Risk and Compliance Officer
7 days ago
Role Summary
The Risk & Compliance Officer owns the day-to-day operation of the organization's
Governance, Risk, and Compliance program. The role identifies and assesses risks,
maintains the control framework, drives remediation with control owners, and ensures
ongoing compliance with applicable standards, contracts, and regulations (e.g., ISO
27001:2022, SOC 2, PCI DSS, Data Privacy Act of 2012, HIPAA as applicable). The officer
partners with IT, Security, Operations, Legal, HR, and third parties to keep risk within
appetite and audit-ready.
Key Responsibilities:
1) Governance & Policy
- Maintain the Information Security & Privacy policies, standards, and procedures;
run annual reviews and board approvals.
- Ensure policy dissemination (briefings, acknowledgments) and map policies to
control frameworks.
2) Enterprise Risk Management
- Run periodic risk assessments (business, cyber, operational, vendor); document
risks, likelihood/impact, and treatment plans.
- Maintain the Risk Register; track mitigations to closure and report residual risk vs.
appetite.
- Facilitate risk acceptances/exceptions with defined expiry and compensating
controls.
3) Compliance & Audits
- Plan and execute internal control testing; collect evidence for external audits and
customer due-diligence.
- Lead readiness for ISO 27001, SOC 2, PCI DSS (as applicable), and client
assessments; coordinate gap remediation.
- Monitor regulatory obligations (e.g., NPC/PH Data Privacy Act) and ensure
compliance.
4) Third-Party/Vendor Risk Management
- Operate supplier onboarding due diligence, security questionnaires (SIG/CAIQ),
contract clause reviews, and ongoing monitoring.
- Maintain a Supply Chain Risk Register; track KRIs (e.g., cert validity, patch latency,
incident notifications).
5) Security Control Assurance
- Validate operation of key controls: access management, PAM/JIT, vulnerability
management, EDR/XDR, logging/SIEM, backup/DR, encryption, MDM/Intune.
- Coordinate quarterly segmentation/penetration testing and monthly vulnerability
scans; track findings to closure.
6) Training & Awareness
- Run the annual security/privacy training program (employees & third parties); track
completion and escalate non-compliance.
- Conduct targeted trainings (e.g., phishing simulations, secure handling of customer
data).
7) Incident & Change Support
- Support incident response (documentation, regulatory/customer notifications,
post-incident RCA & corrective actions).
- Participate in change advisory reviews to ensure security and compliance impacts
are addressed.
8) Reporting & Stakeholder Management
- Produce monthly/quarterly GRC dashboards for leadership (risk heatmap, control
health, exceptions, audit status).
- Act as customer/auditor point of contact for security questionnaires and contract
exhibits.
Required Qualifications:
- Bachelor's degree in IT, Information Security, Business, Accounting, or related field
(or equivalent experience).
3–7+ years in risk, audit, information security, or compliance (GRC) roles.
Hands-on experience with at least two frameworks: ISO 27001:2022, SOC 2, PCI
DSS, NIST CSF/800-53, HIPAA, PH Data Privacy Act.
- Strong understanding of access control, vulnerability management, incident
response, logging/SIEM, cloud/SaaS security.
- Excellent communication skills; capable of translating technical risk into business
impact and clear actions.
Preferred (nice to have) Certifications:
- ISO 27001 Lead Implementer/Lead Auditor, CISA, CISM, CRISC, PCI ISA/PCIP,
CIPM/CIPT, ITIL.
- PH Data Privacy certifications (e.g., DPO training) if handling personal data.
Tools & Technologies (familiarity desired)
GRC/IRM: ServiceNow, Archer, OneTrust, Drata, Tugboat, or similar.
Identity & Devices: Entra ID/Azure AD, Intune/MDM, LAPS/PAM, Okta/SSO.
Security Ops: SIEM (e.g., Microsoft Sentinel), EDR/XDR (e.g., Defender, Palo Alto,
Wazuh), vulnerability scanners (Tenable/Qualys/OpenVAS).
- Collab & Evidence: Microsoft 365, SharePoint, Confluence/Jira, ticketing
(ServiceNow/Jira).
- Cloud: Azure/AWS/GCP basics, logging & IAM concepts.
Competencies:
Risk analysis & prioritization
• Control testing
• Vendor management
• Policy writingStakeholder influence
• Project management
• Analytical & documentation rigorIntegrity, discretion, and strong ownership of outcomes
KPIs / Success Measures
% of controls tested and passing (quarterly)
% audit findings/corrective actions closed within SLA
Risk register freshness (≤30 days) & reduction in high risks over time
Training compliance rate (employees & third parties)
Vendor due-diligence coverage and on-time renewals Vulnerability remediation SLA adherence (e.g., critical ≤ 15 days)
Job Type: Full-time
Pay: Php30, Php80,000.00 per month
Application Question(s):
- Do you have a Bachelor's degree in IT, Information Security, Business, Accounting, or any related field?
- Do you have at least 3–7+ years in risk, audit, information security, or compliance (GRC) roles?
