IT Governance, Risk and Compliance Manager

OwnBank

Taguig

On-site

PHP 1,800,000 - 2,600,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

OwnBank is seeking an IT Governance Manager / Head of IT Governance, Risk & Compliance to establish, implement, and maintain the Bank’s IT governance, technology risk management, compliance, IT controls, business continuity, disaster recovery, and outsourcing risk framework.

The role ensures that IT operations, systems, projects, vendors, policies, and controls are aligned with regulatory requirements, internal policies, business objectives, and the Bank’s risk appetite.

Qualifications

  • Bachelor’s degree in IT, CS, IS, Engineering or related field required.
  • Master’s degree or postgraduate qualification is an advantage.
  • Experience in banking, fintech, or regulated industries preferred.

Responsibilities

  • Establish, implement and maintain IT governance framework.
  • Manage technology risk, compliance, and IT controls.
  • Lead business continuity and disaster recovery efforts.
  • Oversee third-party outsourcing risk and vendor management.
  • Prepare regulatory reporting and management dashboards.

Skills

IT governance
Risk management
Regulatory compliance
Vendor management

Education

Bachelor’s degree in IT / Information Systems
Master’s degree (advantage)

Tools

GRC software

Job description

The IT Governance Manager / Head of IT Governance, Risk & Compliance is responsible for establishing, implementing, and maintaining the Bank’s IT governance, technology risk management, compliance, IT controls, business continuity, disaster recovery, and third-party outsourcing risk management framework.

The role ensures that IT operations, systems, projects, vendors, policies, and controls are aligned with regulatory requirements, internal policies, business objectives, and the Bank’s risk appetite. The position also provides oversight on IT resilience, regulatory compliance, audit readiness, and Board and Management reporting.

Key Responsibilities
  1. IT Governance Framework

  • Develop, implement, and maintain the Bank’s IT Governance Framework.

  • Ensure IT governance policies, standards, and procedures are aligned with business objectives and regulatory expectations.

  • Support IT Steering Committee, Risk Committee, and Management reporting requirements.

  • Monitor IT governance action items, decisions, and commitments.

  • Promote clear accountability, ownership, and segregation of duties across IT functions.

  • Ensure governance practices are embedded in IT operations, projects, systems, and vendor management.

  1. Technology Risk & Compliance Management

  • Establish and maintain the IT Risk Management Framework.

  • Conduct regular technology risk assessments covering IT systems, infrastructure, applications, cloud services, and critical projects.

  • Maintain the IT Risk Register, including identified risks, risk owners, mitigation plans, target dates, and residual risk ratings.

  • Monitor compliance with BSP regulations, internal policies, cybersecurity requirements, and applicable industry standards.

  • Track and escalation high-risk issues, breaches, exceptions, and overdue remediation items.

  • Ensure timely closure of audit, compliance, and regulatory findings.

  1. Policy & Standard Management

  • Own and manage the lifecycle of IT policies, standards, procedures, and governance documents.

  • Ensure IT policies are reviewed, updated, approved, communicated, and implemented on schedule.

  • Maintain version control, approval records, and evidence of policy dissemination.

  • Coordinate with IT, Risk, Compliance, Audit, and business units to ensure policy alignment.

  • Conduct policy awareness sessions and monitor completion of required training.

  1. IT Controls & Assurance

  • Monitor and assess the effectiveness of IT general controls and technology risk controls.

  • Support internal audits, external audits, regulatory examinations, and control reviews.

  • Coordinate IT control self-assessments and compliance testing.

  • Track audit observations, management action plans, and remediation status.

  • Ensure control gaps are properly documented, risk-rated, assigned to owners, and resolved within agreed timelines.

  • Provide independent challenge on IT control weaknesses and risk acceptance decisions.

  1. Business Continuity & Disaster Recovery

  • Oversee IT disaster recovery governance and ensure alignment with the Bank’s Business Continuity Management requirements.

  • Ensure all critical systems have documented Recovery Time Objectives, Recovery Point Objectives, recovery procedures, escalation paths, and dependency mapping.

  • Coordinate with IT Operations, business units, Risk, and Compliance in developing and maintaining disaster recovery plans.

  • Ensure annual disaster recovery testing and tabletop exercises are conducted, documented, and reported.

  • Review disaster recovery test results, identify gaps, and track corrective actions to closure.

  • Ensure backup, restoration, system failover, and recovery capabilities are periodically validated.

  • Report IT resilience status, DR readiness, and unresolved recovery risks to Management and relevant governance committees.

  1. Third-Party & Outsourcing Risk Management

  • Establish and maintain governance over IT third-party and outsourced service providers.

  • Conduct or coordinate vendor risk assessments, due diligence reviews, and periodic performance evaluations.

  • Ensure critical IT vendors are covered by appropriate contracts, service level agreements, information security requirements, data privacy provisions, business continuity requirements, and exit arrangements.

  • Monitor vendor compliance with agreed SLAs, regulatory expectations, and contractual obligations.

