Governance, Risk, & Compliance Manager

CIBI Information Inc.

Philippines

On-site

PHP 1,339,000 - 2,678,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CIBI Information Inc. in the Philippines seeks a GRC Manager to design and implement integrated governance, risk, and compliance frameworks aligned with CIC, DPA, and ISO/SOC 2 standards.

The role emphasizes audit readiness, incident response, and institutional resilience across functions including IT and Internal Audit. The ideal candidate has 2–3 years in GRC/audit with supervisory experience, a finance/legal/business background, and professional certifications.

Qualifications

  • Bachelor’s degree in Finance, Accounting, Law, Business Administration or related field; Master’s degree preferred.
  • Professional certifications (e.g., CRMs, CCEP, CIA) are highly desirable.

Responsibilities

  • Design, implement, and operationalize governance, risk, and compliance frameworks.
  • Advise on governance best practices; maintain policy repository embedded in workflows.
  • Monitor regulatory adherence including DPA, BSP, AML, CIC; conduct health checks.

Skills

Governance & risk
Regulatory compliance
Internal controls
Leadership
Communication
Audit
Regulatory frameworks

Education

Bachelor’s degree in Finance, Accounting, Law, Business Administration
Master’s degree preferred
Professional certifications desirable

Job description

Be part of CIBI Information Inc., a purpose-driven company at the forefront of enabling better credit decisions in the Philippines and beyond.

ROLE OVERVIEW:

The GRC Manager will be responsible for the design, implementation, and operationalization of CIBI’s integrated governance, risk, and compliance frameworks. This is a high-impact, individual contributor-plus role focused on ensuring that CIBI’s operations remain resilient, audit-ready, and fully aligned with the mandates of the Credit Information Corporation (CIC), the Data Privacy Act (DPA), and international standards (ISO/SOC 2).

DUTIES AND RESPONSIBILITIES:
Governance Framework & Strategy
  • Operationalize the Enterprise Risk Management (ERM) and Governance frameworks to align with CIBI’s mission and vision and strategic objectives;
  • Advisory on best industry practice in governance and regulatory compliance;
  • Draft and maintain the repository of corporate policies, ensuring they are not merely documented but functionally embedded into departmental workflows.
  • Evaluate the effectiveness of internal controls and provide technical recommendations to the Board and Senior Management on daily operations towards promotion of a culture of integrity, accountability and compliance by design.
Enterprise Risk & Internal Controls
  • Assist in the assessment, and prioritization of potential risks, including operational, compliance, financial, reputational, and strategic risks and the creation of risk mitigation plans through deep-dive risk assessments across all business units (Operational, Financial, Reputational, and Strategic).
  • Develop and monitor Key Risk Indicators (KRIs) and control metrics to provide early-warning signals to the Risk Management Committee.
  • Audit and test the efficacy of internal controls, ensuring the safeguarding of CIBI’s data assets and the reliability of reporting.
Regulatory Compliance Management
  • Monitor adherence to all relevant laws pertinent to the operations of CIBI and internal policies, including the Data Privacy Act of 2012, BSP regulations, Anti-Money Laundering (AML) and CIC Circulars, serving as a primary point of contact for regulatory inquiries.
  • Conduct regular compliance "health checks" and gap analyses to ensure the organization maintains its "Advanced Tier" standing.
  • Manage the end-to-back compliance lifecycle, from detection of potential non-compliance to the implementation of remedial actions.
Technical Collaboration (ISO & SOC 2)
  • Serve as the GRC lead in partnership with Internal Audit for ISO 27001 and SOC 2 Type 2 certifications and collaboration in all governance and compliance audit
  • Map GRC requirements against technical security controls, ensuring that governance documentation matches technical implementation.
  • Work with Lead Internal Auditor in remediating findings from ISO/SOC 2 audits by redesigning processes to meet international security and availability standards.
Incident Response & Institutional Resilience
  • Lead the GRC component of the Incident Response Plan, ensuring that compliance breaches are detected, reported, and mitigated within statutory timelines.
  • Design Business Continuity and Crisis Management protocols focused on maintaining the integrity of CIBI’s credit database during unforeseen events.
  • Coordinate with other departments, including Internal Audit and IT, for incident investigations and risk assessments.
Reporting, Documentation & Training
  • Document and maintain a centralized repository for all GRC policies, procedures, risk registers, and compliance reports.
  • Ensure all GRC documentation aligns with regulatory and organizational standards, facilitating easy access for audits and regulatory reviews.
  • Assist in the development and delivery of GRC training programs on compliance, risks and governance policies and the creation of awareness initiatives to promote ethical and compliance by design practices.
  • Maintain up-to-date training materials that reflect regulatory changes and align with CIBI’s policies and procedures.
JOB SPECIFICATIONS
Educational Background
  • Bachelor’s degree in Finance, Accounting, Law, Business Administration, or a related field. Master’s degree or equivalent preferred.
  • Professional certifications (e.g., Certified Risk Manager, Certified Compliance Professional, or Certified Internal Auditor) are highly desirable.
Experience
  • 2-3 years of experience in governance, risk, compliance, or audit functions, with at least 1 year in a supervisorial or managerial role, preferably in financial services, banking, or credit bureau, audit compliance industries.
  • Strong knowledge of relevant regulatory frameworks, particularly BSP and CIC regulations, Anti-Money Laundering (AML) laws, data privacy laws (e.g., Data Privacy Act of the Philippines).
  • Deep understanding of governance, risk management, and compliance frameworks.
  • Proven leadership and team management skills, with the ability to foster a collaborative and ethical work environment.
  • Excellent analytical and problem-solving abilities, with a strategic mindset and attention to detail.
  • Effective communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels.
  • Strong organizational and project management skills, with the ability to prioritize and manage multiple tasks.
  • High ethical standards and integrity, with a commitment to upholding the company’s values and promoting a compliance-oriented culture.
  • Ability to handle sensitive and confidential information with discretion.
  • Proactive, resourceful, and self-motivated with a results-oriented approach.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Manager: Risk, Compliance & Controls Leader
GRC Manager: Risk, Compliance & Controls Leader

CIBI Information Inc. • Philippines

On-site
PHP 1,339,000 - 2,678,000
Project Management Lead
Project Management Lead

CIBI Information Inc. • Philippines

On-site
PHP 1,200,000 - 2,400,000
Senior Governance Risk and Compliance Analyst
Senior Governance Risk and Compliance Analyst

Permhunt • Metro Manila

On-site
Competitive salary
Benefit package
On-call support
General Manager - Risk & Compliance
General Manager - Risk & Compliance

Atain • Metro Manila

On-site
PHP 1,500,000 - 2,100,000
Relationship Manager (multiple openings)
Relationship Manager (multiple openings)

CIBI Information Inc. • Philippines

On-site
PHP 600,000 - 900,000
IT Governance and Compliance Officer
IT Governance and Compliance Officer

PJ Lhuillier Group of Companies • Philippines

On-site
PHP 600,000 - 1,200,000
Head of Compliance Governance
Head of Compliance Governance

Our Clients • Philippines

On-site
PHP 2,000,000 - 4,000,000
Head of Compliance Governance
Head of Compliance Governance

Create Synergies Inc. • Philippines

On-site
PHP 1,500,000 - 2,100,000
Head of Compliance Governance
Head of Compliance Governance

PM Consulting • Philippines

On-site
PHP 4,000,000 - 6,000,000
General Manager Risk & Compliance
General Manager Risk & Compliance

Atain • Manila

On-site
PHP 3,000,000 - 5,000,000