- Do you have hands-on experience with at least two frameworks: ISO 27001:2022, SOC 2, PCI DSS, NIST CSF/800-53, HIPAA, PH Data Privacy Act?
- Can you start ASAP?
- How much is your expected salary?
- Are you okay working 100% onsite, in Ortigas Pasig?
Work Location: In person
-
Legal Risk and Compliance Officer
2 weeks ago
Pasig, National Capital Region, Philippines Robert Walters Full time ₱1,200,000 - ₱2,400,000 per yearAn exciting opportunity has arisen for a Legal Risk and Compliance Officer to join a respected financial services organisation based in Ortigas. With a focus on professional growth, this position offers you the chance to expand your expertise through hands-on involvement in compliance initiatives, training sessions, and direct engagement with key...
-
Risk Officer
2 weeks ago
Pasig, National Capital Region, Philippines WHR Global Consulting Full time ₱35,000 - ₱50,000 per yearPOSITION TITLE:Risk Officer (Power Sector)WORK LOCATION:Ortigas, Pasig CityWORK SETUP:Full Time, OnsiteSALARY:PHP 35,000–50,000JOB SUMMARY:The Risk Officer is responsible for supporting the implementation and execution of the enterprise risk management (ERM) framework across the organization. The role focuses on identifying, assessing, monitoring, and...
-
governance, risk and compliance
2 weeks ago
Pasig, National Capital Region, Philippines TraxionTech Inc Full time ₱900,000 - ₱1,200,000 per yearBASIC FUNCTIONSThe GRC Specialist will be responsible for developing, implementing, and maintaining governance, risk management, and compliance frameworks and policies. This role requires a strong understanding of regulatory requirements, industry standards, and best practices in GRC. Essential Duties and Responsibilities:General Responsibilities:Assists in...
-
IT Compliance Officer
2 weeks ago
Pasig, National Capital Region, Philippines Connext Global Solutions Inc Full time ₱1,200,000 - ₱2,400,000 per yearJob SummaryThe Compliance Officer is responsible for supporting the company's quality management program to meet regulatory and statutory requirements. The role ensures departments comply with standards, supports internal audits, provides oversight on risk and data protection, and implements the organization's Compliance Strategy. The Compliance Officer also...
-
Compliance Officer
2 weeks ago
Pasig, National Capital Region, Philippines Connext Global Solutions Inc Full time $40,000 - $80,000 per yearConnext is a dedicated team of business process outsourcing experts and innovators, with experience in supporting world-class companies in Title and Escrow, Healthcare, Produce Distribution, Retail and Fashion, Design Consulting, and Finance.We are currently looking for a Compliance Officer who will be working with Connext's Client in the United States of...
-
Compliance Officer
5 days ago
Pasig, National Capital Region, Philippines Optimum Solutions Pte Ltd Full time ₱600,000 - ₱800,000 per yearCompliance OfficerLocation: Pasig CityWe are seeking aCompliance Officerto lead the company's efforts in managing regulatory compliance and risk exposure. The role ensures adherence to theBangko Sentral ng Pilipinas (BSP),Anti-Money Laundering (AML),Foreign Accounts Tax Compliance Act (FATCA), and theData Privacy Act (DPA), along with all related laws,...
-
Compliance Officer
2 weeks ago
Pasig, National Capital Region, Philippines House of Franchise Pvt. Ltd. Full timeTo ensure that the company and its franchise operations adhere to internal policies, regulatory requirements, and industry standards. The Compliance Officer monitors compliance activities, identifies risks, and implements corrective actions to maintain ethical and lawful business operations.Conduct regular compliance checks across departments and franchise...
-
Compliance Officer
7 days ago
Pasig, National Capital Region, Philippines Acquire Intelligence Full time ₱900,000 - ₱1,200,000 per yearWe're an award-winning global outsourcer providing contact center and back office services on behalf of our global clients. Come work at a place where innovation and teamwork come together to support the most exciting missions in the worldAt Acquire Intelligence, our mission is to help businesses work smarter.We bring together the best people, efficient...
-
Risk Management and Compliance Analyst
7 days ago
Pasig, National Capital Region, Philippines Acquire Intelligence Full time ₱1,200,000 - ₱2,400,000 per yearWe're an award-winning global outsourcer providing contact center and back office services on behalf of our global clients. Come work at a place where innovation and teamwork come together to support the most exciting missions in the worldAcquire BPO is an award-winning business process outsource provider, to some of the world's largest brands operating...
-
Enterprise Risk Officer
2 weeks ago
Pasig, National Capital Region, Philippines Jollibee Group Full time ₱600,000 - ₱1,200,000 per yearTitle: Enterprise Risk OfficerJFC'sEnterprise Risk Officeris responsible for the following:ERM Framework ImplementationSupport ERM framework implementation.Handle ERM documentation.Administer JFC's risk register and coordinate risk actions.Review and recommend process improvements.ERM AdministrationExecute ERM projects per plan and strategies.Collect and...