Risk and Compliance Officer

2 weeks ago


Pasig, National Capital Region, Philippines PAN ASIA Resources Full time ₱720,000 - ₱1,440,000 per year

Role Summary

The Risk & Compliance Officer owns the day-to-day operation of the organization's

Governance, Risk, and Compliance program. The role identifies and assesses risks,

maintains the control framework, drives remediation with control owners, and ensures

ongoing compliance with applicable standards, contracts, and regulations (e.g., ISO

27001:2022, SOC 2, PCI DSS, Data Privacy Act of 2012, HIPAA as applicable). The officer

partners with IT, Security, Operations, Legal, HR, and third parties to keep risk within

appetite and audit-ready.

Key Responsibilities:

1) Governance & Policy

  • Maintain the Information Security & Privacy policies, standards, and procedures;

run annual reviews and board approvals.

  • Ensure policy dissemination (briefings, acknowledgments) and map policies to

control frameworks.

2) Enterprise Risk Management

  • Run periodic risk assessments (business, cyber, operational, vendor); document

risks, likelihood/impact, and treatment plans.

  • Maintain the Risk Register; track mitigations to closure and report residual risk vs.

appetite.

  • Facilitate risk acceptances/exceptions with defined expiry and compensating

controls.

3) Compliance & Audits

  • Plan and execute internal control testing; collect evidence for external audits and

customer due-diligence.

  • Lead readiness for ISO 27001, SOC 2, PCI DSS (as applicable), and client

assessments; coordinate gap remediation.

  • Monitor regulatory obligations (e.g., NPC/PH Data Privacy Act) and ensure

compliance.

4) Third-Party/Vendor Risk Management

  • Operate supplier onboarding due diligence, security questionnaires (SIG/CAIQ),

contract clause reviews, and ongoing monitoring.

  • Maintain a Supply Chain Risk Register; track KRIs (e.g., cert validity, patch latency,

incident notifications).

5) Security Control Assurance

  • Validate operation of key controls: access management, PAM/JIT, vulnerability

management, EDR/XDR, logging/SIEM, backup/DR, encryption, MDM/Intune.

  • Coordinate quarterly segmentation/penetration testing and monthly vulnerability

scans; track findings to closure.

6) Training & Awareness

  • Run the annual security/privacy training program (employees & third parties); track

completion and escalate non-compliance.

  • Conduct targeted trainings (e.g., phishing simulations, secure handling of customer

data).

7) Incident & Change Support

  • Support incident response (documentation, regulatory/customer notifications,

post-incident RCA & corrective actions).

  • Participate in change advisory reviews to ensure security and compliance impacts

are addressed.

8) Reporting & Stakeholder Management

  • Produce monthly/quarterly GRC dashboards for leadership (risk heatmap, control

health, exceptions, audit status).

  • Act as customer/auditor point of contact for security questionnaires and contract

exhibits.

Required Qualifications:

  • Bachelor's degree in IT, Information Security, Business, Accounting, or related field

(or equivalent experience).

  • 3–7+ years in risk, audit, information security, or compliance (GRC) roles.

  • Hands-on experience with at least two frameworks: ISO 27001:2022, SOC 2, PCI

DSS, NIST CSF/800-53, HIPAA, PH Data Privacy Act.

  • Strong understanding of access control, vulnerability management, incident

response, logging/SIEM, cloud/SaaS security.

  • Excellent communication skills; capable of translating technical risk into business

impact and clear actions.

Preferred (nice to have) Certifications:

  • ISO 27001 Lead Implementer/Lead Auditor, CISA, CISM, CRISC, PCI ISA/PCIP,

CIPM/CIPT, ITIL.

  • PH Data Privacy certifications (e.g., DPO training) if handling personal data.

Tools & Technologies (familiarity desired)

  • GRC/IRM: ServiceNow, Archer, OneTrust, Drata, Tugboat, or similar.

  • Identity & Devices: Entra ID/Azure AD, Intune/MDM, LAPS/PAM, Okta/SSO.

  • Security Ops: SIEM (e.g., Microsoft Sentinel), EDR/XDR (e.g., Defender, Palo Alto,

Wazuh), vulnerability scanners (Tenable/Qualys/OpenVAS).

  • Collab & Evidence: Microsoft 365, SharePoint, Confluence/Jira, ticketing

(ServiceNow/Jira).

  • Cloud: Azure/AWS/GCP basics, logging & IAM concepts.

