Cybersecurity Governance | Risk | Compliance

Philip Frias Jr.

Strengthening Security. Reducing Risk. Enabling Compliance.

I help organizations build stronger cybersecurity programs, manage information security risk, and navigate complex compliance requirements through practical, business-aligned solutions.

Frameworks & Standards
ISO/IEC 27001ISO/IEC 42001ISO/IEC 27701 SOC 2NISTCIS Controls
OGIS PHILIPPINES — Cybersecurity Delivery Team
Head of Cybersecurity
2026 — Present

Lead the cybersecurity function of OGIS Philippines, driving cybersecurity governance, compliance, consulting, and client delivery while serving as the organization's primary technical authority.

View responsibilities & initiatives

Key Responsibilities

  • Lead strategic security initiatives, including ISO/IEC 27001:2022 ISMS implementation, SOC 2 readiness, and enterprise security policies, standards, and governance frameworks
  • Established OGIS Philippines' Cloud Security Assessment process to ensure applications and cloud solutions undergo security review before production deployment
  • Partner with OGIS RI (Japan) executives, business leaders, and technical teams to implement enterprise cybersecurity initiatives and strengthen organizational security governance
  • Serve as a trusted cybersecurity advisor on cloud security, governance, risk management, vulnerability management, AI governance, and security architecture
  • Lead the design and delivery of cybersecurity consulting services covering GRC, ISO 27001, SOC 2, Cloud Security, VAPT, Privacy, IAM, Managed Security Services, and AI Governance
  • Act as Lead Security Consultant and Pre-Sales Solution Architect, developing technical proposals, SOWs, solution designs, project estimates, pricing strategies, and executive presentations
  • Mentor the cybersecurity team and champion professional development, achieving 100% ISO/IEC 27701:2025 PIMS Lead Auditor certification across the practice
  • Collaborate with Sales, Marketing, and strategic technology partners — including Microsoft, AWS, Azure, Alibaba Cloud, Bitdefender, Vanta, Scrut, Vicarius, and Acronis — to expand cybersecurity capabilities

Major Initiatives

  • Architected OGIS Oculus, the Cybersecurity Managed Services function of OGIS Philippines
  • Worked with OGIS Philippines stakeholders and executives to establish internal Cybersecurity and Information Security initiatives and projects
  • Started implementing ISO/IEC 27001:2022 ISMS phase by phase across OGIS Philippines
  • Serve as a Cybersecurity Champion across OGIS Philippines
Security Profile
Current Role
Head of Cybersecurity
Organization
OGIS Philippines
Core Domains
Cybersecurity • GRC • Risk • Compliance • AI Governance
Consulting
Upwork • Direct Engagements
Credentials
ISO 27001 • ISO 42001 • ISO 27701
About Me

Security expertise grounded in real-world delivery.

Portrait of Philip Frias Jr.

My work sits at the intersection of business, risk, security, compliance and technology. I help organizations take cybersecurity and compliance requirements — ISO/IEC 27001, ISO/IEC 42001, ISO/IEC 27701, SOC 2 — and turn them into security programs, controls, assessments, documentation and remediation activities that actually get implemented, not just written down.

Day to day, that means leading cybersecurity delivery at OGIS Philippines: running security assessments, building out ISMS and governance structures, and helping teams get audit-ready. It also means working across adjacent areas as they intersect with security — AI governance, privacy, cloud security, and third-party risk. Earlier in my career, that same focus took shape at Accenture, leading global security assessments across hosting sites and cloud services, and at N-able, running third-party and vendor security assessments.

Alongside my current role, I take on independent consulting engagements — through Upwork and direct client relationships — supporting organizations on ISO 27001 implementation, GRC-as-a-Service, privacy compliance, and security assessments.

Business Risk Security Compliance Execution
RISK-BASED

I start by understanding the organization's environment, objectives and actual risks before recommending controls or frameworks.

IMPLEMENTATION-ORIENTED

Compliance should improve security rather than simply check boxes for certification.

GRC + TECHNICAL

I work across governance, frameworks, risk management, cloud security, and hands-on implementation.

Professional Journey

Where the work has happened.

