IT Risk Manager

2 hours ago


Pasig, National Capital Region, Philippines JG Summit Holdings Inc. Full time ₱1,200,000 - ₱2,400,000 per year

Department
Governance, Risk & Compliance

Employee Type
Probationary

The IT Risk Manager plays a critical role in managing the organization's technology risk exposure, ensuring a resilient and secure IT environment. This position leads the development and execution of risk management strategies, including third-party risk oversight, major incident management, and enterprise business continuity planning. The role serves as a central point of contact for identifying, evaluating, and mitigating IT and cyber risks that could impact operations, compliance, or reputation. The IT Risk Manager collaborates with stakeholders across IT, legal, procurement, and business units to maintain a strong control posture and ensure preparedness for disruptions.

WHAT IS THE JOB LIKE?

IT Risk Management Program

  • Develop and implement the IT Risk Management Framework, aligned with enterprise risk and international standards (ISO 27005, NIST RMF, COSO).
  • Identify, assess, and prioritize technology and cyber risks across infrastructure, applications, and services.
  • Maintain the IT risk register and facilitate regular risk reviews, treatment plans, and reporting to senior leadership.
  • Coordinate risk assessments for new projects, technologies, and change initiatives.

Third-Party Risk Management (TPRM)

  • Lead the development and execution of the third-party IT risk management program, from vendor selection and onboarding to ongoing monitoring and offboarding.
  • Conduct due diligence and risk assessments on third-party vendors with access to sensitive data or critical systems.
  • Ensure third-party contracts include appropriate security and resilience clauses.
  • Monitor third-party security posture and performance, ensuring compliance with established policies and standards.
  • Manage third-party security incidents and breaches, coordinating response and remediation efforts.

Major Incident Management

  • Develop and maintain an enterprise-wide Major Incident Management Plan to ensure swift and effective response to IT and operational incidents.
  • Lead incident response activities, including identifying, assessing, and managing incidents to minimize business impact.
  • Establish an Incident Response Team (IRT) and facilitate regular incident response simulations and drills.
  • Facilitate coordination with the Chief Information Security Officer to ensure effective collaboration among IT, cybersecurity, and business stakeholders in resolving incidents and providing timely updates to leadership.
  • Perform root cause analyses (RCA) post-incident, document findings, and recommend process improvements to prevent recurrence.
  • Define and monitor incident management key performance indicators (KPIs) such as response times and resolution rates.

Business Continuity Management

  • Design and implement the organization's Disaster Recovery Plans (DRP) to ensure resilience of critical systems and processes.
  • Conduct Business Impact Analysis (BIA) to identify critical business functions, dependencies, and recovery time objectives (RTOs).
  • Develop and maintain contingency plans for various disruption scenarios, including IT outages, cybersecurity events, and natural disasters.
  • Lead BCP and DRP testing activities, including tabletop exercises and full-scale simulations.
  • Collaborate with business units to identify continuity requirements, ensure stakeholder buy-in, and align plans with organizational priorities.
  • Oversee vendor dependencies and third-party risk management as it relates to continuity and recovery planning.

Stakeholder Engagement & Communication

  • Communicate IT risk posture, incident status, and business continuity readiness to various stakeholders, including executive leadership, business unit heads, and technical teams.
  • Serve as the key point of contact for incident escalation, recovery efforts, and crisis communication.
  • Provide leadership during crisis situations, ensuring clear communication and decision-making to minimize operational disruption.

WHO ARE YOU?

  • Bachelor's degree in Information Technology, Risk Management, or a related field.
  • 8+ years of progressive experience in Incident Management, Business Continuity, Disaster Recovery, or IT Operations, with at least 3-5 years in a leadership or managerial capacity.
  • Demonstrated experience covering the full spectrum of IT risk, including operational risk, cybersecurity risk, and third-party risk.
  • Excellent analytical, critical thinking, and problem-solving skills, with the ability to translate complex technical issues into business risks.
  • Exceptional communication, presentation, and interpersonal skills, with the ability to influence and collaborate effectively with diverse stakeholders at all levels.

Relevant Certifications (one Or More Highly Desirable)

  • Certified in Risk and Information Systems Control (CRISC) - Highly relevant for IT risk management.
  • Certified Information Security Manager (CISM) - Covers information security governance, risk management, and incident management.
  • Certified Information Systems Auditor (CISA) - Focuses on auditing, control, and assurance of information systems.
  • Certified Business Continuity Professional (CBCP) / Master Business Continuity Professional (MBCP) from DRI International - Specific to business continuity.
  • Certificate of the Business Continuity Institute (CBCI) / FBCI from BCI - Specific to business continuity.
  • Certified Third-Party Risk Professional (CTPRP) from Shared Assessments - Specific to third-party risk management.
  • Certified Information Systems Security Professional (CISSP) - Broad cybersecurity knowledge,

including risk management.

