Governance Risk and Compliance Consultant
1 day ago
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together.
Primary Responsibilities
This role is responsible for developing, implementing, and maintaining governance, risk, and compliance (GRC) frameworks while managing third-party risk for our clients. The position ensures adherence to regulatory requirements, internal policies, and industry standards, while proactively identifying and mitigating risks associated with internal processes and external vendors.
· Develop and maintain GRC frameworks aligned with organizational goals and regulatory requirements.
· Perform risk assessments, maintain risk registers, and manage risk acceptance and policy exceptions.
· Ensure compliance with regulatory requirements for clients and internal policies.
· Monitor information security risks and drive remediation of policy exceptions.
· Conduct control testing to evaluate the maturity and effectiveness of security controls (HIPAA, HITRUST, NIST
· Define risk thresholds, implement risk frameworks, and remediate identified gaps.
· Manage risk and policy exceptions through GRC platforms.
· Review High and Critical risks monthly with risk owners and executive leadership.
· Create executive dashboards and reports for leadership visibility into risk posture and KPIs.
· Stay current on regulatory changes, security trends, and compliance requirements.
· Track key risk register and policy exception metrics.
· Establish a baseline of vendor risk and identify areas of potential exposure.
· Design and implement a consistent Third-Party Risk Management (TPRM) program aligned with internal policy and regulatory requirements.
· Conduct pre-contract due diligence and ongoing vendor risk assessments.
· Develop mitigation plans and partner with internal stakeholders to monitor vendor performance post-contract.
· Provide guidance to business units and sourcing teams on VRM requirements.
· Maintain structured governance for vendor risk and procurement compliance.
· Ensure compliance with SOC 1 and SOC 2 audit requirements.
· Continually reassess operational risks and emerging threats related to vendors.
· Create executive summaries with recommendations for remediation and risk disposition.
· Track key vendor-related metrics.
Qualifications
· Bachelor's degree or higher level of education
· years of technical experience in Information Security
· GRC platform implementation experience (such as NAVEX Service Now, LogicGate, Rsam)
· Auditing skills and the ability to manage risk assessments / projects independently.
· Excellent communication skills both verbal and written.
· Good presentation skills particularly ability to present technology elements in manner personnel can follow and act.
· Good understanding of HIPAA, HITRUST and Security Core Concepts
· Experience with federal cyber security standards (such as NIST
· Experience in performing vendor & Product assessment (manual or tool-based)
Nice To Have Skills
Professional accreditation in IT audit, security, privacy or other related technology disciplines (CISA, CISSP, CompTIA Security+: etc.)
Careers with Optum. Here's the idea. We built an entire organization around one giant objective; make the health system work better for everyone. So, when it comes to how we use the world's large accumulation of health-related information, or guide health and lifestyle choices or manage pharmacy benefits for millions, our first goal is to leap beyond the status quo and uncover new ways to serve. Optum, part of the UnitedHealth Group family of businesses, brings together some of the greatest minds and most advanced ideas on where health care must go in order to reach its fullest potential. For you, that means working on high performance teams against sophisticated challenges that matter. Optum, incredible ideas in one incredible company and a singular opportunity to do your life's best work.
Market Competitive Benefits and Pay Levels
Great Workplace
Career Growth and Development
-
Consultant, Risk and Compliance
2 weeks ago
Taguig, National Capital Region, Philippines Marsh McLennan Full timeWe are seeking a talented individual to join our Mercer Sentinel team at Mercer. This role will be based in Manila, Philippines. This is a hybrid role that has a requirement of working at least three days a week in the office.You will be part of a newly established and growing Mercer Sentinel team located in the Philippines, reporting into the Mercer...
-
Chief Compliance and Risk Officer
2 weeks ago
Taguig, National Capital Region, Philippines Delivery Hero Full timeCompany Description foodpanda is part of the Delivery Hero Group, the world's pioneering local delivery platform, our mission is to deliver an amazing experience—fast, easy, and to your door. We operate in over 70+ countries worldwide. Headquartered in Berlin, Germany. Delivery Hero has been listed on the Frankfurt Stock Exchange since 2017 and is part of...
-
IT Auditor/Technology Risk Consultant
1 week ago
Taguig, National Capital Region, Philippines HRTX Full timeAs a Privacy Analyst, Technology Analyst, you will play a key role in assessing, implementing, and maintaining privacy-enhancing technologies and compliance solutions. This position collaborates closely with legal, IT, security, and data governance teams to ensure privacy controls are integrated into business processes and technology systems. The...
-
Technology Risk Senior Consultant
2 weeks ago
Taguig, National Capital Region, Philippines HRTX Full timeThe Technology Risk Senior Consultant - Cloud Control, specifically within Financial Services, focuses on assessing and managing technology risks related to cloud computing for financial institutions. This role involves leading teams, conducting risk assessments, developing and implementing controls, and ensuring compliance with relevant regulations and...
-
IT Risk
2 weeks ago
Taguig, National Capital Region, Philippines Goodyear Regional Business Services, Inc. Full timeJob Description SummaryThis role is part of the Global IT Risk & Security team and reports to the Global IT Risk & Security Manager. The IT Risk & Security Consultant will provide expert guidance in security planning, consulting, and assessment for both IT and physical security initiatives. This position plays a key role in developing and implementing...
-
IT Security Risk and Compliance Analyst
5 days ago
Taguig, National Capital Region, Philippines Cushman & Wakefield Full timeJob TitleIT Security Risk and Compliance AnalystJob Description SummaryJob SummaryThe IT Security Risk & Compliance Analyst is responsible for managing daily security operations, supporting cross-regional initiatives, and ensuring compliance with internal and external security standards. The role involves collaboration with various teams, including Legal and...
-
Governance Operational Risk Analyst
3 days ago
Taguig, National Capital Region, Philippines ByteDance Full timeResponsibilitiesE-commerce's Governance and Experience (GNE) is a global team responsible for ensuring our marketplace is safe and trustworthy for not only our users, but also sellers and creators. We value user satisfaction and work on policies, rules and systems to ensure quality. Our mission is to provide world-class service and experience for customers,...
-
Analyst, Risk and Compliance
2 weeks ago
Taguig, National Capital Region, Philippines Marsh McLennan Full timeWe are seeking a talented individual to join our Mercer Sentinel team at Mercer. This role will be based in Manila, Philippines. This is a hybrid role that has a requirement of working at least three days a week in the office.You will be part of a newly established and growing Mercer Sentinel team located in the Philippines, reporting into the Mercer...
-
Risk Management and Compliance Lead
2 weeks ago
Taguig, National Capital Region, Philippines Globe Telecom Full timeAt Globe, our goal is to create a wonderful world for our people, business, and nation. By uniting people of passion who believe they can make a difference, we are confident that we can achieve this goal.Job DescriptionThe Risk Management and Compliance Lead plays a crucial role in ensuring our organization's adherence to environmental, energy, occupational...
-
Data Governance Head
7 days ago
Taguig, National Capital Region, Philippines EastWest Bank Full timeAbout the Job Location: Taguig Corporate Title: Assistant Vice President to Vice President Work Arrangement: Hybrid Our Enterprise Data Office team is looking for experienced professionals to join us in Taguig with the role of Data Governance Head. In this role you will define, implement, and sustain the Banks enterprise-wide data and model governance...