General Manager - Risk & Compliance

Atain

Metro Manila

On-site

PHP 1,500,000 - 2,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Atain is seeking a senior risk and compliance leader to drive the organization’s framework across the Philippines and South Africa. You will steer enterprise risk management, internal controls, and governance while coordinating with leadership and auditors to ensure robust control effectiveness.

You will serve as Data Protection Officer for the Philippines location, manage DPIAs, and drive certifications (ISO 27001/9001) and regulatory readiness.

Qualifications

  • 15+ years of progressive experience in Risk Management, Compliance, Internal Controls, Corporate Governance, or Business Excellence.
  • Experience leading Enterprise Risk Management programs and governance reporting.
  • Strong background in regulatory compliance frameworks, audits, and vendor monitoring.
  • Exposure to data privacy, DPIA processes, and GDPR-aligned practices.
  • Cross-functional leadership and senior stakeholder engagement.

Responsibilities

  • Oversee identification, assessment, and treatment of strategic, operational, financial, information security, and third‑party risks.
  • Maintain process risk register, KRIs, and risk appetite frameworks.
  • Provide insights and risk heatmaps to leadership and stakeholder forums.
  • Lead ISO 27001 & ISO 9001 compliance efforts and ISMS governance.
  • Oversee audits (internal, external, regulatory) and evidence collection.
  • Act as Data Protection Officer for the Philippines location; DPIA coordination.
  • Drive third‑party risk management, vendor reviews, and contractual compliance.
  • Develop dashboards and analytics for risk, compliance, and certifications.
  • Deliver training on ethics, privacy, cyber hygiene, and compliance.
  • Promote transparent reporting and a speak‑up culture.

Skills

Strategic leadership
Risk management
Governance
Stakeholder engagement
Data privacy
Audits & controls

Education

Bachelor’s degree
Master’s degree preferred

Tools

GRC tools

Job description

Serve as a key leader in driving, shaping, and governing the organization’s Risk and Compliance framework, ensuring alignment with contractual requirements, internal controls, risk assessment and enterprise‑wide strategic objectives. Provide strategic oversight and direction to core Risk & Compliance initiatives, acting as an anchor member of the organization’s governance structure. Selected candidate will be leading Philippines and South Africa clusters.

ORGANISATIONALCHART
PRINCIPLE ACCOUNTABILITIES
EXPECTED END RESULTS
MAJOR ACTIVITIES
  • Oversee identification, assessment, and treatment of strategic, operational, financial, Information security, and third‑party risks.
  • Maintain process risk register, KRIs, and risk appetite frameworks.
  • Provide insights and risk heatmaps to leadership and stakeholder forums.

Security Certifications & Compliance Standards (ISO 27001, ISO 9001, PCI DSS, SOC 1 & 2, HIPAA)

  • Lead, maintain, and enhance compliance with ISO 27001 & ISO 9001, and other global security frameworks like PCI DSS, SOC -1, SOC – 2 etc.
  • Oversee ISMS governance, process risk assessments, internal audits, surveillance audits, and certification cycles.
  • Ensure secure handling, processing, and storage of sensitive data in line with applicable standards.
  • Collaborate with internal stakeholders and external auditors to ensure control effectiveness.
  • Maintain evidence repositories, Statement of Applicability (SoA), risk treatment plans (RTP), and continuous improvement logs.
  • Drive annual certification, recertification, and readiness assessments.
  • Ensure closure of non‑conformities and alignment with regulatory and industry requirements.

Internal Controls & Assurance Specific to NPC (National Privacy Commission, Philippines)

  • Strengthen the organisation’s internal control environment on NPC guidelines.
  • Employee will act as a Data Protection Officer for Philippines location.
  • Conduct process‑level DPIA’s, control testing, and remediation tracking.
  • Ensure readiness for internal, external, and regulatory audits.

Audit Governance (Internal, External & Regulatory)

  • Coordinate internal audits, external audits, and compliance audits.
  • Manage end‑to‑end audit lifecycle: planning, fieldwork, evidence, closure, CAPA validation.
  • Prepare consolidated audit reports for leadership review.

Incident, Breach & Root Cause Management

  • Lead investiagtion for incident/breach management including detection, escalation, containment, and RCA.
  • Provide timely and transparent reporting to leadership.

Third‑Party (Client & Vendor Risk Management)

  • Lead end to end client audits & maintain contractual compliance
  • Implement and maintain third‑party due diligence, vendor reviews, and ongoing monitoring.
  • Ensure all high‑risk vendors are assessed for security, compliance, and contractual controls.
  • Oversee remediation and compliance certification requirements for vendors.

Data Privacy

  • Drive privacy compliance with laws and frameworks (e.g., GDPR principles).
  • Ensure coverage of DFD, ROPA & DPIA’s vis‑à‑vis GDPR
  • Lead data lifecycle governance, retention controls, and breach response readiness.