2026 — Present
Head of Cybersecurity
OGIS Philippines
Leading the cybersecurity function of OGIS Philippines — governance, compliance, consulting, and client delivery.
Responsibilities
  • ISO/IEC 27001:2022 ISMS implementation and SOC 2 readiness leadership
  • Cloud Security Assessment process design and ownership
  • Lead Security Consultant & Pre-Sales Solution Architect — proposals, SOWs, pricing, executive presentations
  • Technical mentorship across the cybersecurity practice
Frameworks & Tools
ISO/IEC 27001SOC 2Microsoft DefenderVantaScrut
Previous
Security Engineering Specialist — Lead Level
Accenture in the Philippines
Led end-to-end global security assessments across hosting sites, cloud services, and acquisitions, ensuring alignment with ISO/IEC 27001:2022 and Accenture's Security Framework.
Responsibilities
  • Led global security assessments across hosting sites, cloud services, and acquisitions
  • Conducted ISMS effectiveness reviews for regional teams worldwide
  • Managed security audit workflows and remediation tracking using RSA Archer eGRC
  • Processed and analyzed global security exception requests, collaborating with Information Security Leads and leadership on risk-based approvals
  • Partnered with project teams and stakeholders to remediate security gaps
  • Generated and presented assessment and exception reports to Information Security Managers and leadership
Core Skills
ISMSRSA Archer eGRCISO/IEC 27001:2022AWSAzureGCPCompliance Gap AnalysisRisk ScoringExecutive Reporting
Previous
Senior Security Engineer
N-able
Conducted third-party and vendor security assessments, evaluating technical and organizational controls and supporting risk-based security decisions.
Responsibilities
  • Conducted comprehensive security risk assessments of vendors
  • Evaluated access management, encryption, vulnerability management, and incident response readiness
  • Assessed vendor compliance against ISO/IEC 27001, SOC 2, NIST CSF, GDPR and CCPA
  • Reviewed security certifications, penetration test results and audit reports
  • Evaluated patch management, logging, monitoring, SIEM integration and identity controls
  • Maintained vendor security risk registers and produced risk-rated assessment reports
  • Collaborated with Procurement, Legal and IT Security teams
Core Skills & Tools
Vendor Risk ManagementThird-Party AssessmentsISO/IEC 27001SOC 2SalesforceRSA Archer
Selected Engagements

Selected cybersecurity, information security, GRC and compliance engagements.

Clients are anonymized. Expand any card for the full case study.

BPO / People ServicesCompleted

ISO 27001 — Essential Eight Mapping Project

Client ConfidentialRole ISO/IEC 27001 ConsultantFrameworks ISO 27001 · Essential Eight

Mapping Essential Eight controls into ISO/IEC 27001:2022 with practical implementation guidance for Microsoft environments.

View case study
Approach
  • Reviewed existing processes and Essential Eight controls
  • Developed required documentation and deliverables
  • Mapped Essential Eight controls into an ISO/IEC 27001 perspective
  • Developed configuration guidance and compliance steps
  • Created a practical implementation playbook covering Essential Eight and its relationship to ISO/IEC 27001
Outcome

The client received a practical playbook to implement Essential Eight controls while aligning the implementation with ISO/IEC 27001 requirements.

Technology / Digital HealthCompleted

GDPR Compliance Support & Privacy Program Development

Client ConfidentialRole GDPR Compliance ConsultantFrameworks GDPR · Privacy

Establishing and strengthening a GDPR compliance program, including review of existing privacy and data protection practices.

View case study
Approach
  • Assessed existing privacy and data protection practices against applicable GDPR requirements
  • Provided recommendations for improving privacy governance and compliance processes
  • Supported development and refinement of GDPR-related documentation
  • Advised on practical implementation of privacy controls and organizational requirements
Outcome

Improved GDPR compliance readiness and privacy governance, supported by a structured roadmap for addressing identified gaps.

Technology / SaaSCompleted

ISO/IEC 27001 Pre-Implementation & Delivery Framework Design

Client ConfidentialRole ISO/IEC 27001 Lead ImplementerFrameworks ISO 27001 · ISMS

A structured delivery approach was needed ahead of formal ISO/IEC 27001 implementation — scope, activities, responsibilities, deliverables and sequencing.

View case study
Approach
  • Designed the overall ISO/IEC 27001 implementation delivery framework
  • Defined implementation phases, workstreams, activities and deliverables
  • Supported project scoping and identification of key ISMS requirements
  • Provided guidance on governance, risk management, documentation and implementation planning
Outcome

Established a structured roadmap that provided the foundation for transitioning from pre-implementation planning into formal ISMS implementation.

Technology / SaaSOngoing

ISO/IEC 27001 ISMS Implementation & Compliance Management

Client ConfidentialRole ISO/IEC 27001 Compliance LeadFrameworks ISO 27001 · ISMS · Vanta

Ongoing leadership and hands-on support to establish, operate and maintain the client's ISO/IEC 27001 compliance program.

