Governance Risk And Compliance I Analyst II

Vertiv

Mandaluyong

On-site

PHP 900,000 - 1,300,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Vertiv in the Philippines is seeking a Governance, Risk and Compliance Analyst II to strengthen IT security program maturity across the enterprise. The role focuses on risk assessments, policy controls, and third-party risk management.

You will collaborate with global teams, drive risk mitigation actions, and prepare audit-ready evidence using tools like OneTrust and ServiceNow GRC. A 5+ year background in GRC or information security is expected.

Qualifications

  • Bachelor's degree in information systems or cybersecurity and related field.
  • 5+ years in GRC, IT risk, or information security.
  • Experience with GRC platforms and audit-ready evidence.

Responsibilities

  • Lead IT risk assessments, mitigation planning, and control monitoring.
  • Oversee risk register updates and coordinate with risk owners.
  • Drive third-party risk reviews using OneTrust and SecurityScorecard.
  • Conduct contract reviews for information security terms.
  • Respond to customer security questionnaires with SMEs input.
  • Supervise compliance training rollouts (phishing campaigns, awareness).
  • Review IT security policies aligned with ISO 27001 and NIST CSF.
  • Generate GRC dashboards and KPIs for leadership.
  • Escalate GRC inquiries and manage exceptions.
  • Mentor junior analysts and develop SOPs.

Skills

GRC experience
IT risk management
Audit readiness
Stakeholder management
Documentation

Education

Bachelor’s degree in Information Systems / Cybersecurity

Tools

ServiceNow GRC
OneTrust
SecurityScorecard

Job description

Job Description:

Job Title: Governance Risk and Compliance Analyst II

Division: Governance, Risk & Compliance – IT Security

Position Summary

The GRC Analyst will act as a key contributor to Vertiv’s Governance, Risk, and Compliance initiatives, driving risk assessments, security reviews, audit readiness, and third-party risk management efforts. This role supports continuous improvement of the risk register and policy exception processes, partners with cross-functional stakeholders, and helps develop a scalable security and compliance posture across the organization.

Key Responsibilities
  • Lead IT risk assessments, mitigation planning, and control monitoring activities.
  • Oversee risk register updates and coordinate with risk owners and SMEs to track mitigation actions.
  • Drive third-party risk reviews and assessments using OneTrust and SecurityScorecard, escalating high-risk vendors for action.
  • Conduct contract reviews focused on information security terms and recommend necessary revisions.
  • Respond to customer security questionnaires with input from SMEs using Loopio.
  • Supervise compliance training rollouts (e.g., phishing campaigns, annual security awareness training).
  • Review and recommend changes to IT security policies and standards aligned with ISO 27001, NIST CSF, and other frameworks.
  • Generate and present GRC dashboards and KPIs to leadership to inform risk posture and team performance.
  • Act as an escalation point for GRC process inquiries and ticket-related exceptions.
  • Mentor junior analysts and support GRC program maturity through playbooks, SOPs, and process documentation.
Qualifications
  • Bachelor’s degree in information systems, Cybersecurity, or a related field.
  • 5+ years of experience in GRC, IT Risk Management, or Information Security.
  • Strong understanding of ITGC, SOX, ISO 27001, NIST CSF, and data privacy regulations (e.g., HIPAA, GDPR).
  • Experience with GRC platforms such as ServiceNow GRC, OneTrust, and SecurityScorecard.
  • Strong documentation and analytical skills with experience preparing audit-ready evidence.
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer or Auditor (preferred).
  • Excellent communication and stakeholder management skills across global teams.
  • Strong organizational skills and ability to manage multiple deliverables independently.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Governance Risk and Compliance I Analyst II
Governance Risk and Compliance I Analyst II

Vertiv Co • Mandaluyong

On-site
PHP 600,000 - 900,000
Governance Risk and Compliance I Analyst II
Governance Risk and Compliance I Analyst II

Vertiv Group Corporation • Mandaluyong

On-site
PHP 700,000 - 1,100,000
Senior GRC Analyst: IT Risk, Compliance & Security
Senior GRC Analyst: IT Risk, Compliance & Security

Vertiv Co • Mandaluyong

On-site
PHP 600,000 - 900,000
Senior GRC Analyst - IT Security and Compliance
Senior GRC Analyst - IT Security and Compliance

Vertiv Group Corporation • Mandaluyong

On-site
PHP 700,000 - 1,100,000
Senior Specialist, GRC
Senior Specialist, GRC

LaVie • Manila

On-site
PHP 1,200,000 - 1,800,000
GRC Analyst II: Elevate IT Risk & Compliance
GRC Analyst II: Elevate IT Risk & Compliance

Vertiv • Mandaluyong

On-site
PHP 900,000 - 1,300,000
Governance and Information Security Analyst
Governance and Information Security Analyst

InnovaThink Corporation • Metro Manila

On-site
PHP 800,000 - 1,200,000
Sr. Specialist, GRC
Sr. Specialist, GRC

LaVie Resort and Casino Manila • Manila

On-site
PHP 550,000 - 900,000
Cyber Security Specialist
Cyber Security Specialist

Sterling Global Call Center, Inc. • Pasig

On-site
PHP 900,000 - 1,300,000
Information Technology Governance Analyst
Information Technology Governance Analyst

RBox International Solutions Inc. • Philippines

On-site
PHP 600,000 - 900,000