Senior Manager, Risk and Compliance

iQor

Carmen

On-site

PHP 1,800,000 - 3,000,000

Full time

17 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

iQor Philippines seeks a Manager/Senior Manager, Risk and Compliance to establish and maintain an enterprise-wide governance framework covering risk management, regulatory compliance, internal audit coordination, and data privacy. This role also serves as the organization’s DPO under Philippine law and NPC regulations.

The position leads risk assessments, policy development, audits, and breach management while coordinating with various departments to strengthen governance and protect sensitive

Qualifications

  • Bachelor's degree in business or related field required.
  • Master's degree is an advantage.
  • 7–10 years of progressive experience in risk, compliance, governance, audit, data privacy, or internal controls.
  • At least 3 years in a leadership or management role.

Responsibilities

  • Develop and maintain enterprise risk management frameworks, policies and processes.
  • Conduct risk assessments and maintain organizational risk registers.
  • Assess operational, financial, regulatory, technology, cybersecurity and strategic risks.
  • Monitor risk mitigation plans and provide recommendations to leadership.
  • Prepare risk reports, dashboards and executive updates.
  • Promote a risk-aware culture across business functions.

Skills

Enterprise risk management
Regulatory compliance
Data privacy
Internal controls
Audit coordination
Stakeholder management
Leadership
Analytical thinking
Policy development

Education

Bachelor's degree in Business Administration, Finance, Accounting, Legal Management, Information Security, Information Technology, Risk Management, or related discipline
Master's degree is an advantage

Job description

The Manager or Senior Manager, Risk and Compliance is responsible for establishing and maintaining an enterprise-wide governance framework covering risk management, regulatory compliance, internal audit coordination, and data privacy. This role ensures compliance with Philippine regulatory requirements,

Company's corporate standards, and applicable data protection laws while strengthening internal controls, managing audits, and promoting a culture of integrity, accountability, and risk awareness across the organization.

The position also serves as the organization's Data Protection Officer (DPO) in accordance with the

Philippine Data Privacy Act of 2012 and National Privacy Commission (NPC) regulations