View case study
Approach
  • Leading ongoing ISO/IEC 27001 implementation and compliance activities
  • Managing ISMS requirements, documentation and risk management activities
  • Coordinating evidence collection and remediation of compliance gaps
  • Supporting control implementation, monitoring, and audit/certification readiness
Outcome

Strengthened the client's ISMS and ISO/IEC 27001 readiness while establishing a more structured approach to managing information security compliance.

Technology / Professional ServicesOngoing

ISO/IEC 27001 Compliance Program Implementation & Support

Client ConfidentialRole ISO/IEC 27001 Compliance SpecialistFrameworks ISO 27001 · ISMS · Vanta

Dedicated support for implementing and managing ISO/IEC 27001 requirements — evidence collection, gap remediation and certification readiness.

View case study
Approach
  • Supported implementation and maintenance of ISO/IEC 27001 controls
  • Conducted compliance reviews
  • Assisted with evidence collection, documentation and control validation
  • Supported risk assessment and treatment activities
  • Monitored compliance activities through compliance management tooling
Outcome

Improved ISO/IEC 27001 compliance maturity and audit readiness while establishing consistent processes for managing controls, evidence, risks and remediation.

Healthcare / AI Health-TechOngoing

HIPAA Compliance Implementation — Healthcare AI Startup

Client ConfidentialRole HIPAA Compliance ConsultantFrameworks HIPAA · NIST CSF · NIST 800-53

Guiding a healthcare AI startup through a practical, lightweight HIPAA compliance implementation — building strong security foundations and audit-ready evidence from day one.

View case study
Approach
  • Conducted a gap assessment and mapped ePHI data flows to define scope and boundaries
  • Established core security policies, roles, responsibilities and security awareness foundations
  • Implemented core technical controls — access control, MFA, endpoint protection, encryption and secure configuration baselines
  • Built ePHI classification and handling standards, logging and audit controls, and a lightweight incident response plan
  • Validated control effectiveness, remediated gaps, and prepared documentation for ongoing compliance
Outcome

Delivered a scalable, right-sized HIPAA compliance foundation — reducing breach and regulatory risk while establishing a program the client can grow into as the business scales.

Security Investigation

Microsoft 365 OAuth Phishing Investigation

OAuth abuse · Microsoft 365 · Phishing Investigation · Identity Security · Incident Triage

View investigation summary
The Incident

A phishing campaign attempted to abuse OAuth application consent within a Microsoft 365 environment to gain unauthorized access to user accounts and data.

The Investigation

Triaged the incident, analyzed OAuth application activity and sign-in logs within Microsoft 365, and traced the scope of the attempted abuse to assess exposure.

Key Findings
  • Identified the OAuth consent phishing vector used against user identities
  • Assessed the scope of affected accounts and application permissions
  • Determined the attack path from initial phishing contact to attempted access
Recommendations
  • Restrict user consent for third-party OAuth applications
  • Strengthen identity monitoring and conditional access controls
  • Improve phishing awareness specific to OAuth consent abuse
Expertise

Where I focus.

Cybersecurity

  • Security Assessments
  • Threat Modeling
  • Security Controls
  • Cloud Security
  • Vulnerability Management
  • Incident Investigation

GRC

  • Governance
  • Risk Management
  • Compliance
  • Security Policies
  • Third-Party Risk
  • Audit Readiness

Information Security

  • ISMS
  • Security Program Development
  • Control Frameworks
  • Security Documentation
  • Security Assurance

AI & Privacy

  • AI Governance
  • AI Risk Management
  • NIST AI RMF
  • ISO/IEC 42001
  • Privacy Management
  • ISO/IEC 27701
Security Stack

Technologies and platforms I've worked with.

Listed as tools used in the course of assessments and delivery — not implied partnerships or vendor certifications.

Microsoft

DefenderEntra IDIntunePurviewAzure

Cloud

AWSAzureAlibaba Cloud

GRC / Compliance

VantaScrutRSA Archer eGRC

Security

BitdefenderVicariusAcronisVAPT
Frameworks & Standards

Frameworks I work with.

Distinct from personal certifications — see Credentials below for what I'm certified in.

Information Security

ISO/IEC 27001NIST CSFCIS Controls

AI Governance

ISO/IEC 42001NIST AI RMF

Privacy

ISO/IEC 27701GDPRData Protection

Compliance

SOC 2HIPAAEssential Eight
Professional Credentials

Certified.

Credential and membership ID numbers are kept private.

BSI ISO/IEC 27001 Lead Auditor certified professional badge

ISO/IEC 27001:2022 ISMS Lead Auditor

BSI | CQI-IRCA

Lead Auditor certification covering ISO/IEC 27001:2022 Information Security Management Systems, audit planning, execution, reporting and conformity assessment.

