Sole certification owner
Led the company's ISMS from documentation restructuring and risk assessment through full certification — and maintained it across subsequent surveillance audits as sole responsible owner.
Senior Information Security & IT Manager
IT & Information Security leader ready for director-level scope — turning IT operations into secure, sustainable, audit-ready business functions.

Certified
ISO 27001 · DPO
01 — Profile
Strategic IT and Information Security leader with 13+ years of experience turning IT operations into secure, sustainable, and audit-ready business functions. Sole owner of an organization-wide ISO 27001:2022 certification — leading the full ISMS lifecycle from gap analysis through certification and ongoing surveillance — while concurrently serving as Data Protection Officer (PDPA/GDPR) and sustainability lead (MSC/CES).
A versatile, hands-on operator who bridges infrastructure, compliance, vendor strategy, and executive reporting in lean environments — recognized for operationalizing secure Generative AI workflows that cut administrative overhead by ~30% without compromising data governance.
At a glance
02 — Impact
Outcomes that pair rigorous governance with measurable business value.
Led the company's ISMS from documentation restructuring and risk assessment through full certification — and maintained it across subsequent surveillance audits as sole responsible owner.
Designed secure Generative AI workflows to automate ISO documentation and gap analysis, cutting administrative overhead by ~30% while enforcing strict data-governance controls.
Led the digital transformation to Google Workspace, consolidating collaboration tooling and reducing recurring licensing costs against rising enterprise renewal pricing.
Embedded carbon tracking into operations aligned to the Singapore Green Plan 2030 using MSC and CES frameworks — a rare dual credential pairing IT governance with ESG.
03 — Capabilities
A full-stack leadership toolkit spanning compliance, strategy, infrastructure, and ESG. Hover to pause and read.
04 — Track record
Jan 2020 – Present
MICE Depot Pte Ltd
Singapore
Sole IT, security, and compliance owner for the organization — reporting directly to the Director of Operations.
Information Security Governance: Own the full ISO 27001:2022 ISMS — risk assessment, Statement of Applicability, documentation, and audit preparation — achieving certification and maintaining it through surveillance audits.
Data Protection: Serve as appointed Data Protection Officer (DPO), ensuring continuous PDPA and GDPR compliance, managing data-subject obligations, and embedding privacy-by-design across operations.
Sustainable IT & ESG: Lead Sustainable IT strategy aligned to the Singapore Green Plan 2030; integrated carbon tracking into operational processes using MSC and CES frameworks.
AI & Innovation: Operationalized secure Generative AI workflows to automate ISO documentation and gap analysis, reducing administrative overhead by ~30% under strict data-governance controls.
Digital Transformation: Led the migration to Google Workspace, enhancing collaboration capacity and reducing recurring licensing costs.
Infrastructure & Availability: Oversee security and availability of the entire IT estate — cloud, endpoints, CCTV, and network peripherals — sustaining 24/7 operational continuity.
Vendor & Contract Management: Negotiate IT hardware, software, and service contracts with strict SLA and budget adherence, drafting supplier data-protection addenda to close compliance gaps.
Mar 2013 – Oct 2019
George P. Johnson Pte Ltd
Singapore
Compliance & Audit: Led the successful 2015 EICC v5 (now RBA) audit and conducted recurring internal ISO 27001 security audits.
Governance & Strategy: Built and implemented the Business Continuity Plan and Risk Assessment frameworks for the Singapore office.
Project Management: Delivered the full office relocation and renovation on time, managing vendors and budget end-to-end.
Digital Transformation: Developed and deployed an Online Leave Management System and digital Visitor Logbook, streamlining HR operations and strengthening physical security.
Data Privacy & Regional Support: Delivered GDPR/PDPA training for new hires and provided regional IT support across Singapore and Korea, maintaining high availability of HVAC, IoT, and AV systems.
May 2012 – Feb 2013
Autobahn BMW
Negros Occidental, Philippines
Infrastructure Project Management: Directed end-to-end build of the dealership's IT and telecom infrastructure to BMW Germany technical standards.
Systems & Security: Rolled out the ABC warehouse inventory and warranty-claims system; configured hardware firewalls and maintained proprietary BMW diagnostic servers (ISIS/ISSS/ISID/IMIB) at 100% availability.
Aug 2009 – Apr 2012
Convergys (now Concentrix)
Bacolod, Philippines
Training & Support: Delivered product training for Comcast and Time Warner accounts and led floor support for complex technical escalations.
Oct 2008 – May 2009
Teletech
Bacolod, Philippines
Leadership & Mentorship: Served as interim Team Leader and SME during the Sta. Rosa site launch; coached agents on ADSL/Cable technologies, recognized by Telstra/Bigpond for service quality.
05 — Web development
Production sites I designed and built end-to-end — live and running on this same server.
06 — Credentials
Every credential links to its verified certificate.
Education
University of St. La Salle · Bacolod City, Philippines
2004 – 2008
07 — Contact
Open to senior IT and information-security leadership roles — Senior IT Manager, IT Director, and Head of IT — backed by an ISO 27001-certified, audit-ready IT function. The fastest way to reach me is email or LinkedIn.