Key Responsibilities:
  • Develop and implement enterprise risk management frameworks, policies, and processes.
  • Conduct risk assessments and maintain organizational risk registers.
  • Assess operational, financial, regulatory, technology, cybersecurity, and strategic risks.
  • Monitor risk mitigation plans and provide recommendations to leadership.
  • Prepare risk reports, dashboards, and executive updates.
  • Promote a risk-aware culture across business functions.
2. Regulatory Compliance
  • Ensure organizational compliance with Philippine laws, labor regulations, corporate governance requirements, and applicable industry standards.
  • Monitor regulatory developments and assess their impact on company policies and operations.
  • Develop, review, and maintain compliance policies, procedures, and governance standards.
  • Investigate compliance concerns and coordinate corrective actions.
  • Act as primary liaison with regulatory authorities and government agencies when required.
  • Provide guidance to business leaders on compliance obligations and regulatory requirements.
3. Audit & Internal Controls
  • Develop and maintain internal control frameworks to safeguard company assets and ensure operational effectiveness.
  • Coordinate internal audits, management reviews, and external audits.
  • Ensure audit readiness and completeness of supporting documentation.
  • Monitor remediation plans and closure of audit findings.
  • Conduct control testing and compliance reviews.
  • Partner with HR, Finance, Operations, Technology, Procurement, and Legal teams to strengthen governance and controls.
4. Data Privacy & Protection (DPO Function)
  • Serve as the designated Data Protection Officer (DPO).
  • Ensure compliance with the Data Privacy Act of 2012, NPC issuances, and applicable global privacy standards.
  • Develop and implement privacy governance programs, policies, and procedures.
  • Conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs).
  • Monitor compliance with privacy requirements related to employee, client, vendor, and company data.
  • Maintain records of processing activities and data inventories.
  • Coordinate privacy incident investigations and breach management activities.
  • Lead breach notification assessments and reporting requirements.
  • Serve as primary contact with the National Privacy Commission.
  • Monitor vendor and third-party compliance with privacy obligations.
  • Conduct privacy awareness and training programs across the organization.
5. Investigations & Incident Management
  • Lead investigations involving compliance violations, privacy incidents, fraud, ethics concerns, and policy breaches.
  • Conduct root cause analyses and develop corrective and preventive actions.
  • Prepare incident reports for leadership review.
  • Escalate significant risks and compliance concerns appropriately.
  • Ensure confidentiality, fairness, and integrity throughout investigative processes.
6. Stakeholder Engagement & Advisory
  • Advise senior leadership regarding risk exposure, compliance obligations, audit results, and privacy matters.
  • Support strategic projects by identifying regulatory, compliance, privacy, and operational risks.
  • Collaborate with internal and external stakeholders to achieve governance objectives.
  • Communicate complex compliance and risk matters clearly to business leaders.
  • Represent Risk, Compliance, Audit, and Privacy functions in governance forums and project teams.
7. Training & Culture
  • Develop and deliver training programs on compliance, ethics, risk management, audit readiness, and data privacy.
  • Promote awareness of regulatory and privacy obligations across all levels of the organization.
  • Support organizational initiatives that strengthen ethical conduct and governance culture.
Qualifications
Education
  • Bachelor's degree in Business Administration, Finance, Accounting, Legal Management, Information Security, Information Technology, Risk Management, or related discipline.
  • Master's degree is an advantage.
Experience
  • Minimum 7-10 years of progressive experience in risk management, compliance, governance, audit,data privacy,or internal controls.
  • At least 3 years in a leadership or management role.
  • Experience in BPO, shared services, financial services, insurance, healthcare, or highly regulated
  • Experience working with Philippine regulatory agencies and compliance frameworks.
Knowledge & Skills
  • Strong understanding of:
  • Philippine Data Privacy Act of 2012
  • National Privacy Commission regulations
  • Enterprise Risk Management principles
  • Internal controls and audit methodologies
  • Corporate governance practices
  • Regulatory compliance frameworks
  • Excellent analytical and problem-solving skills.
  • Strong stakeholder management and influencing capabilities.
  • Ability to handle confidential and sensitive information.
  • Excellent written and verbal communication skills.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

General Manager Risk & Compliance
General Manager Risk & Compliance

Atain • Manila

On-site
PHP 3,000,000 - 5,000,000
General Manager - Risk & Compliance
General Manager - Risk & Compliance

Atain • Metro Manila

On-site
PHP 1,500,000 - 2,100,000
IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

Compass Experience Labs • Manila

Hybrid
PHP 1,800,000 - 3,200,000
IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

Compass Experience Labs LLC • Manila

Hybrid
PHP 1,800,000 - 3,200,000
IT & Information Security / Data Protection Officer (DPO) - PH
IT & Information Security / Data Protection Officer (DPO) - PH

compassexperiencelabs • Manila

Hybrid
PHP 1,200,000 - 1,600,000
Corporate Legal Counsel & Data Privacy Officer
Corporate Legal Counsel & Data Privacy Officer

SuperStaff • Makati

On-site
PHP 1,800,000 - 3,600,000
Data Privacy Officer (Midshift, Onsite)
Data Privacy Officer (Midshift, Onsite)

blaseek • Pasig

On-site
Data Privacy Specialist
Data Privacy Specialist

Maxicare Healthcare Corporation • Makati

On-site
PHP 600,000 - 800,000
Corporate Legal Counsel And Data Privacy Officer
Corporate Legal Counsel And Data Privacy Officer

SuperStaff Outsourcing • Manila

Hybrid
PHP 1,200,000 - 2,000,000
HMO with 1 free dependent
Life Insurance
20 PTO leave credits
+3
Head of Compliance Governance
Head of Compliance Governance

Our Clients • Philippines

On-site
PHP 2,000,000 - 4,000,000