IssuedMarch 2024
View certificate ↗
BSI ISO/IEC 42001 Lead Implementer practitioner badge

ISO/IEC 42001:2023 AI Management Systems Lead Implementer

BSI

Lead Implementer certification focused on establishing, implementing, maintaining and continually improving an AI Management System, including AI governance and responsible AI practices.

IssuedAugust 2025
View certificate ↗
ISO/IEC 27701:2025 Lead Auditor certified badge

ISO/IEC 27701:2025 PIMS Lead Auditor

Mastermind Assurance

Lead Auditor certification covering Privacy Information Management Systems, privacy governance, data protection requirements and privacy risk assessment.

IssuedJune 2026
View certificate ↗
IRCA member badge

IRCA Registered ISO/IEC 27001:2022 Associate Auditor

CQI | IRCA

IRCA-registered qualification covering auditing principles and practices for ISO/IEC 27001:2022 Information Security Management Systems.

IssuedApril 2026
View certificate ↗
CQI Practitioner badge

Practitioner, Chartered Quality Institute (PCQI)

CQI | Chartered Quality Institute

Professional practitioner credential demonstrating competence in quality management principles, continual improvement and management system practices.

IssuedApril 2026
View certificate ↗
DICT-Recognized Cybersecurity Professional — Category 3 Expert badge

DICT-Recognized Cybersecurity Professional

Department of Information and Communications Technology (DICT)

Government-recognized cybersecurity professional credential demonstrating competency in cybersecurity and information security.

IssuedAugust 2026
View certificate ↗
Professional Memberships
ISACA member badge

ISACA

Professional Member

Information systems audit, cybersecurity, governance, risk and compliance.

CISO Intelligence Council logo

CISO Intelligence Council

Professional Member

Cybersecurity leadership, information security governance and CISO community.

Cybersecurity Council of the Philippines logo

Cybersecurity Council of the Philippines

Member

Cybersecurity collaboration, professional development and security community engagement in the Philippines.

Philippine Cybersecurity Professionals Registry (PCPR) badge

Philippine Cybersecurity Professionals Registry

Member (PCPR)

Department of Information and Communications Technology's Registry of Certified Cybersecurity Professionals in the Philippines.

How I Think About Security
Security should enable the business, not slow it down.
01

Practical

Security controls should work in the real world.

02

Risk-Based

Security investment should be aligned with actual risk.

03

Evidence-Driven

Security decisions should be supported by evidence and measurable outcomes.

04

Business-Aligned

Security should protect what matters most to the organization.

What I Want People To Remember
01

I MAKE CYBERSECURITY PRACTICAL.

I translate complex security, risk and compliance requirements into clear, actionable solutions that organizations can actually implement.

02

I BRIDGE SECURITY, COMPLIANCE & TECHNOLOGY.

I understand both the governance side of cybersecurity and the technical realities behind the controls — connecting business requirements with practical security implementation.

03

I DON'T JUST IDENTIFY GAPS — I HELP SOLVE THEM.

My focus goes beyond assessments and reports. I work with teams to turn findings into remediation plans, implement controls, and build sustainable security programs.

Independent Consulting

Independent Consulting.

Independent cybersecurity, information security, GRC and compliance consulting — active since October 2025, via Upwork, direct client engagements, and my professional network.

Cybersecurity Consulting & Advisory
Governance, Risk & Compliance Consulting
ISO/IEC 27001:2022 ISMS Implementation
GRC-as-a-Service (GRCaaS)
ISO/IEC 27701:2025 PIMS Implementation
GDPR Compliance Support / DPO-as-a-Service
Essential Eight Implementation
Security Risk Assessments
UPWORK

Cybersecurity GRC Consultant | ISO 27001 LA, ISO 27701 LA, ISO 42001 LI

I help startups, SaaS companies, healthcare organizations, and enterprises build audit-ready cybersecurity, GRC, privacy, and AI governance programs — from gap assessment and implementation to audit and certification readiness.

VIEW MY UPWORK PROFILE →
ISO 27001 Implementation ISMS Gap Assessments Cyber Risk Assessments SOC 2 Readiness Privacy Programs AI Governance Vendor Risk Cloud Security GRC Program Design Security Strategy
Insights

Perspectives on security, risk & compliance.

Practical perspectives from my work across cybersecurity, GRC, cloud security, privacy, and AI governance.

"Security isn't just about controls. It's about understanding risk, making informed decisions, and building programs that organizations can actually operate."

This perspective is in progress and not yet published. Check back soon, or get in touch if you'd like to discuss this topic directly.

GET IN TOUCH
Let's Talk Security

Have a challenge worth discussing?

Cybersecurity, compliance, risk, or security assessment — let's talk it through.