Governance Risk and Compliance I Analyst II

Vertiv Group Corporation

Mandaluyong

On-site

PHP 700,000 - 1,100,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Vertiv is seeking a Governance, Risk, and Compliance Analyst II in the Philippines to drive risk assessments, security reviews, and compliance initiatives across IT security. You will coordinate risk ownership, monitor mitigations, and support audit readiness while collaborating with cross-functional teams.

The role requires a strong background in GRC, IT risk management, and information security, with experience using leading GRC platforms.

Qualifications

  • Bachelor's degree in information systems, cybersecurity, or related field.
  • 5+ years of experience in GRC, IT risk management, or information security.
  • Knowledge of ITGC, SOX, ISO 27001, NIST CSF, and data privacy regs (HIPAA, GDPR).

Responsibilities

  • Lead IT risk assessments and mitigation planning.
  • Oversee risk register updates and coordinate with risk owners.
  • Drive third-party risk reviews and assessments using OneTrust and SecurityScorecard.
  • Conduct contract reviews focused on information security terms.
  • Respond to customer security questionnaires with input from SMEs using Loopio.
  • Supervise compliance training rollouts (e.g., phishing campaigns, security awareness).
  • Review and update IT security policies and standards aligned with ISO 27001 and NIST CSF.
  • Generate and present GRC dashboards and KPIs to leadership.
  • Act as escalation point for GRC inquiries and exceptions.
  • Mentor junior analysts and develop SOPs and playbooks.

Skills

GRC experience
IT risk management
Info security
Audit readiness

Education

Bachelor's degree in information systems or cybersecurity

Tools

ServiceNow GRC
OneTrust
SecurityScorecard
Loopio

Job description

Job Title: Governance Risk and Compliance Analyst II

Division: Governance, Risk & Compliance - IT Security

Position Summary

The GRC Analyst will act as a key contributor to Vertivs Governance, Risk, and Compliance initiatives, driving risk assessments, security reviews, audit readiness, and third-party risk management efforts. This role supports continuous improvement of the risk register and policy exception processes, partners with cross-functional stakeholders, and helps develop a scalable security and compliance posture across the organization.

Key Responsibilities
  • Lead IT risk assessments, mitigation planning, and control monitoring activities.
  • Oversee risk register updates and coordinate with risk owners and SMEs to track mitigation actions.
  • Drive third-party risk reviews and assessments using OneTrust and SecurityScorecard, escalating high-risk vendors for action.
  • Conduct contract reviews focused on information security terms and recommend necessary revisions.
  • Respond to customer security questionnaires with input from SMEs using Loopio.
  • Supervise compliance training rollouts (e.g., phishing campaigns, annual security awareness training).
  • Review and recommend changes to IT security policies and standards aligned with ISO 27001, NIST CSF, and other frameworks.
  • Generate and present GRC dashboards and KPIs to leadership to inform risk posture and team performance.
  • Act as an escalation point for GRC process inquiries and ticket-related exceptions.
  • Mentor junior analysts and support GRC program maturity through playbooks, SOPs, and process documentation.
Qualifications
  • Bachelor's degree in information systems, Cybersecurity, or a related field.
  • 5+ years of experience in GRC, IT Risk Management, or Information Security.
  • Strong understanding of ITGC, SOX, ISO 27001, NIST CSF, and data privacy regulations (e.g., HIPAA, GDPR).
  • Experience with GRC platforms such as ServiceNow GRC, OneTrust, and SecurityScorecard.
  • Strong documentation and analytical skills with experience preparing audit-ready evidence.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Governance Risk and Compliance I Analyst II
Governance Risk and Compliance I Analyst II

Vertiv Co • Mandaluyong

On-site
PHP 600,000 - 900,000
Governance Risk And Compliance I Analyst II
Governance Risk And Compliance I Analyst II

Vertiv • Mandaluyong

On-site
PHP 900,000 - 1,300,000
Senior GRC Analyst: IT Risk, Compliance & Security
Senior GRC Analyst: IT Risk, Compliance & Security

Vertiv Co • Mandaluyong

On-site
PHP 600,000 - 900,000
Senior GRC Analyst - IT Security and Compliance
Senior GRC Analyst - IT Security and Compliance

Vertiv Group Corporation • Mandaluyong

On-site
PHP 700,000 - 1,100,000
Sr. Specialist, GRC
Sr. Specialist, GRC

LaVie Resort and Casino Manila • Manila

On-site
PHP 550,000 - 900,000
GRC Analyst II: Elevate IT Risk & Compliance
GRC Analyst II: Elevate IT Risk & Compliance

Vertiv • Mandaluyong

On-site
PHP 900,000 - 1,300,000
Senior Specialist, GRC
Senior Specialist, GRC

LaVie • Manila

On-site
PHP 1,200,000 - 1,800,000
Information Technology Governance Analyst
Information Technology Governance Analyst

RBox International Solutions Inc. • Philippines

On-site
PHP 600,000 - 900,000
Cyber Security Specialist
Cyber Security Specialist

Sterling Global Call Center, Inc. • Pasig

On-site
PHP 900,000 - 1,300,000
IT Governance, Risk & Compliance (GRC) Analyst
IT Governance, Risk & Compliance (GRC) Analyst

Satellite Office • Taguig

On-site
PHP 420,000 - 660,000