General Manager Risk & Compliance

Atain

Manila

On-site

PHP 3,000,000 - 5,000,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Atain, a key leader in risk and compliance, seeks an executive to drive Enterprise Risk Management, data privacy, and regulatory compliance across the Philippines and South Africa clusters. You will oversee internal controls, audits, vendor risk and third-party due diligence, ensuring alignment with ISO, PCI, SOC, and HIPAA standards.

You will guide governance, risk-based decision making, and KPI dashboards, while partnering with stakeholders and auditors to maintain certification readiness and

Qualifications

  • 15+ years of progressive experience in Risk Management, Compliance, Internal Controls, Corporate Governance, or Business Excellence within mid-to-large-scale organizations.
  • Proven experience leading Enterprise Risk Management (ERM) programs, including risk identification, assessment, treatment planning, KRI development, and governance reporting.
  • Extensive experience managing regulatory compliance frameworks, statutory obligations, internal/external audits, and regulatory inspections.
  • Hands-on experience implementing and maintaining security and compliance certifications (ISO 27001, PCI DSS, SOC 1 & 2, HIPAA).

Responsibilities

  • Oversee identification, assessment, and treatment of strategic, operational, financial, information security, and third-party risks.
  • Maintain process risk register, KRIs, and risk appetite frameworks.
  • Provide insights and risk heatmaps to leadership and stakeholder forums.
  • Lead ISMS governance, process risk assessments, internal audits, surveillance audits, and certification cycles.
  • Ensure secure handling, processing, and storage of sensitive data in line with applicable standards.
  • Drive annual certification, recertification, and readiness assessments.
  • Coordinate internal audits, external audits, and compliance audits.
  • Manage end-to-end audit lifecycle: planning, fieldwork, evidence, closure, CAPA validation.

Skills

ERM programs
Regulatory compliance
Audits
Data privacy
Vendor risk management
Internal controls
Stakeholder engagement
Policy creation
GRC tools

Tools

GRC tools

Job description

Location- Philippines

Work Mode- Onsite

Serve as a key leader in driving, shaping, and governing the organization’s Risk and Compliance framework, ensuring alignment with contractual requirements, internal controls, risk assessment and enterprise wide strategic objectives. Provide strategic oversight and direction to core Risk & Compliance initiatives, acting as an anchor member of the organization’s governance structure. Selected candidate will be leading Philippines and South Africa clusters.

  • Oversee identification, assessment, and treatment of strategic, operational, financial, information security, and third-party risks.
  • Maintain process risk register, KRIs, and risk appetite frameworks.
  • Provide insights and risk heatmaps to leadership and stakeholder forums.

Security Certifications & Compliance Standards (ISO 27001, ISO 9001, PCI DSS, SOC 1 & 2, HIPAA)

  • Lead, maintain, and enhance compliance with ISO 27001 & ISO 9001, and other global security frameworks like PCI DSS, SOC -1, SOC – 2 etc.
  • Oversee ISMS governance, process risk assessments, internal audits, surveillance audits, and certification cycles.
  • Ensure secure handling, processing, and storage of sensitive data in line with applicable standards.
  • Collaborate with internal stakeholders and external auditors to ensure control effectiveness.
  • Maintain evidence repositories, Statement of Applicability (SoA), risk treatment plans (RTP), and continuous improvement logs.
  • Drive annual certification, recertification, and readiness assessments.
  • Ensure closure of non-conformities and alignment with regulatory and industry requirements.

Internal Controls & Assurance Specific to NPC (National Privacy Commission, Philippines)

  • Strengthen the organisation’s internal control environment on NPC guidelines.
  • Employee will act as a Data Protection Officer for Philippines location.
  • Conduct process-level DPIA’s, control testing, and remediation tracking.
  • Ensure readiness for internal, external, and regulatory audits.

Audit Governance (Internal, External & Regulatory)

  • Coordinate internal audits, external audits, and compliance audits.
  • Manage end-to-end audit lifecycle: planning, fieldwork, evidence, closure, CAPA validation.
  • Prepare consolidated audit reports for leadership review.

Incident, Breach & Root Cause Management

  • Lead investiagtion for incident/breach management including detection, escalation, containment, and RCA.
  • Provide timely and transparent reporting to leadership.