  • Track vendor-related incidents, SLA breaches, control issues, and remediation plans.

  • Coordinate with Procurement, Legal, Compliance, Risk, and IT teams on vendor onboarding, contract renewal, and outsourcing risk reviews.

  • Ensure outsourced IT services remain subject to adequate oversight, monitoring, and governance by the Bank.

  1. Regulatory Reporting, Management Reporting & Oversight

  • Prepare regular IT governance, risk, compliance, audit, resilience, and vendor oversight reports for Management and Board-level committees.

  • Maintain governance dashboards covering IT risks, audit findings, policy compliance, DR readiness, vendor risks, and key risk indicators.

  • Ensure reports are accurate, timely, and supported by proper evidence.

  • Escalate critical technology risks, control gaps, compliance breaches, and unresolved vendor issues.

  • Support regulatory examinations and ensure timely submission of required evidence and management responses.

  1. Leadership & Stakeholder Management

  • Lead and develop the IT Governance, Risk & Compliance function.

  • Coordinate closely with IT Operations, IT Engineering, Product Management, Cybersecurity, Risk, Compliance, Internal Audit, Legal, Procurement, and business units.

  • Promote a strong culture of governance, accountability, risk awareness, compliance, and continuous improvement.

  • Provide guidance to IT teams on policy interpretation, control requirements, risk assessments, and regulatory expectations.

  • Support training and awareness initiatives related to IT governance, cybersecurity, business continuity, disaster recovery, and vendor risk management.

Qualifications
Education
  • Bachelor’s degree in Information Technology, Computer Science, Information Systems, Engineering, Risk Management, or related field.

  • Master’s degree or postgraduate qualification is an advantage.

Experience
  • At least 8 to 10 years of experience in IT governance, IT risk management, information security, technology audit, compliance, business continuity, disaster recovery, or third-party risk management.

  • At least 3 to 5 years in a managerial or leadership role.

  • Experience in banking, digital banking, fintech, financial services, or regulated industries is highly preferred.

  • Strong working knowledge of BSP IT risk management expectations, outsourcing governance, cybersecurity, business continuity, and disaster recovery practices.

Preferred Certifications
  • Certified Information Systems Auditor

  • Certified Information Security Manager

  • Certified in Risk and Information Systems Control

  • Certified Information Systems Security Professional

  • COBIT Foundation

  • ISO/IEC 27001 Lead Implementer or Lead Auditor

  • ISO 22301 Business Continuity Management certification

  • Project Management Professional or equivalent certification

Technical Competencies
  • IT Governance Frameworks

  • Technology Risk Management

  • Regulatory Compliance

  • IT Controls and Assurance

  • IT Policy and Standards Management

  • Business Continuity Management

  • Disaster Recovery Governance

  • Third-Party and Outsourcing Risk Management

  • Vendor Risk Assessment and SLA Monitoring

  • IT Audit and Regulatory Examination Management

  • Cybersecurity Governance

  • Risk Reporting and Dashboarding

  • Control Testing and Remediation Tracking

Behavioral Competencies
  • Strong leadership and accountability

  • Risk-based decision-making

  • Analytical and critical thinking

  • Strong communication and reporting skills

  • Stakeholder management

  • Integrity and professional judgment

  • Attention to detail

  • Ability to challenge constructively

  • Collaboration across IT, Risk, Compliance, Audit, and business teams

  • Continuous improvement mindset

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Governance and Compliance Specialist
IT Governance and Compliance Specialist

Palawan Group of Companies • Mandaluyong

On-site
PHP 600,000 - 1,000,000
IT Governance and Compliance Officer
IT Governance and Compliance Officer

PJ Lhuillier Group of Companies • Makati

On-site
PHP 700,000 - 1,100,000
IT Operations & Infrastructure Manager
IT Operations & Infrastructure Manager

HRTX • Makati

On-site
PHP 1,800,000 - 3,000,000
Senior Digital Risk Consultant
Senior Digital Risk Consultant

Jobtailor • Taguig

On-site
PHP 670,000 - 1,339,000
IT Governance and Compliance Officer
IT Governance and Compliance Officer

PJ Lhuillier Group of Companies • Philippines

On-site
PHP 600,000 - 1,200,000
IT Governance Manager
IT Governance Manager

MEGA PRIME FOODS INCORPORATED • Quezon City

On-site
PHP 1,200,000 - 2,000,000
Cybersecurity Compliance Head
Cybersecurity Compliance Head

Smart Communications, Inc. • Makati

On-site
PHP 3,000,000 - 5,000,000
Department Head, IT Management Services / Business Continuity Leader
Department Head, IT Management Services / Business Continuity Leader

RCBC Bankard Services Corporation • Metro Manila

On-site
PHP 2,000,000 - 3,500,000
IT Compliance Analyst
IT Compliance Analyst

Satellite Office • Pasig

On-site
PHP 700,000 - 1,000,000
IT.Security Analyst
IT.Security Analyst

Citco • Makati

On-site
PHP 600,000 - 1,200,000