GRC Lead

MicroSourcing

Manila

On-site

PHP 1,800,000 - 2,400,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Healthcare on day one
Performance bonuses
Paid time-off

Job summary

MicroSourcing invites an experienced GRC Lead to join our Manila-area hybrid team. Based at Eastwood City, Quezon City, this role drives governance, risk, and compliance programs across IT and business functions.

You will partner with Information Security, IT, Internal Audit, and stakeholders to identify risks, strengthen controls, and ensure regulatory readiness. The Lead GRC Associate oversees SOX/SOC programs, maintains documentation, and drives remediation.

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Internal Audit, or related field.
  • 8+ years with CPA required
  • 3+ years in GRC, IT Risk, Information Security Compliance, Technology Risk, or related fields.
  • Experience supporting IT compliance programs, risk assessments, control frameworks, and remediation activities.
  • Familiarity with SOX, SOC, ITGC, ISO 27001, NIST, or similar compliance requirements.

Responsibilities

  • Manage IT governance, risk, and compliance activities across business and technology functions.
  • Perform IT risk assessments to identify risks and remediation needs.
  • Maintain and improve IT policies, standards, procedures, and control documentation.
  • Support SOX, SOC, ISO 27001 and related frameworks.
  • Coordinate with process owners to ensure understanding and implementation of requirements.
  • Monitor control activities and address identified risks and gaps.
  • Assist in audit readiness and evidence collection.

Skills

GRC expertise
IT risk assessment
Regulatory compliance
Stakeholder communication

Education

Bachelor's degree in IT/CS/Accounting
CPA required

Tools

AuditBoard
ServiceNow GRC
Archer
OneTrust
TeamMate+

Job description

Job Description:

Discover your 100% YOU with MicroSourcing!

Position: GRC Lead

Location: Eastwood City, Quezon City

Work setup & shift: Hybrid | Night shift

Why join MicroSourcing?
You'll Have
Competitive Rewards:

Enjoy above-market compensation, healthcare coverage on day one, plus one or more dependents, paid time-off with cash conversion, group life insurance, and performance bonuses

A Collaborative Spirit:

Contribute to a positive and engaging work environment by participating in company-sponsored events and activities.

Work-Life Harmony:

Enjoy the balance between work and life that suits you with flexible work arrangements.

Career Growth:

Take advantage of opportunities for continuous learning and career advancement.

Inclusive Teamwork:

Be part of a team that celebrates diversity and fosters an inclusive culture.

Your Role

The Lead GRC Associate will support the organization's Governance, Risk, and Compliance (GRC) programs by managing IT risk assessments, compliance initiatives, control frameworks, and security governance activities. This role will partner with Information Security, IT, Internal Audit, and business stakeholders to identify technology risks, strengthen internal controls, maintain compliance readiness, and drive remediation efforts.

The Lead GRC Associate will support regulatory and industry compliance requirements, including SOX and SOC programs, by ensuring IT processes and controls are properly documented, monitored, and continuously improved.

Key Responsibilities
  • Manage and support IT governance, risk, and compliance activities across business and technology functions.
  • Perform IT risk assessments to identify potential risks, control gaps, and areas requiring remediation.
  • Maintain and improve IT policies, standards, procedures, and control documentation.
  • Support compliance programs such as SOX, SOC, ISO 27001, and other applicable security and regulatory frameworks.
  • Coordinate with process owners to ensure compliance requirements are understood and effectively implemented.
  • Monitor control activities and collaborate with stakeholders to address identified risks and compliance gaps.
  • Support audit readiness activities by coordinating documentation, evidence collection, and responses with relevant teams.
  • Track remediation activities, risk acceptance, and corrective action plans to ensure timely closure of identified issues.
  • Partner with IT teams during system implementations and process changes to assess governance and compliance requirements.
  • Evaluate technology processes and recommend improvements to strengthen security, operational effectiveness, and compliance posture.
  • Assist in preparing risk reports, compliance dashboards, and management updates.
  • Communicate security risks, compliance requirements, vulnerabilities, and mitigation strategies to technical and business stakeholders.
  • Support continuous improvement initiatives related to IT controls, governance processes, and risk management practices.
Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Internal Audit, or related field.
  • 8+ years with CPA required
  • 3+ years of experience in Governance, Risk, and Compliance (GRC), IT Risk, Information Security Compliance, Technology Risk, or related fields.
  • Experience supporting IT compliance programs, risk assessments, control frameworks, and remediation activities.
  • Familiarity with SOX, SOC, ITGC, ISO 27001, NIST, or similar compliance requirements.
  • Experience working with audit, risk, or compliance management tools (e.g., AuditBoard, ServiceNow GRC, Archer, OneTrust, TeamMate+).
Preferred Qualifications/Nice To Have
  • Strong understanding of IT governance, risk management, and compliance concepts.
  • Knowledge of security frameworks and compliance standards such as SOX, SOC, ISO 27001, NIST, or COBIT.
  • Experience collaborating with internal audit, external audit, security, and technology teams is preferred.
  • Big 4 Technology Risk, IT Audit, or Risk Advisory experience is an advantage.
  • Strong analytical skills with the ability to identify risks and recommend practical solutions.
  • Excellent communication skills with the ability to work with technical and non-technical stakeholders.
  • Strong documentation, organization, and project coordination skills.
  • Ability to manage multiple compliance activities and prioritize deadlines.
  • Detail-oriented with strong problem-solving capabilities.
About MicroSourcing