Reporting, Analytics & GRC Tool Enablement

  • Build and own dashboards for risk, compliance, security certification status, KRIs, audits, and incidents.
  • Ensure high data quality, automation, and real‑time governance.
  • Optimize GRC tools for reporting, workflow automation, and maturity uplift.
  • Build organizational competency in risk and compliance.
  • Deliver training programs in ethics, privacy, cyber hygiene, security standards, and compliance.
  • Promote speak‑up, transparent reporting, and non‑retaliation culture.
SKILLS AND KNOWLEDGE
EDUCATIONAL QUALIFICATIONS
  • Bachelor’s degree in business administration, Commerce, Law, Information Security, Computer Science, or a related discipline.
  • Master’s Degree (Preferred) in Business Administration (MBA), Risk Management, Corporate Governance, Information Security, or related fields.
Professional Certifications
  • ISO 27001 & ISO 9001 Lead Auditor / Lead Implementer – Must Have
  • CISA (Certified Information Systems Auditor)
  • PCI DSS Implementation
  • SOC 1 & SOC 2 compliance training
  • HIPAA Compliance Training / Certified HIPAA Professional (CHP)

Additional training in ERM Frameworks, GRC Tools, and Cybersecurity Governance is an advantage.

RELEVANT EXPERIENCE

  • 15+ years of progressive experience in Risk Management, Compliance, Internal Controls, Corporate Governance, or Business Excellence within mid‑to‑large‑scale organizations.
  • Demonstrated experience in leading Enterprise Risk Management (ERM) programs, including risk identification, assessment, treatment planning, KRI development, and governance reporting.
  • Proven expertise in managing regulatory compliance frameworks, statutory obligations, internal/external audits, and regulatory inspections.
  • Hands‑on experience implementing and maintaining security and compliance certifications, including:
    - ISO 27001 (ISMS implementation, audit readiness, SoA, RTP, recertification cycles) PCI DSS compliance (assessment support, evidence readiness, ASV scans, hardening) SOC 1 & SOC 2 Type I/II (control mapping, walkthroughs, evidence coordination) HIPAA compliance for PHI environments (privacy/security safeguards, breach readiness) Strong background in designing and strengthening internal control frameworks, conducting control testing, and resolving audit findings with a focus on eliminating repeat issues.
  • Prior responsibility for third‑party risk management, vendor assessments, contract compliance, and continuous monitoring of high‑risk suppliers.
  • Exposure to data privacy, including DPIA, data lifecycle controls, consent management, and privacy compliance (e.g., NPC Act, GDPR‑aligned practices).
  • Experience working closely with Information Security, including vulnerability management, security hardening, access reviews, and cyber awareness initiatives.
  • Demonstrated leadership in policy creation, risk governance, process standardization, and continuous improvement initiatives aligned with Business Excellence.
  • Experience managing cross‑functional teams, senior stakeholder engagement, and presenting insights to leadership, Board, and Audit Committees.
BEHAVIORAL COMPETENCIES -
  • Strategic Mindset: Anticipates risks, connects insights to business strategy, and makes informed decisions.
  • Leadership & Collaboration: Leads cross‑functional teams effectively and builds strong stakeholder relationships.
  • Integrity & Ethical Conduct: Demonstrates sound judgement, transparency, and promotes a culture of compliance.
  • Analytical Thinking: Solves complex problems using structured, data‑driven approaches.
  • Executive Communication: Communicates clearly, simplifies complex issues, and presents confidently to senior leadership.
  • Change Agility: Adapts quickly to evolving regulations, risks, and organizational priorities.
  • Attention to Detail: Ensures accuracy and rigor in documentation, controls, and reporting.
  • Continuous Improvement Orientation: Drives efficiency, automation, and process excellence using structured methodologies.
  • Accountability & Ownership: Takes responsibility for outcomes and ensures timely closure of actions.
  • Risk & Control Mindset: Promotes early identification, escalation, and mitigation of risks across the organization.

It is our policy to provide equal employment opportunities to all individuals based on job‑related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, colour, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non‑discriminatory environment free from intimidation, harassment or bias based upon these grounds

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

General Manager Risk & Compliance
General Manager Risk & Compliance

Atain • Manila

On-site
PHP 3,000,000 - 5,000,000
Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)
Senior Manager – InfoSec Risk and Compliance (Clark/ Onsite)

Sutherland • Mabalacat

On-site
PHP 1,500,000 - 2,300,000
IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

Compass Experience Labs LLC • Manila

Hybrid
PHP 1,800,000 - 3,200,000
IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

compassexperiencelabs • Manila

Hybrid
PHP 1,200,000 - 1,600,000
Senior Governance Risk and Compliance Analyst
Senior Governance Risk and Compliance Analyst

Permhunt • Metro Manila

On-site
Competitive salary
Benefit package
On-call support
IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

Compass Experience Labs • Manila

Hybrid
PHP 1,800,000 - 3,200,000
Head of Compliance Governance
Head of Compliance Governance

Our Clients • Philippines

On-site
PHP 2,000,000 - 4,000,000
Data Privacy Officer (Midshift, Onsite)
Data Privacy Officer (Midshift, Onsite)

blaseek • Pasig

On-site
Specialist Controls And Compliance
Specialist Controls And Compliance

Concentrix • Philippines

On-site
PHP 360,000 - 600,000
Head of Compliance Governance
Head of Compliance Governance

Create Synergies Inc. • Philippines

On-site
PHP 1,500,000 - 2,100,000