Compliance Manager

NQX Philippines

Taytay

On-site

PHP 1,200,000 - 2,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NQX Philippines is seeking a Compliance Manager to lead audits and ensure adherence to PCI DSS, SOC 2 Type 2, BCP, and PIPEDA across the organization. You will collaborate with IT, security, HR, and business teams to strengthen controls, document findings, and drive continuous improvement in regulatory compliance.

The role requires certifications like CISM, PCI Professional or SOC 2, 5+ years in compliance, and strong analytical and communication skills.

Qualifications

  • CISM, PCI Professional, SOC 2, or similar certifications are highly desirable.
  • Proven experience (5+ years) in compliance management, specifically with PCI DSS, SOC 2 Type 2, BCP, and PIPEDA.
  • Strong understanding of regulatory frameworks and industry standards.
  • Experience with audit methodologies and internal control frameworks.
  • Strong analytical, problem-solving, and risk management skills.
  • Excellent communication and interpersonal skills with the ability to interact with all levels of the organization.
  • Knowledge of data privacy laws and IT security best practices.

Responsibilities

  • Conduct internal audits to assess PCI DSS, SOC 2 Type 2, BCP, and PIPEDA compliance.
  • Oversee PCI DSS controls, assessments, and audits.
  • Coordinate SOC 2 Type 2 audit with external auditors.
  • Develop and test Business Continuity Plans and Disaster Recovery plans.
  • Ensure data privacy compliance and enforce data protection policies.
  • Provide compliance training and raise awareness.
  • Prepare compliance reports for senior management.

Skills

CISM (Certified Information Security)
PCI Professional
SOC 2

Education

SOC 2 Type 2 or similar certifications

Job description

ROLE OVERVIEW

Compliance Manager oversees and manages the compliance activities for our organization, focusing on PCI DSS, SOC 2 Type 2, Business Continuity Planning (BCP), and PIPEDA (Personal Information Protection and Electronic Documents Act). The ideal candidate will be responsible for auditing, monitoring, and ensuring compliance with these standards, as well as leading initiatives to improve our internal control frameworks. This role will involve working closely with IT, Human Resources, security, and business teams to ensure that our practices meet the highest standards of regulatory compliance.

KEY RESPONSIBILITIES
Compliance Audits and Monitoring:
  • Conduct internal audits to assess the organization’s compliance with PCI DSS, SOC 2 Type 2, BCP, and PIPEDA.
  • Perform periodic risk assessments and gap analysis to identify and address compliance issues proactively.
  • Ensure that all compliance programs are up-to-date and align with industry standards and regulatory requirements.
PCI DSS Compliance Oversight:
  • Oversee the implementation and maintenance of PCI DSS controls and processes.
  • Manage the preparation, execution, and documentation of PCI DSS assessments and audits.
  • Work closely with IT and security teams to ensure that proper encryption, access controls, and secure payment practices are in place.
SOC 2 Type 2 Compliance Management:
  • Oversee the design, implementation, and testing of controls for SOC 2 Type 2 compliance.
  • Coordinate with external auditors for the SOC 2 Type 2 audit process and address any findings or issues.
  • Collaborate with relevant departments to maintain a secure and compliant IT environment.
Business Continuity and Disaster Recovery (BCP):
  • Manage the development, implementation, and testing of Business Continuity Plans (BCP) and Disaster Recovery (DR) plans.
  • Ensure that the company is prepared for operational disruptions and maintain up-to-date records of BCP tests and drills.
  • Work with senior leadership to identify and mitigate potential risks that could affect business continuity.
PIPEDA Compliance and Privacy Oversight:
  • Ensure the organization’s practices comply with PIPEDA regulations and data privacy requirements.
  • Implement and enforce data protection policies and guidelines to safeguard personal information.
  • Conduct audits and reviews of data collection, storage, and processing activities to ensure they align with legal and regulatory requirements.
Training and Awareness:
  • Develop and deliver training programs to employees on compliance-related topics, including PCI DSS, SOC 2, BCP, and PIPEDA.
  • Raise awareness on the importance of compliance and data security throughout the organization.
  • Stay updated on evolving industry standards and regulatory changes to ensure the organization remains compliant.
Reporting and Documentation:
  • Prepare regular reports for senior management, highlighting compliance status, audit findings, and areas of improvement.
  • Document compliance activities, audit results, and corrective actions taken in accordance with regulatory standards.
  • Track and report on compliance KPIs and metrics.
Collaboration and Stakeholder Management:
  • Act as the primary point of contact for internal and external stakeholders regarding compliance matters.
  • Collaborate with external auditors and regulatory bodies as needed.
  • Foster a culture of continuous improvement by recommending enhancements to compliance processes and systems.
QUALIFICATIONS
  • CISM (Certified Information Security Manager), PCI Professional, SOC 2, or similar certifications are highly desirable.
  • Proven experience (5+ years) in compliance management, specifically with PCI DSS, SOC 2 Type 2, BCP, and PIPEDA.
  • Strong understanding of regulatory frameworks and industry standards.
  • Experience with audit methodologies and internal control frameworks.
  • Strong analytical, problem-solving, and risk management skills.
  • Excellent communication and interpersonal skills with the ability to interact with all levels of the organization.
  • Knowledge of data privacy laws and IT security best practices.

#LI-KN1

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Manager
Compliance Manager

Quantrics Enterprises Inc. • Taytay

On-site
Compliance Manager
Compliance Manager

Quantrics • Hinoba-an

On-site
PHP 900,000 - 1,300,000
Compliance Program Lead - PCI DSS, SOC 2 & Privacy
Compliance Program Lead - PCI DSS, SOC 2 & Privacy

Quantrics Enterprises Inc. • Taytay

On-site
PHP 400,000 - 600,000
Compliance Manager - PCI DSS, SOC 2, BCP, PIPEDA
Compliance Manager - PCI DSS, SOC 2, BCP, PIPEDA

NQX Philippines • Taytay

On-site
PHP 1,200,000 - 2,100,000
Regulatory Compliance & Privacy Leader (PCI-DSS, SOC 2)
Regulatory Compliance & Privacy Leader (PCI-DSS, SOC 2)

Quantrics • Hinoba-an

On-site
PHP 900,000 - 1,300,000
Specialist - Governance Risk and Compliance
Specialist - Governance Risk and Compliance

Concentrix • Morong

On-site
PHP 600,000 - 1,000,000
Data Security Analyst (Work from Home)
Data Security Analyst (Work from Home)

Quantrics Enterprises Inc. • Manila

On-site
PHP 600,000 - 1,100,000
Compliance Analyst
Compliance Analyst

Eastvantage Careers • Manila

On-site
PHP 480,000 - 720,000
Security, Data Privacy & Compliance Manager (Accepting Applicants)
Security, Data Privacy & Compliance Manager (Accepting Applicants)

AF Payments Inc. • Philippines

On-site
PHP 1,500,000 - 2,700,000
InfoSec Framework & Compliance Lead (ISMS/PCI-DSS) | Hybrid
InfoSec Framework & Compliance Lead (ISMS/PCI-DSS) | Hybrid

GCash • Manila

On-site
PHP 1,800,000 - 3,000,000