With over 9,000 professionals across 13 delivery centers, MicroSourcing is the pioneer and largest offshore provider of managed services in the Philippines.

Our commitment to 100% YOU

MicroSourcing firmly believes that our company's strength lies in our people's diversity and talent. We are proud to foster an inclusive culture that embraces individuals of all races, genders, ethnicities, abilities, and backgrounds. We provide space for everyone, embracing different perspectives, and making room for opportunities for each individual to thrive.

At MicroSourcing, equality is not merely a slogan – it's our commitment. Our way of life. Here, we don't just accept your unique authentic self - we celebrate it, valuing every individual's contribution to our collective success and growth. Join us in celebrating YOU and your 100%!

For more information, visit https://www.microsourcing.com/

  • Terms & conditions apply

Requirements:

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead GRC Associate
Lead GRC Associate

MicroSourcing • Philippines

Hybrid
PHP 1,800,000 - 3,000,000
Healthcare day one**
Dependent coverage
Performance bonuses
Risk Analyst
Risk Analyst

MicroSourcing • Philippines

Hybrid
PHP 450,000 - 750,000
Healthcare on day one
PTO with cash conversion
Group life insurance
+3
GRC Lead — IT Risk & Compliance Strategist (Hybrid)
GRC Lead — IT Risk & Compliance Strategist (Hybrid)

MicroSourcing • Manila

Hybrid
PHP 1,800,000 - 2,400,000
Healthcare on day one
Performance bonuses
Paid time-off
Senior Information Security Manager for Information Security Group (ISG)
Senior Information Security Manager for Information Security Group (ISG)

Manatal • Western Visayas

Hybrid
PHP 1,800,000 - 3,000,000
Healthcare coverage on day one
Performance bonuses
Paid time-off with cash conversion
+1
Cyber Security Specialist
Cyber Security Specialist

MicroSourcing International • Philippines

On-site
PHP 700,000 - 1,100,000
Healthcare on Day 1
Dependent coverage
Performance bonus
+2
Risk Analyst
Risk Analyst

Manatal • Philippines

On-site
PHP 600,000 - 900,000
Healthcare coverage on day one
Paid time off with cash conversion
Group life insurance
Remote ICFR Controls Manager | Night Shift
Remote ICFR Controls Manager | Night Shift

MicroSourcing • Philippines

On-site
PHP 1,800,000 - 3,200,000
Healthcare coverage on day one
Dependents coverage
Performance bonuses
+3
IT Service Desk Lead — Remote, Growth & Impact
IT Service Desk Lead — Remote, Growth & Impact

MicroSourcing • Manila

On-site
PHP 420,000 - 720,000
Healthcare coverage on day one (free,
Group life insurance
Paid time off with cash conversion
+3
Senior Information Security Manager for Information Security Group (ISG)
Senior Information Security Manager for Information Security Group (ISG)

MicroSourcing • Manila

Hybrid
PHP 3,000,000 - 5,000,000
Healthcare coverage on day one
Dependent coverage
Paid time-off with cash conversion
+3
Sr. Internal Auditor
Sr. Internal Auditor

MicroSourcing • Manila

On-site
PHP 900,000 - 1,200,000
Healthcare coverage on day one
Paid time-off with cash conversion
Group life insurance
+1