Governance Risk and Compliance I Analyst II

Vertiv Co

Mandaluyong

On-site

PHP 600,000 - 900,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Vertiv Co. is seeking a Governance Risk and Compliance Analyst II to drive risk assessments, security reviews, and policy improvements within IT Security.

You will partner with cross‑functional teams to enhance the organization’s risk posture and audit readiness, while mentoring junior staff and supporting playbooks and SOPs. The role emphasizes coordinating risk mitigation actions, managing third‑party assessments, and producing GRC dashboards for leadership insights, with a focus on ISO 27001

Qualifications

  • Bachelor’s degree in information systems, cybersecurity, or related field.
  • 5+ years of experience in GRC, IT Risk Management, or Information Security.
  • Strong understanding of ITGC, SOX, ISO 27001, NIST CSF, and data privacy regulations (e.g., HIPAA, GDPR).
  • Experience with GRC platforms such as ServiceNow GRC, OneTrust, and SecurityScorecard.
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer or Auditor (preferred).

Responsibilities

  • Lead IT risk assessments, mitigation planning, and control monitoring activities.
  • Oversee risk register updates and coordinate with risk owners and SMEs to track mitigation actions.
  • Drive third‑party risk reviews and assessments using OneTrust and SecurityScorecard, escalating high‑risk vendors for action.
  • Conduct contract reviews focused on information security terms and recommend necessary revisions.
  • Respond to customer security questionnaires with input from SMEs using Loopio.
  • Supervise compliance training rollouts (e.g., phishing campaigns, annual security awareness training).
  • Review and recommend changes to IT security policies and standards aligned with ISO 27001, NIST CSF, and other frameworks.
  • Generate and present GRC dashboards and KPIs to leadership to inform risk posture and team performance.
  • Act as an escalation point for GRC process inquiries and ticket‑related exceptions.
  • Mentor junior analysts and support GRC program maturity through playbooks, SOPs, and process documentation.

Skills

Stakeholder management
Documentation
Analytical skills
Communication
Mentoring

Education

Bachelor’s degree in information systems or cybersecurity

Tools

ServiceNow GRC
OneTrust
SecurityScorecard
Loopio

Job description

Job Title: Governance Risk and Compliance Analyst II

Division: Governance, Risk & Compliance – IT Security

Position Summary

The GRC Analyst will act as a key contributor to Vertiv’s Governance, Risk, and Compliance initiatives, driving risk assessments, security reviews, audit readiness, and third‑party risk management efforts. This role supports continuous improvement of the risk register and policy exception processes, partners with cross‑functional stakeholders, and helps develop a scalable security and compliance posture across the organization.

Key Responsibilities
  • Lead IT risk assessments, mitigation planning, and control monitoring activities.
  • Oversee risk register updates and coordinate with risk owners and SMEs to track mitigation actions.
  • Drive third‑party risk reviews and assessments using OneTrust and SecurityScorecard, escalating high‑risk vendors for action.
  • Conduct contract reviews focused on information security terms and recommend necessary revisions.
  • Respond to customer security questionnaires with input from SMEs using Loopio.
  • Supervise compliance training rollouts (e.g., phishing campaigns, annual security awareness training).
  • Review and recommend changes to IT security policies and standards aligned with ISO 27001, NIST CSF, and other frameworks.
  • Generate and present GRC dashboards and KPIs to leadership to inform risk posture and team performance.
  • Act as an escalation point for GRC process inquiries and ticket‑related exceptions.
  • Mentor junior analysts and support GRC program maturity through playbooks, SOPs, and process documentation.
Qualifications
  • Bachelor’s degree in information systems, Cybersecurity, or a related field.
  • 5+ years of experience in GRC, IT Risk Management, or Information Security.
  • Strong understanding of ITGC, SOX, ISO 27001, NIST CSF, and data privacy regulations (e.g., HIPAA, GDPR).
  • Experience with GRC platforms such as ServiceNow GRC, OneTrust, and SecurityScorecard.
  • Strong documentation and analytical skills with experience preparing audit‑ready evidence.
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer or Auditor (preferred).
  • Excellent communication and stakeholder management skills across global teams.
  • Strong organizational skills and ability to manage multiple deliverables independently.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance Risk And Compliance I Analyst II
Governance Risk And Compliance I Analyst II

Vertiv • Mandaluyong

On-site
PHP 900,000 - 1,300,000
Senior GRC Analyst: IT Risk, Compliance & Security
Senior GRC Analyst: IT Risk, Compliance & Security

Vertiv Co • Mandaluyong

On-site
PHP 600,000 - 900,000
GRC Analyst II: Elevate IT Risk & Compliance
GRC Analyst II: Elevate IT Risk & Compliance

Vertiv • Mandaluyong

On-site
PHP 900,000 - 1,300,000
Sr. Specialist, GRC
Sr. Specialist, GRC

LaVie Resort and Casino Manila • Manila

On-site
PHP 550,000 - 900,000
Information Technology Governance Analyst
Information Technology Governance Analyst

RBox International Solutions Inc. • Philippines

On-site
PHP 600,000 - 900,000
Senior GRC Analyst New India
Senior GRC Analyst New India

Litmos Limited • Hinoba-an

On-site
PHP 600,000 - 1,200,000
Senior Specialist, GRC
Senior Specialist, GRC

LaVie • Manila

On-site
PHP 1,200,000 - 1,800,000
IT Governance, Risk & Compliance (GRC) Analyst
IT Governance, Risk & Compliance (GRC) Analyst

Satellite Office • Taguig

On-site
PHP 420,000 - 660,000
Cyber Security Specialist
Cyber Security Specialist

Sterling Global Call Center, Inc. • Pasig

On-site
PHP 900,000 - 1,300,000
Governance and Information Security Analyst
Governance and Information Security Analyst

InnovaThink Corporation • Metro Manila

On-site
PHP 800,000 - 1,200,000