Confidential mandate
Chief Product Officer — Cybersecurity Hub
Urgent / New
CPO - Product mandate in Manila, Philippines · Global Capability Centres
Build a coherent security-product portfolio from consolidating cyber sites, preserving threat context and client obligations while eliminating duplicate roadmaps.
The mandate
Cyber teams from three locations are consolidating into a Manila-led hub with overlapping detection, identity, vulnerability and response capabilities. Each site calls its work a product, but roadmaps are shaped by different sponsors, adoption is measured inconsistently and duplicate functions carry different control evidence. Migration dates are approaching without a single executive authorised to decide the future portfolio.
The newly created Chief Product Officer will lead product decisions affecting approximately 1,775 employees and partners and a security-services perimeter near PHP 31 billion. The CPO owns portfolio, discovery, user and sponsor needs, roadmaps, adoption, service propositions and lifecycle decisions. Engineering owns technical delivery; security officers own risk; operations owns response. The CPO makes those perspectives resolve into usable, funded products.
Cyber products differ from ordinary internal software. Users may be analysts, control owners or businesses whose risk choices affect design. Low visible adoption can reflect poor fit, or a capability retained for rare severe events. The CPO must distinguish everyday utility, mandatory control and contingency value and set evidence appropriate to each.
Consolidation must preserve local threat and regulatory context. Common product cores can improve quality, but a forced single workflow may erase language, data or response obligations. Variants need explicit value, owners and retirement criteria rather than indefinite exception status.
Retirement in cybersecurity carries evidence obligations beyond user migration. Historical alerts, decisions and case records may need to remain searchable for investigation, audit or legal need after the active product closes. The CPO will make archive, retention, access and reconstruction part of lifecycle economics and will ensure that successor products can interpret the inherited record. Deleting a licence is not completion if evidentiary access disappears with it.
Product reviews will include users responsible for later investigation so archival usability is tested before the active service is removed.
Failed retrieval will block final retirement approval.
Why this seat is open
No existing site product leader has authority across the combined portfolio. Consolidation therefore prompted urgent creation of a new enterprise role, not a replacement. The board seeks an appointment within eight weeks before irreversible migration and vendor choices are made. Site leaders remain accountable for current products until transfer acceptance.
What you will own
- Reconstruct the portfolio by users, security outcomes, obligations, adoption, cost and technical dependency.
- Decide which site products combine, become common cores, remain dedicated or retire.
- Establish discovery with analysts, control owners and global sponsors before roadmap commitment.
- Define success for daily-use, mandatory-control and contingency products without forcing one metric.
- Negotiate funding, risk, service and decision rights with security officers and consuming businesses.
- Govern variants through explicit rationale, cost, owner and review date.
- Lead migration acceptance and product communication across sites and users.
- Build product-management careers and successors with sufficient cyber and operating judgement.
The first 12 months
In the first 60 days, the CPO will establish a trustworthy product inventory and stop duplicate roadmap commitments. By day 90, the future disposition of the 15 most consequential products will be proposed, with sponsors, risks and migration conditions. Two pilots should represent different product types and sites.
By month eight, the pilots should use common discovery, roadmap and adoption governance. At least one duplicate product will be retired, including user migration and vendor obligations, while one justified local variant receives a funded contract. Product and engineering leadership boundaries will be operating.
At year-end, 70% of in-scope expenditure should align to an approved product portfolio, duplicate product cost should fall by 15% and adoption of selected common products should improve by 20%. Critical contingency products must pass realistic tests, and no material security obligation should be lost through consolidation.
What the board will measure
- Portfolio simplification and actual retirement, not renamed duplication.
- Adoption and security outcomes appropriate to each product type.
- Sponsor and risk authority visible in roadmap decisions.
- Preservation of valid local threat, data and regulatory requirements.
- Product leadership and succession across the consolidated hub.
The person
You are a Chief Product Officer, cyber product executive or security-services leader who has consolidated products across teams or markets. You know when adoption is meaningful and when resilience or control value needs different proof. Relevant experience includes cybersecurity, identity, regulated platforms and global security operations.
You bring 22–28 years of experience and have owned at least PHP 18 billion of product or service scope affecting 1,250 people or more. The committee will examine a product you retired, a local variant you preserved and a roadmap decision changed by a CISO or end user.
This is an onsite Manila role with travel to originating and sponsor locations.
Compensation and terms
For the CPO remit, base compensation is PHP 20–28 million, accompanied by annual incentive and long-term incentives. Measures include portfolio decisions, adoption, risk alignment, retirement economics and talent. Product counts alone do not indicate performance. Final terms reflect current mix and scope and carry standard vesting and malus provisions.
Confidentiality
The products, sites, users and threat obligations are confidential. Controlled detail follows qualification and a signed undertaking. The Manila location and rounded portfolio figures should not be used to infer the hub.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.