  • ITIL 4 Practitioner: Incident Management (or similar ITIL certifications) - Relevant for incident management processes.

Experience Range Range (Years)
6 - 8 years

Job posted on



  • Pasig, National Capital Region, Philippines City Savings Bank Full time ₱900,000 - ₱1,200,000 per year

    We are looking for a skilled and detail-oriented Risk MIS and Model Risk Management Officer to become a key member of our Risk Management Team. This vital position involves managing the hands-on execution of our essential PFRS 9 / ECL credit risk models (Probability of Default, Loss Given Default, Exposure-at-Default), providing key inputs that inform the...

  • IT Project Manager

    3 hours ago


    Pasig, National Capital Region, Philippines MEGAXCESS IT SOLUTIONS INC. Full time ₱900,000 - ₱1,200,000 per year

    THE OPPORTUNITYTheIT PROJECT MANAGERis responsible for providing direction to the team including planning, overseeing and documentation of all aspects of the project and workloads being worked on.DUTIES AND RESPONSIBILITIESLead the planning and implementation of IT projectsDirectly people management of all IT teams/staffFacilitate the definition of project...


  • Pasig, National Capital Region, Philippines Acquire Intelligence Full time ₱1,200,000 - ₱2,400,000 per year

    We're an award-winning global outsourcer providing contact center and back office services on behalf of our global clients. Come work at a place where innovation and teamwork come together to support the most exciting missions in the worldAcquire BPO is an award-winning business process outsource provider, to some of the world's largest brands operating...

  • Operational Risk Lead

    2 weeks ago


    Pasig, National Capital Region, Philippines Tonik Full time ₱900,000 - ₱1,200,000 per year

    Responsibilities:Reports to the Chief Risk OfficerContributes to the efficient and effective functioning of the Risk Management Unit.Leads the implementation of the Operational Risk Management framework and in ensuring that all operational risk methodologies and policies are compliant to the minimum regulatory requirement and updated as relevant to state of...


  • Pasig, National Capital Region, Philippines Jollibee Full time ₱900,000 - ₱1,200,000 per year

    JFC's Enterprise Risk Officer is responsible for the following:ERM Framework ImplementationSupport ERM framework implementation.Handle ERM documentation.Administer JFC's risk register and coordinate risk actions.Review and recommend process improvements.ERM AdministrationExecute ERM projects per plan and strategies.Collect and clarify information from data...


  • Pasig, National Capital Region, Philippines Jollibee Group Full time ₱900,000 - ₱1,200,000 per year

    Jollibee Group'sEnterprise Risk Officeris responsible for the following:ERM Framework ImplementationSupport ERM framework implementation.Handle ERM documentation.Administer JFC's risk register and coordinate risk actions.Review and recommend process improvements.ERM AdministrationExecute ERM projects per plan and strategies.Collect and clarify information...


  • Pasig, National Capital Region, Philippines Nezda Global Full time $100,000 - $150,000 per year

    About the RoleWe're looking for an experiencedUnsecured Risk Collections & Bureau Headto lead our risk analytics, collection strategy, and bureau data management for consumer unsecured products. This role owns credit loss forecasting, scorecard implementation, bureau partnerships, and innovation in risk mitigation. You'll mentor a team of senior analysts and...


  • Pasig, National Capital Region, Philippines Viventis Search Asia Full time ₱2,000,000 - ₱2,500,000 per year

    Responsible for advanced analytics and modeling initiative within the company's Risk Management. She/ He will be responsible for developing and enhancing score models across multiple risk areas using traditional methods as well as new AI/ML techniques. Working with the tech team she/he will lay out the ML ops pipelines and structure for rapid rollout and...


  • Pasig, National Capital Region, Philippines Viventis Search Asia Full time ₱2,000,000 - ₱2,500,000 per year

    Role ResponsibilitiesLead advanced analytics and modeling initiatives within the company's Risk Management function.Develop and enhance score models across multiple risk areas using: Traditional methods (Regression, Decision Trees, etc.) and AI/ML techniques (Gradient Boosting, NLP, etc.)Collaborate with the tech team to design ML Ops pipelines ...


  • Pasig, National Capital Region, Philippines MegaXcess IT Solutions Inc. Full time ₱1,500,000 - ₱3,000,000 per year

    JOB SUMMARY:We are seeking a dynamic and personable individual to help senior management build and manage key external relationships as the company continues its fast-paced growth. You will join a team of founders, innovators, and industry leaders, supporting the day-to-day operations and overall management of the company.The Director of Client Relations is...