing an outsourced SOC or MDR provider and holding them accountable to agreed service levels.
Strong working knowledge of Microsoft 365 / Entra ID security, endpoint management, and cloud environments such as AWS or Azure.
Clear communicator who can explain security risks to non-technical leaders and influence without direct authority.
Must be willing to work on a mid-shift schedule with a hybrid work setup in Makati City.
Nice to Have
Security experience in a SaaS or data business, ideally through a merger, integration, or platform migration.
Familiarity with securing SaaS platforms and integrations such as HubSpot, NetSuite, Chargebee, and Make.com.
Knowledge of UK GDPR and data protection obligations across multiple jurisdictions.
Certifications such as CISSP, CISM, ISO 27001 Lead Implementer, or Lead Auditor.
Experience with Cyber Essentials Plus or other customer-driven security frameworks.
Why Join Hubexo?
Be part of a global organization driving innovation in the construction technology industry.
Work closely with international teams and enterprise transformation initiatives.
Hybrid work setup with a collaborative and flexible work environment.
Opportunity to lead security, governance, and transformation initiatives with global impact.
Gain exposure to large-scale global IT, security, and business systems projects.
Play a key leadership role in strengthening Hubexo's security posture as the organization continues its global transformation.
If you are a hands-on security leader who can balance strategic direction with operational execution, compliance, and technical risk management, we'd love to hear from you.