Competencies:

  • Risk analysis & prioritization
    • Control testing
    • Vendor management
    • Policy writing

  • Stakeholder influence
    • Project management
    • Analytical & documentation rigor

  • Integrity, discretion, and strong ownership of outcomes

KPIs / Success Measures

  • % of controls tested and passing (quarterly)

  • % audit findings/corrective actions closed within SLA

  • Risk register freshness (≤30 days) & reduction in high risks over time

  • Training compliance rate (employees & third parties)

  • Vendor due-diligence coverage and on-time renewals Vulnerability remediation SLA adherence (e.g., critical ≤ 15 days)

Job Type: Full-time

Pay: Php30, Php80,000.00 per month

Application Question(s):

  • Do you have a Bachelor's degree in IT, Information Security, Business, Accounting, or any related field?
  • Do you have at least 3–7+ years in risk, audit, information security, or compliance (GRC) roles?
  • Do you have hands-on experience with at least two frameworks: ISO 27001:2022, SOC 2, PCI DSS, NIST CSF/800-53, HIPAA, PH Data Privacy Act?
  • Can you start ASAP?
  • How much is your expected salary?
  • Are you okay working 100% onsite, in Ortigas Pasig?

Work Location: In person


  • Compliance Officer

    2 weeks ago


    Pasig, National Capital Region, Philippines Optimum Solutions Pte Ltd Full time ₱600,000 - ₱800,000 per year

    Compliance OfficerLocation: Pasig CityWe are seeking aCompliance Officerto lead the company's efforts in managing regulatory compliance and risk exposure. The role ensures adherence to theBangko Sentral ng Pilipinas (BSP),Anti-Money Laundering (AML),Foreign Accounts Tax Compliance Act (FATCA), and theData Privacy Act (DPA), along with all related laws,...

  • Compliance Officer

    2 weeks ago


    Pasig, National Capital Region, Philippines Acquire Intelligence Full time ₱900,000 - ₱1,200,000 per year

    We're an award-winning global outsourcer providing contact center and back office services on behalf of our global clients. Come work at a place where innovation and teamwork come together to support the most exciting missions in the worldAt Acquire Intelligence, our mission is to help businesses work smarter.We bring together the best people, efficient...


  • Pasig, National Capital Region, Philippines Acquire Intelligence Full time ₱1,200,000 - ₱2,400,000 per year

    We're an award-winning global outsourcer providing contact center and back office services on behalf of our global clients. Come work at a place where innovation and teamwork come together to support the most exciting missions in the worldAcquire BPO is an award-winning business process outsource provider, to some of the world's largest brands operating...


  • Pasig, National Capital Region, Philippines City Savings Bank Full time ₱900,000 - ₱1,200,000 per year

    We are looking for a skilled and detail-oriented Risk MIS and Model Risk Management Officer to become a key member of our Risk Management Team. This vital position involves managing the hands-on execution of our essential PFRS 9 / ECL credit risk models (Probability of Default, Loss Given Default, Exposure-at-Default), providing key inputs that inform the...


  • Pasig, National Capital Region, Philippines Jollibee Full time ₱900,000 - ₱1,200,000 per year

    JFC's Enterprise Risk Officer is responsible for the following:ERM Framework ImplementationSupport ERM framework implementation.Handle ERM documentation.Administer JFC's risk register and coordinate risk actions.Review and recommend process improvements.ERM AdministrationExecute ERM projects per plan and strategies.Collect and clarify information from data...


  • Pasig, National Capital Region, Philippines Acquire Intelligence Full time ₱300,000 - ₱600,000 per year

    We're an award-winning global outsourcer providing contact center and back office services on behalf of our global clients. Come work at a place where innovation and teamwork come together to support the most exciting missions in the worldRISK MANAGEMENT ANALYSTAs a Risk Management Analyst, you will partner with cross-functional department heads and business...


  • Pasig, National Capital Region, Philippines Robert Walters Full time ₱400,000 - ₱800,000 per year

    Join a leading fintech company in Ortigas as a Legal and Compliance Officer – Junior Lawyer. This role offers hands-on experience in contract drafting, regulatory compliance, and risk management. Ideal for a Philippine Bar member with 2–3 years' experience in corporate or financial law, this is a great opportunity to grow within a dynamic, supportive...

  • Operational Risk Lead

    2 weeks ago


    Pasig, National Capital Region, Philippines Tonik Full time ₱900,000 - ₱1,200,000 per year

    Responsibilities:Reports to the Chief Risk OfficerContributes to the efficient and effective functioning of the Risk Management Unit.Leads the implementation of the Operational Risk Management framework and in ensuring that all operational risk methodologies and policies are compliant to the minimum regulatory requirement and updated as relevant to state of...


  • Pasig, National Capital Region, Philippines HRTX Full time ₱2,500,000 - ₱5,000,000 per year

    Overview:We are seeking a seasoned risk professional to lead and strengthen our Enterprise Risk Management (ERM) initiatives. This role is pivotal in ensuring that frameworks, policies, and processes are robust, compliant with BSP regulations, and aligned with industry best practices. Reporting directly to the Chief Risk Officer, the position provides direct...


  • Pasig, National Capital Region, Philippines IQ-EQ Full time ₱800,000 - ₱1,200,000 per year

    Company Description We're a leading Investor Services group offering end-to-end services in administration, accounting, reporting, regulatory and compliance needs of the investment sector worldwide.  We employ a global workforce of 5,800+ people across 25 jurisdictions and have assets under administration (AUA) exceeding US$750 billion. We work with 13 of...