Sr. Specialist, GRC

LaVie Resort and Casino Manila

Manila

On-site

PHP 550,000 - 900,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

LaVie Resort and Casino Manila is seeking a Senior Specialist, GRC to oversee governance, risk, and compliance across IT systems, infrastructure, and security controls. You will partner with IT, Security, Engineering, and Audit teams to manage technology risk and support regulatory programs.

The role focuses on aligning IT strategy with business objectives, conducting risk assessments, and ensuring adherence to standards such as ISO 27001, SOC2, and PCI DSS.

Qualifications

  • Bachelor's degree in Information Systems, Risk Management, Business, Law, or a related field.
  • 2+ years of experience in GRC, risk management, compliance, audit, or information security.
  • Strong understanding of IT controls, cybersecurity principles, and system architecture.
  • Experience with audits and regulatory examinations.
  • Experience with cloud platforms and SaaS environments preferred.
  • Excellent analytical, documentation, and communication skills.
  • Experience in a regulated industry (PCI DSS, DPA, SOC2, etc.)

Responsibilities

  • Develop and maintain IT policies, standards, and procedures.
  • Support governance frameworks (e.g., ISO 27001, COBIT, NIST CSF, COSO).
  • Ensure alignment between business objectives, IT strategy, and security controls.
  • Conduct IT and information security risk assessments.
  • Evaluate technical controls across infrastructure, cloud, applications, and data.
  • Support vulnerability management and control remediation tracking.
  • Perform third-party IT and cybersecurity risk assessments.
  • Support compliance with IT-focused regulations and standards (e.g., SOC2, ISO 27001, PCI DSS, SOX ITGCS, HIPAA Security Rules).
  • Coordinate IT audits and penetration testing activities.
  • Collect, review, and maintain technical audit evidence Monitor regulatory changes and assess business impact.
  • Track remediation efforts and continuous improvement initiatives.
  • Partner with IT Infrastructure, CyberSecurity, Technical/Application Support and DevOps teams.
  • Prepare IT risk metrics, dashboards, and compliance reports Support security awareness and control training initiatives.

Skills

GRC
Risk management
Compliance
Audit
IT controls
Cybersecurity basics

Education

Bachelor's degree

Tools

Cloud platforms
SaaS environments

Job description

  • The Senior Specialist, GRC focuses on technology, cybersecurity, and information risk. This role ensures IT systems, infrastructure, and security controls align with regulatory requirements, industry standards, and internal policies. The specialist works closely with IT, Security, Engineering, and Audit teams to manage technology risks and support compliance initiatives.
JOB RESPONSIBILITIES
  • Develop and maintain IT policies, standards, and procedures.
  • Support governance frameworks (e.g., ISO 27001, COBIT, NIST CSF, COSO).
  • Ensure alignment between business objectives, IT strategy, and security controls.
  • Conduct IT and information security risk assessments.
  • Evaluate technical controls across infrastructure, cloud, applications, and data.
  • Support vulnerability management and control remediation tracking.
  • Perform third-party IT and cybersecurity risk assessments.
  • Support compliance with IT-focused regulations and standards (e.g., SOC2, ISO 27001, PCI DSS, SOX ITGCS, HIPAA Security Rules).
  • Coordinate IT audits and penetration testing activities.
  • Collect, review, and maintain technical audit evidence Monitor regulatory changes and assess business impact.
  • Track remediation efforts and continuous improvement initiatives.
  • Partner with IT Infrastructure, CyberSecurity, Technical/Application Support and DevOps teams.
  • Prepare IT risk metrics, dashboards, and compliance reports Support security awareness and control training initiatives.
JOB QUALIFICATIONS
  • Bachelor's degree in Information Systems, Risk Management, Business, Law, or a related field
  • 2+ years of experience in GRC, risk management, compliance, audit, or information security
  • Strong understanding of IT controls, cybersecurity principles, and system architecture
  • Experience with audits and regulatory examinations
  • Experience with cloud platforms and SaaS environments preferred
  • Excellent analytical, documentation, and communication skills
  • Experience in a regulated industry (PCI DSS, DPA, SOC2, etc.)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Specialist, GRC
Senior Specialist, GRC

LaVie • Manila

On-site
PHP 1,200,000 - 1,800,000
GRC Specialist
GRC Specialist

Robinsons Retail Holdings Inc. • Quezon City

On-site
PHP 600,000 - 900,000
Information Security & Compliance Senior Specialist
Information Security & Compliance Senior Specialist

CITADEL PACIFIC, LTD. - ROHQ • Taguig

On-site
PHP 600,000 - 900,000
GRC Risk & Compliance Specialist – IT & Security
GRC Risk & Compliance Specialist – IT & Security

LaVie • Manila

On-site
PHP 1,200,000 - 1,800,000
GRC & ISMS Specialist: Lead Security Compliance & Risk
GRC & ISMS Specialist: Lead Security Compliance & Risk

Virtual Business Partners Pty. Ltd. • Cebu City

On-site
PHP 800,000 - 1,200,000
HMO + Dental/Optical
Christmas vacation
Electricity & Data subsidies
+3
Cyber Security Specialist
Cyber Security Specialist

Sterling Global Call Center, Inc. • Pasig

On-site
PHP 900,000 - 1,300,000
Governance Risk and Compliance I Analyst II
Governance Risk and Compliance I Analyst II

Vertiv Co • Mandaluyong

On-site
PHP 600,000 - 900,000
Cyber Governance, Risk and Compliance Specialist
Cyber Governance, Risk and Compliance Specialist

Virtual Business Partners Pty. Ltd. • Cebu City

On-site
PHP 800,000 - 1,200,000
HMO + Dental/Optical
Christmas vacation
Electricity & Data subsidies
+3
Governance Risk And Compliance I Analyst II
Governance Risk And Compliance I Analyst II

Vertiv • Mandaluyong

On-site
PHP 900,000 - 1,300,000
Technology Controls Senior Analyst
Technology Controls Senior Analyst

Vault Outsourcing OPC • Muntinlupa

On-site
PHP 600,000 - 900,000