Confidence in defending risk assessments and responding constructively to challenges
Responsibilities
Enterprise Risk Management
- Own the enterprise risk register, including its structure, scoring, tolerance thresholds, and escalation triggers.
- Lead organization-wide risk intake and hold named owners accountable for mitigation plans and quarterly attestations.
- Quantify financial exposure and mitigation-versus-acceptance costs with Finance.
- Maintain monthly reporting, elevate threshold breaches, and present risk positions to executive and Board-level audiences.
- Integrate risk reporting into governance processes and coordinate documentation with Compliance and Audit.
Business Continuity and Crisis Management
- Own the business continuity framework across all locations, including policies, standards, plans, and governance.
- Maintain business impact analyses, dependency maps, and recovery objectives across critical sites, services, and functions.
- Identify and address single points of failure involving people, systems, vendors, and facilities.
- Manage annual exercises, after-action reviews, and remediation through closure.
- Serve as incident commander and coordinate stakeholder communications during major disruptions.
- Review client continuity requirements, support audits and assessments, and extend the framework across international locations.
Employee Health Services and Occupational Safety
- Lead Employee Health Services and Safety Officers in compliance with Philippine labor and occupational safety regulations.
- Ensure each site meets statutory staffing requirements for health personnel and accredited safety officers.
- Oversee clinics, healthcare providers, health programs, emergency response, and safety committees.
- Maintain regulatory records, workplace inspections, and DOLE inspection readiness.
- Promote hazard identification, corrective action, and reduced workplace incidents.
Physical Security and Surveillance
- Oversee access controls, guarding, visitor procedures, asset movement, incident reporting, and investigations.
- Manage CCTV coverage, retention, monitoring, and footage release in compliance with privacy, legal, and HR requirements.
- Govern contracted security providers in partnership with Procurement.
- Ensure security controls meet requirements for regulated and data-sensitive accounts.
Leadership and Governance
- Build and lead the enterprise risk and business resiliency function.
- Recruit and develop the Business Continuity Planning Manager, Physical Security Manager, and wider team.
- Establish performance indicators, reporting cadences, operating rhythms, and evidence standards.
- Manage budgets and present cost-versus-exposure analyses supporting resilience investments.
Priority Mandates: First 12 Months
Two existing programs will transfer to this role on the first day and must be completed successfully.
Mandate 1: Company-Wide Risk Register and Refresh Framework
- Design the risk register structure, ownership model, scoring, tolerance thresholds, and escalation paths.
- Establish a Finance-approved methodology assigning peso-denominated exposure values to material risks.
- Implement phased risk intake across all functions.
- Introduce quarterly attestations, monthly exception reporting, and event-triggered updates.
- Present a quantified enterprise risk view to the COO by December and integrate it into executive and Board reporting.
Mandate 2: Strengthening Business Continuity Controls
- Assess existing controls against ISO 22301 principles and contractual requirements.
- Address gaps in notifications, call trees, remote-work continuity, site failover, dependency mapping, and recovery objectives.
- Validate recovery objectives through testing and realistic continuity exercises.
- Assign findings to named owners and monitor corrective actions through closure.
- Create a reusable response pack for client audits and due diligence reviews.
Success Measures
- Present the enterprise risk view by December and complete departmental intake within 6 months of launch.
- Achieve at least 95% on-time quarterly attestations, with every material risk assigned an owner and mitigation plan.
- Exercise every critical site and service line within 12 months and assign all findings to owners and closure dates.
- Maintain zero adverse DOLE findings and meet statutory health and safety staffing requirements.
- Complete after-action reviews within 5 working days of major incidents and track corrective actions through closure.
- Fill both manager positions within 6 months and ensure they are fully performing.
Join Emapta, recognized as one of HR Asia's Best Companies to Work For in Asia 2025 and winner of Inspiring Workplaces Australasia 2026. With a 50/50 gender ratio and a culture rooted in care and empathy, you'll feel valued from day one. We're committed to growing talent and setting you up for success.
Be part of a team that showcases Filipino excellence to the world. With over 30 offices across 11 countries and 1,200+ clients, you'll create real impact every day—whether you work from home or on-site. Our 100% virtual recruitment process makes it easy to get started.
At Emapta, you're not just joining a company—you're becoming part of a thriving community of 12,000+ professionals growing careers with purpose. And behind every partnership we build is a deep respect for people and the impact they make.
We place integrity at the heart of everything we do and truly value the human experience. That's why, for clients, it's a profound and transformational process that gives them the opportunity to achieve the business growth they desire.
Tim Vorbach, CEO
#EmaptaEra