Skip to content

Open nowPosted 8 days ago

Governance, Risk & Compliance Manager

satelliteoffice-1742766257140 open roles

Where
Pasig, Philippines
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGovernance, Risk & Compliance Managersatelliteoffice-1742766257 · Pasig, Philippines
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on satelliteoffice-1742766257's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 8 days ago

The posting

Satellite Office is looking for an experienced Governance, Risk & Compliance (GRC) Manager to join our Risk Management team in Ortigas.

The GRC Manager is responsible for the assurance phase of Satellite Office's risk management function, following the establishment of its policies, risk register, and process documentation.

The role independently tests that internal controls operate as designed, maintains the organisation's compliance posture across applicable regulatory, certification, and client-contractual requirements, and serves as the Company's Data Protection Officer (DPO) under the Philippine Data Privacy Act.

The GRC Manager additionally maintains the enterprise risk registers and administers the RCSA, reporting outcomes to the Risk Committee.

This is a hands-on role with exposure across internal controls, compliance, enterprise risk, data privacy and governance, with regular interaction with senior executives and governance committees.

What You'll Be Doing

Control Testing (Audit Function)

  • Design and run an ongoing controls-testing program.
  • Assess both the design and the operating effectiveness of controls through transaction and evidence sampling, maintain formal workpapers, and assign a rating to each control tested.
  • Report control exceptions, remediation plans, and re-test results to the Risk Committee in accordance with the established reporting cycle.
  • Coordinate with control owners on the closure of identified gaps, while maintaining independence from the functions whose controls are subject to testing.

Compliance Management

  • Monitor adherence to all relevant laws pertinent to the operations of Satellite Office, internal policies and relevant industry standards such as ISO27001, SOC2, GDPR and HIPAA.
  • Monitor compliance with applicable regulatory and client-contractual requirements, including requirements for regulated clients and sector-specific obligations.
  • Develop, implement, and maintain compliance policies and procedures.
  • Maintain and monitor the Compliance Register and oversee and govern statutory reporting outside tax.
  • Monitor compliance findings and pending actions through to formal closure.

Data Protection Officer (DPO)

  • Serve as the Company's registered Data Protection Officer with the National Privacy Commission (NPC), maintain current NPC registration, and act as the official point of contact for the NPC and for data subjects.
  • Lead personal data breach response, including compliance with the 72-hour NPC notification requirement.
  • Conduct Privacy Impact Assessments (PIAs) for new or materially changed processes.
  • Administer data subject requests and deliver periodic privacy awareness training across the organisation.

Working knowledge of the Philippine Data Privacy Act and NPC requirements is required. Formal DPO training/certification is an advantage, with certification support available following appointment.

Enterprise Risk

  • Operationalize the Enterprise Risk Management (ERM) and Governance frameworks to align with Satellite Office’s mission and vision and strategic objectives.
  • Maintain the Enterprise risk registers on an annual refresh cycle, in coordination with the designated risk owners and the Business Process Manager.
  • Administer and further develop the KRI program established for the principal residual risks, and escalate early-warning indicators to the Risk Committee.
  • Lead the GRC component of Incident Reporting, ensuring that operational risk incidents are detected, reported, and mitigated within statutory and policy timelines.
  • Design Business Continuity and Crisis Management protocols.
  • Coordinate with other departments, including Legal and IT, for incident investigations and risk assessments.

Governance Support

  • Own the Risk Committee reporting and meeting cadence and apply the organisation's established risk appetite framework.
  • Act as a liaison to address compliance concerns or inquiries from stakeholders.
  • Ensure pending actions and committee reporting obligations are completed on schedule.
  • Assist in the development and delivery of GRC training programs on compliance, risks and governance policies and the creation of awareness initiatives to promote ethical and compliance by design practices.
  • Provide independent risk opinions and advisory input on projects, systems, vendors, and process changes, including sign-off on risk acceptance and escalation of residual exposures.
  • Present findings and risk insights directly and independently to senior executives and committees.

What We're Looking For

We're looking for an experienced GRC professional who can combine strong risk and compliance knowledge, independent assurance capability and confident stakeholder management.

You'll ideally bring:

  • Bachelor's degree in Accounting, Finance, Information Systems, Law or a related field.
  • 8+ years in risk and compliance management, internal audit, IT/compliance control testing, or GRC.
  • Experience in BPO, financial services or another regulated industry. BPO experience is particularly relevant.
  • Professional certification preferred: CPA, CIA or CISA.
  • ISO 27001 Lead Auditor certification is preferred.
  • Strong knowledge of regulatory requirements and risk management frameworks.
  • Experience with US regulatory requirements. Australian regulatory knowledge is advantageous.
  • Working knowledge of the Philippine Data Privacy Act and NPC requirements.
  • Hands-on experience with a GRC platform such as Sprinto, Vanta or similar. Experience with Sprinto is advantageous, but the ability to learn a GRC platform is important.
  • Demonstrated project management experience — able to plan, scope, and deliver GRC initiatives on schedule and across multiple stakeholders.
  • Experience issuing independent risk opinions and advisory input on projects, systems, vendors, and process changes.
  • Comfortable presenting findings directly and independently to senior executives and committees.
  • Strong communication and stakeholder management skills, with the confidence to engage with senior leadership and challenge constructively where required.

What Will Set You Apart

You'll stand out if you have:

  • Experience in BPO and/or financial services, particularly in a regulated environment.
  • Experience with control testing, RCSA, KRIs and enterprise risk registers.
  • Experience supporting SOC 2, ISO 27001, GDPR, HIPAA or similar assurance requirements.
  • Previous experience as a DPO or significant hands-on privacy compliance experience.
  • Experience with Sprinto, Vanta or similar GRC platforms.
  • Experience presenting directly to ExCo, Risk Committees, Boards or similar governance forums.
  • A practical approach to risk management and the ability to work across multiple stakeholders to drive remediation and closure.

Why Join Satellite Office?

This is an opportunity to take ownership of a broad GRC portfolio and have meaningful exposure across the organisation.

You'll work closely with senior leadership and the Risk Committee while helping strengthen Satellite Office's risk, compliance, controls, privacy and governance frameworks.

If you're an experienced GRC professional who enjoys working independently, engaging with senior stakeholders and turning risk and compliance requirements into practical outcomes, we'd love to hear from you.

Apply now and join Satellite Office as our next Governance, Risk & Compliance Manager.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against satelliteoffice-1742766257's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on satelliteoffice-1742766257's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    satelliteoffice-1742766257's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.