Governance Risk and Compliance I Analyst II

2 weeks ago


Mandaluyong City, National Capital Region, Philippines Vertiv Full time

Job Title: GRC Analyst

Division: Governance, Risk & Compliance – IT Security

---

Position Summary

We are seeking a GRC Analyst to support our Governance, Risk, and Compliance services across a global enterprise. The role involves direct execution of risk assessments, third-party risk reviews, audit support, and internal compliance activities. The ideal candidate is proactive, has a working knowledge of compliance frameworks and GRC tools, and demonstrates excellent collaboration, organization, and communication skills.

---

Key Responsibilities


• Conduct and document IT risk assessments and track mitigation plans.


• Maintain the risk register and support periodic risk revalidation with risk owners.


• Perform third-party risk assessments using OneTrust, SecurityScorecard, or similar platforms.


• Support responses to customer security questionnaires and audits using Loopio.


• Review and process exemption and exception requests using ServiceNow.


• Support and coordinate activities for ITGC audits (SOX, ISO 27001, SSAE18).


• Assist with preservation hold reviews and coordinate with Legal on related activities.


• Monitor risks for aging or inactivity and trigger reassessments and follow-ups as needed.


• Track control and audit findings and work with stakeholders to ensure remediation activities are executed.


• Contribute to process improvement efforts, SOP updates, and documentation of best practices.


• Collaborate with senior analysts to track and report GRC KPIs and metrics to leadership.

Qualifications


• Bachelor's degree in information systems, Cybersecurity, Business, or related field.


• 3–5 years of experience in IT GRC, audit support, or information security.


• Familiarity with compliance frameworks such as ISO 27001, NIST CSF, SOX, and SSAE18.


• Experience with GRC tools such as OneTrust, ServiceNow, SecurityScorecard, or AuditBoard.


• Understanding of ITGCs, UAR/TERM, and common risk and control practices.


• Proficiency in Microsoft Office tools, especially Excel and PowerPoint.


• Effective communication, coordination, and documentation skills.


• Certifications such as CISA, ISO 27001 Lead Implementer, or equivalent (preferred).



  • Mandaluyong City, National Capital Region, Philippines Vertiv Group Full time

    DescriptionJob Title: GRC AnalystDivision: Governance, Risk & Compliance – IT Security---Position SummaryWe are seeking a GRC Analyst to support our Governance, Risk, and Compliance services across a global enterprise. The role involves direct execution of risk assessments, third-party risk reviews, audit support, and internal compliance activities. The...


  • Mandaluyong City, National Capital Region, Philippines Vertiv Full time

    Job Title: GRC AnalystDivision: Governance, Risk & Compliance – IT Security-Position SummaryWe are seeking a GRC Analyst to support our Governance, Risk, and Compliance services across a global enterprise. The role involves direct execution of risk assessments, third-party risk reviews, audit support, and internal compliance activities. The ideal candidate...


  • Mandaluyong City, National Capital Region, Philippines Vertiv Group Full time

    DescriptionAt Vertiv, we don't just hire talent—we cultivate leaders who drive innovation and engage teams to push the limits of what's possible. As a global leader in critical digital infrastructure, we are scaling up to meet the demands of AI, data


  • Mandaluyong City, National Capital Region, Philippines Vertiv Full time

    Job Title: Senior GRC AnalystDivision: Governance, Risk & Compliance – IT Security Position SummaryThe Senior GRC Analyst will act as a key contributor to Vertiv's Governance, Risk, and Compliance initiatives, driving risk assessments, security reviews, audit readiness, and third-party risk management efforts. This role supports continuous improvement of...


  • Mandaluyong City, National Capital Region, Philippines Vertiv Group Full time

    DescriptionJob Title: Senior GRC AnalystDivision: Governance, Risk & Compliance – IT Security Position SummaryThe Senior GRC Analyst will act as a key contributor to Vertiv's Governance, Risk, and Compliance initiatives, driving risk assessments, security reviews, audit readiness, and third-party risk management efforts. This role supports continuous...


  • Mandaluyong City, National Capital Region, Philippines Vertiv Full time

    Job Title: Senior GRC AnalystDivision: Governance, Risk & Compliance – IT SecurityPosition SummaryThe Senior GRC Analyst will act as a key contributor to Vertiv's Governance, Risk, and Compliance initiatives, driving risk assessments, security reviews, audit readiness, and third-party risk management efforts. This role supports continuous improvement of...


  • Mandaluyong City, National Capital Region, Philippines Vertiv Group Full time

    DescriptionAt Vertiv, we don't just hire talent—we cultivate leaders who drive innovation and engage teams to push the limits of what's possible. As a global leader in critical digital infrastructure, we are scaling up to meet the demands of AI, data


  • Mandaluyong City, National Capital Region, Philippines Vertiv Full time

    Join a High-Performance Culture That Drives Innovation and ExcellenceAt Vertiv, we don't just hire talent—we cultivate leaderswho driveinnovation and engageteams to push the limits of what's possible. As a global leader in critical digital


  • Mandaluyong City, National Capital Region, Philippines Vertiv Group Full time

    DescriptionAt Vertiv, we don't just hire talent—we cultivate leaders who drive innovation and engage teams to push the limits of what's possible. As a global leader in critical digital infrastructure, we are scaling up to meet the demands of AI, data


  • Mandaluyong City, National Capital Region, Philippines Vertiv Full time

    At Vertiv, we don't just hire talent—we cultivate leaders who drive innovation and engage teams to push the limits of what's possible. As a global leader in critical digital infrastructure, we are scaling up to meet the demands of AI, data