Confidential mandate

Regional Chief Financial Officer — Cybersecurity Hub

Urgent / Unplanned

Regional CFO mandate in Manila, Philippines · Global Capability Centres

Build financial control and capacity visibility in a Manila cyber hub as vendor dependence, service cost and investment exposure become harder to see.

The mandate

A Manila cybersecurity hub is operating with reliable cash and statutory processes but requires stronger management visibility. Vendor extensions, retention actions and security-tool commitments have been approved through different routes. The board cannot reconcile the hub's apparent underspend with rising run-rate obligations and scarce-skill vacancies. A regional finance function designed for a smaller centre no longer provides sufficient control or challenge.

The Regional Chief Financial Officer will take financial stewardship of approximately PHP 23 billion in annual services expenditure associated with 1,525 employees and material partners. Scope includes planning, performance, investment governance, vendor economics, workforce cost, financial control and regional legal-entity coordination. Cybersecurity leaders own operational risk; procurement owns sourcing process. The CFO must ensure their choices are affordable, correctly recorded and presented with complete lifecycle consequences.

This is a recovery and build assignment. The appointee must stabilise close and approval capacity, expose contingent commitments and create cyber-service economics that distinguish tooling, specialist labour, incident surge and shared infrastructure. Speed matters, but so does resisting the urge to fill every finance vacancy before roles are redesigned.

Currency and tax treatment add further complexity. Several major contracts are denominated outside the Philippines, while service charges and payroll follow different cycles. The CFO must expose foreign-exchange and withholding assumptions, determine which risks belong in the hub forecast and stop apparent savings from being created by favourable rates that service leaders cannot control. Investment comparisons should use a consistent currency and lifecycle period, with sensitivities visible to the approving committee.

Insurance and indemnity positions will also enter the review. The CFO should confirm that material cyber contracts align with group coverage and that retained exposures are valued in investment recommendations, rather than left in legal schedules unseen by service owners.

Why this seat is open

The board created this broader regional CFO position outside the annual plan after attrition fragmented financial accountability. It is urgent and unplanned and has no direct predecessor; the local controller continues to hold statutory responsibilities. A permanent appointment is sought within eight weeks so investment and vendor decisions enter the next budget with credible oversight.

What you will own

  • Reconcile contracts, purchase orders, workforce actions and investment approvals into a complete run-rate and commitment view.
  • Protect close, tax and statutory support while rebuilding management-finance capability.
  • Establish unit economics for priority cyber services, including licence, data, specialist and surge costs.
  • Introduce investment gates that recognise threat urgency without granting indefinite exemption from financial evidence.
  • Review vendor concentration, prepaid commitments and termination exposure with procurement and security leaders.
  • Create a workforce-cost model connecting vacancies, contractors, premiums, shifts and time to proficiency.
  • Build a finance leadership team with successors for controllership, planning and commercial-finance roles.
  • Present independent forecasts and downside choices to the relevant board committee.

The first 12 months

Within 30 days, the CFO will validate liquidity, close coverage and material commitments. By day 90, the board should receive a reconciled baseline, a risk-ranked vendor and investment register and a permanent finance design. Unsupported assurances will be withdrawn rather than carried forward for convenience.

Months four to nine will fill pivotal roles, implement service economics for the largest cyber portfolios and reset forecasts around actual capacity. The CFO will renegotiate or exit at least two poorly structured commitments and bring off-cycle approvals into a controlled urgent-investment route.

At year-end, forecast variance should remain within 6% for three quarters, unrecorded material commitments should be eliminated and contractor finance cost should fall by 25% from the emergency run rate. Ninety per cent of cyber expenditure should trace to accountable services or approved enterprise obligations, without a missed filing or material control failure.

What the board will measure

  • Integrity of the commitment and forecast view under continued cyber-investment pressure.
  • Finance capability restored without compromising statutory and close obligations.
  • Decisions changed through service economics, including visible stop or renegotiation outcomes.
  • Vendor and workforce exposures disclosed early and reflected in downside planning.
  • Successors in critical finance roles and retention of the identified pivotal cohort.

The person

You are a Regional CFO, divisional finance leader or group controller who has rebuilt finance around a technology or security operation. You understand recurring licences, specialist labour and urgent threat investment, yet remain a financial steward rather than a technology enthusiast. Experience in global centres, regulated services or technology platforms across Asia is relevant.

You bring 22–28 years of experience and have controlled at least PHP 13 billion or equivalent while leading finance for 1,050 employees or a comparably complex operation. Evidence should include contingent commitments you uncovered and an urgent investment process you made both faster and more accountable.

The role is onsite in Manila and carries board-committee access.

Compensation and terms

Base compensation is PHP 20–28 million plus annual incentive and long-term incentives. Objectives will cover forecast integrity, finance recovery, investment decisions, control and successor depth. Security spend reduction is not an isolated target. Final structure reflects current mix and experience, subject to standard vesting, malus and diligence.

Confidentiality

The hub, legal entities, security services and vendor exposures are not identified. Detailed financial and operating information follows qualification and reciprocal confidentiality. Applicants must not use the Manila location or rounded population to speculate publicly about the organisation.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.