Confidential mandate
CTO – Product and Engineering — Cybersecurity Hub
Planned Replacement
CTO – Product and Engineering mandate in Manila, Philippines · Global Capability Centres
Turn Manila’s detection, identity and security-automation teams into accountable products with durable engineering, transparent risk and reliable global adoption.
The mandate
A Manila cybersecurity hub has built valuable detection content, identity automation and response tooling through projects commissioned by separate global security officers. The same capabilities are now used across businesses, yet funding ends with each project, roadmaps compete and production support depends on engineers who also build the next release. The group has decided to transfer selected capabilities into persistent product ownership while a long-serving CTO prepares for an orderly succession.
The CTO – Product and Engineering will lead approximately 1,100 employees and material partners and steward a technology perimeter near PHP 27 billion. The remit includes product engineering, detection engineering, security automation, platform architecture, developer experience, reliability, technical debt and engineering careers. Chief information security officers own risk and threat priorities; enterprise IT owns shared infrastructure. This executive owns the quality, lifecycle and operability of the hub’s security products.
Product language must not dilute cyber accountability. A roadmap cannot override severity, threat intelligence or mandatory control; equally, every security request cannot become an urgent exception. The CTO will create decision rules, secure engineering standards and product economics that make trade-offs visible to the officers accepting residual risk.
The estate includes client-specific code, privileged integrations and data that cannot always be pooled. The leader must define common product cores and governed variants, establish source and access ownership and be prepared to keep a capability dedicated where contractual or threat evidence justifies it.
Software supply and provenance will sit inside product ownership. Critical components need maintained bills of material, verified build paths, vulnerability decisions and evidence that an emergency patch can reach every authorised variant. The CTO should know when a library or model dependency creates unacceptable inherited exposure and be able to coordinate remediation without disclosing one client’s environment to another.
Why this seat is open
The incumbent will complete a planned regional transition and supports a four-to-six-month handover. This is a planned replacement, unrelated to a service incident, control finding or performance concern. The board wants the successor selected before persistent funding and product leadership appointments are finalised, while present technical authority remains intact.
What you will own
- Select which cyber capabilities become products and define users, outcomes, risk boundaries and lifecycle obligations.
- Establish roadmaps and persistent funding with global security sponsors.
- Set secure development, release, observability and recovery practices proportionate to each product’s consequence.
- Separate common product cores from client-specific configuration and protect privileged data and access.
- Govern technical debt and retirement, including migration and evidence obligations for dependent security operations.
- Create engineering and product leadership roles with unambiguous incident and risk escalation.
- Build principal-engineer careers and successors across detection, identity, automation and platform disciplines.
- Make cloud, licence, vendor and support economics visible at product level.
The first 12 months
The first 90 days will produce a product and dependency inventory, nominate two pilot capabilities and resolve interim support ownership. Every critical component should have source, access, monitoring and recovery accountability. The CTO will agree roadmap and risk decision rights with the sponsoring security officers before funding transfers.
By month eight, the pilots should operate persistent teams, common engineering standards and product-level service objectives. At least one client variation will be moved to the common core or formally retained with evidence. The permanent technology leadership team and technical-career framework will be in place.
At year-end, 65% of eligible engineering capacity should sit in approved products, severe change-related incidents should fall by 30% and median release lead time for pilots by 25%. Critical products must meet recovery objectives for two quarters, with 90% retention of pivotal engineers and a 12% reduction in duplicated platform or vendor cost.
What the board will measure
- Genuine product authority and funded roadmaps accepted by global security sponsors.
- Secure release, recovery and incident outcomes under persistent ownership.
- Reduced duplication without inappropriate pooling of client-specific capability.
- Product economics and technical-debt decisions that change investment.
- Leadership succession beyond the departing CTO and depth in principal engineering.
The person
You are a CTO, cyber-product engineering leader or security-platform executive who has converted commissioned capability into sustained products. You can challenge threat and architecture claims without appropriating the CISO’s risk role. Relevant backgrounds include cybersecurity vendors, regulated platforms, global security operations and secure enterprise software.
You bring 18–22 years of experience and have controlled at least PHP 15 billion in technology scope while leading 775 engineers and partners or more. The committee will test a release you stopped, a client-specific variant you retained and a security product you retired safely. References must confirm production accountability, not only innovation sponsorship.
The position is hybrid in Manila with regular presence during product and incident reviews.
Compensation and terms
For this CTO appointment, base compensation is PHP 20–28 million, supplemented by annual incentive and long-term incentives. Measures will combine product ownership, secure engineering, reliability, economics and successor depth. Release volume alone does not determine performance. Final terms reflect the agreed technology perimeter and current mix, with standard vesting and malus conditions.
Confidentiality
The security products, sponsoring businesses, architecture and incumbent are confidential. Qualified candidates receive controlled details after mutual interest and an undertaking. Manila and the rounded workforce must not be used to identify the hub.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.