Third-Party (Client & Vendor Risk Management)

  • Lead end to end client audits & maintain contractual compliance
  • Implement and maintain third-party due diligence, vendor reviews, and ongoing monitoring.
  • Ensure all high-risk vendors are assessed for security, compliance, and contractual controls.
  • Oversee remediation and compliance certification requirements for vendors.

Data Privacy

  • Drive privacy compliance with laws and frameworks (e.g., GDPR principles).
  • Ensure coverage of DFD, ROPA & DPIA’s vis‑à‑vis GDPR
  • Lead data lifecycle governance, retention controls, and breach response readiness.

Reporting, Analytics & GRC Tool Enablement

  • Build and own dashboards for risk, compliance, security certification status, KRIs, audits, and incidents.
  • Ensure high data quality, automation, and real‑time governance.
  • Optimize GRC tools for reporting, workflow automation, and maturity uplift.
  • Build organizational competency in risk and compliance.
  • Deliver training programs in ethics, privacy, cyber hygiene, security standards, and compliance.
  • Promote speak‑up, transparent reporting, and non‑retaliation culture.

RELEVANT EXPERIENCE –

  • 15+ years of progressive experience in Risk Management, Compliance, Internal Controls, Corporate Governance, or Business Excellence within mid‑to‑large-scale organizations.
  • Demonstrated experience in leading Enterprise Risk Management (ERM) programs, including risk identification, assessment, treatment planning, KRI development, and governance reporting.
  • Proven expertise in managing regulatory compliance frameworks, statutory obligations, internal/external audits, and regulatory inspections.
  • Hands‑on experience implementing and maintaining security and compliance certifications, including:

ISO 27001 (ISMS implementation, audit readiness, SoA, RTP, recertification cycles)

PCI DSS compliance (assessment support, evidence readiness, ASV scans, hardening)

SOC 1 & SOC 2 Type I/II (control mapping, walkthroughs, evidence coordination)

HIPAA compliance for PHI environments (privacy/security safeguards, breach readiness)

  • Strong background in designing and strengthening internal control frameworks, conducting control testing, and resolving audit findings with a focus on eliminating repeat issues.
  • Prior responsibility for thirdparty risk management, vendor assessments, contract compliance, and continuous monitoring of highrisk suppliers.
  • Exposure to data privacy, including DPIA, data lifecycle controls, consent management, and privacy compliance (e.g., NPC Act, GDPR‑aligned practices).
  • Experience working closely with Information Security, including vulnerability management, security hards, etc.
  • Demonstrated leadership in policy creation, risk governance, process standardization, and continuous improvement initiatives aligned with Business Excellence.
  • Experience managing cross‑functional teams, senior stakeholder engagement, and presenting insights to leadership, Board, and Audit Committees.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

General Manager - Risk & Compliance
General Manager - Risk & Compliance

Atain • Metro Manila

On-site
PHP 1,500,000 - 2,100,000
Senior Manager – InfoSec Risk and Compliance
Senior Manager – InfoSec Risk and Compliance

Sutherland • Morong

On-site
PHP 2,000,000 - 3,600,000
Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)
Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)

Sutherland • Mabalacat

On-site
PHP 1,500,000 - 2,300,000
IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

Compass Experience Labs • Manila

Hybrid
PHP 1,800,000 - 3,200,000
IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

Compass Experience Labs LLC • Manila

Hybrid
PHP 1,800,000 - 3,200,000
Senior Governance Risk and Compliance Analyst
Senior Governance Risk and Compliance Analyst

Permhunt • Metro Manila

On-site
Competitive salary
Benefit package
On-call support
Data Privacy Officer (Midshift, Onsite)
Data Privacy Officer (Midshift, Onsite)

blaseek • Pasig

On-site
Head of Risk & Compliance [ONSITE]
Head of Risk & Compliance [ONSITE]

Michael Page • Quezon City

On-site
PHP 1,800,000 - 3,200,000
Opportunity for regional and global exposure
Full onsite work setup
Platform to mentor future risk leaders
Head of Compliance Governance
Head of Compliance Governance

Our Clients • Philippines

On-site
PHP 2,000,000 - 4,000,000
Specialist Controls And Compliance
Specialist Controls And Compliance

Concentrix • Philippines

On-site
PHP 360,000 - 600,000