Strong Understanding Of
IT Risk Management Frameworks
Job Description: Technology Risk & Compliance Officer - BGC - Manila
Location : BGC - Manila
Role Overview
We are seeking a highly motivated Technology Risk & Compliance Officer to strengthen our technology governance, risk management, cybersecurity compliance, and regulatory adherence programs. This role will be responsible for identifying, assessing, monitoring, and mitigating technology risks while ensuring compliance with internal policies, industry standards, and regulatory requirements.
The ideal candidate possesses strong knowledge of IT risk management, cybersecurity controls, regulatory frameworks, audit processes, and technology governance. The role will work closely with IT, Information Security, Internal Audit, Legal, Compliance, and Business stakeholders to ensure technology operations remain secure, compliant, and resilient.
Key Responsibilities
Technology Risk Management
- Identify, assess, and evaluate technology-related risks across applications, infrastructure, cloud environments, and third-party services.
- Maintain and enhance the Technology Risk Management (TRM) framework.
- Conduct risk assessments for projects, systems, cloud implementations, and technology changes.
- Track risk remediation plans and monitor risk treatment activities.
- Develop and maintain technology risk registers and reporting dashboards.
- Facilitate risk reviews and challenge sessions with technology and business teams.
Compliance & Governance
- Ensure compliance with regulatory requirements, internal policies, and technology governance standards.
Support Implementation And Monitoring Of Compliance Frameworks Such As
- ISO 27001
- ISO 42001
- NIST Cybersecurity Framework
- COBIT
- SOC 2
- PCI DSS
- GDPR/PDPA
- MAS TRM Guidelines (where applicable)
- Maintain governance processes for technology policies, standards, and procedures.
- Conduct compliance reviews and self-assessments.
Audit & Control Management
- Coordinate internal, external, regulatory, and client audits.
- Manage audit findings and ensure timely remediation of control gaps.
- Review effectiveness of IT General Controls (ITGCs).
- Evaluate design and operational effectiveness of key technology controls.
- Support control testing and evidence collection activities.
Third-Party & Vendor Risk Management
- Conduct technology and cybersecurity risk assessments for vendors and service providers.
- Review third-party compliance reports, including SOC reports and certifications.
- Monitor vendor risk remediation activities and contractual compliance obligations.
- Support ongoing due diligence and risk monitoring for critical vendors.
Cybersecurity Risk & Control Oversight
- Partner with Information Security teams to evaluate cybersecurity risks.
- Review security controls related to identity management, access control, cloud security, vulnerability management, and data protection.
- Assist in ensuring adherence to cybersecurity policies and standards.
- Monitor emerging threats, vulnerabilities, and regulatory developments.
Regulatory and Reporting Responsibilities
- Prepare risk and compliance reports for senior management and governance committees.
- Track key risk indicators (KRIs) and compliance metrics.
- Support regulatory submissions, assessments, and inspections.
- Maintain compliance documentation and evidence repositories.
Required Qualifications
Education
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business, or related discipline.
Experience
5+ years of experience in Technology Risk, IT Audit, IT Compliance, Information Security, or Governance Risk & Compliance (GRC).
Experience working in regulated industries such as banking, insurance, healthcare, telecommunications, or technology services is preferred.
Technical Knowledge
- Strong Understanding Of IT Risk Management Frameworks
- Cybersecurity Controls
- Regulatory Compliance Requirements
- IT Governance Processes
- Risk Assessment Methodologies
- Cloud Risk Management
- IT General Controls (ITGC)
- Business Continuity & Disaster Recovery
- Vendor Risk Management
Preferred Certifications
- CISA (Certified Information Systems Auditor)
- CRISC (Certified in Risk and Information Systems Control)
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- ISO 27001 Lead Implementer/Auditor
- CGEIT (Certified in the Governance of Enterprise IT)
- Certified Risk Management Professional (CRMP)
Key Competencies
Risk & Control Management
Technology risk assessment
Control design and evaluation
Regulatory compliance monitoring
Issue and remediation management
Analytical Skills
- Strong problem-solving and critical thinking skills
- Ability to analyze complex risk scenarios
- Data-driven decision making
Communication & Stakeholder Management
- Excellent verbal and written communication skills
- Ability to communicate risk matters to technical and non-technical audiences
- Experience engaging with auditors, regulators, and senior management
Organizational Skills
- Ability to manage multiple initiatives simultaneously
- Strong attention to detail
- Effective documentation and reporting skills
Preferred Experience
- Experience with GRC platforms such as ServiceNow GRC, Archer, MetricStream, LogicGate, or OneTrust.
- Experience managing compliance programs in cloud environments (Azure, AWS, GCP).
- Familiarity with AI Governance, Data Privacy, and Emerging Technology Risk.
- Experience supporting digital transformation and cloud migration initiatives.
- Knowledge of DevSecOps and secure software development practices.
Success Measures
The Successful Candidate Will
- Reduce technology and compliance risks through proactive risk management.
- Improve audit and regulatory examination outcomes.
- Ensure timely closure of risk and audit findings.
- Strengthen governance, controls, and compliance posture.
- Achieve high levels of stakeholder confidence and regulatory readiness.
- Enable secure adoption of new technologies and digital initiatives.
Ideal Candidate Profile
A proactive risk professional who combines strong technology knowledge with governance and compliance expertise, capable of balancing regulatory requirements, operational effectiveness, and business objectives while fostering a culture of risk awareness and accountability.