Technology Risk & Compliance Officer - BGC - Manila

Dotco Pte. Ltd.

Taguig

On-site

PHP 1,200,000 - 1,900,000

Full time

6 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Dotco Pte. Ltd. is hiring a Technology Risk & Compliance Officer in Manila (BGC). The role focuses on strengthening governance, risk management, cybersecurity compliance, and regulatory adherence across IT environments.

The successful candidate will lead TRM activities, conduct risk assessments, coordinate audits, and ensure adherence to frameworks such as ISO 27001, NIST, and SOC 2.

Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business, or related discipline.
  • 5+ years in Technology Risk, IT Audit, IT Compliance, Information Security, or GRC.
  • Experience in regulated industries preferred.

Responsibilities

  • Identify, assess, and evaluate technology-related risks across applications, infrastructure, cloud environments, and third-party services.
  • Maintain and enhance the Technology Risk Management framework and risk registers.
  • Conduct risk assessments for projects, systems, cloud implementations, and technology changes.
  • Track remediation plans and monitor treatment activities; report to senior stakeholders.
  • Coordinate internal/external audits and manage findings with timely remediation.
  • Ensure compliance with regulatory requirements, internal policies, and governance standards.
  • Perform vendor risk assessments and review third-party reports (SOC, certifications).
  • Monitor cybersecurity controls: identity management, access, cloud security, vulnerability management, data protection.
  • Prepare risk and compliance reports for governance committees and manage KRIs.

Skills

IT risk frameworks
Cybersecurity controls
Regulatory compliance
IT governance
Risk assessment
Cloud risk management
ITGC
BC/DR
Vendor risk

Education

Bachelor's degree in IT/Cybersecurity/CS/Risk Mgmt

Job description

Strong Understanding Of

IT Risk Management Frameworks


Job Description: Technology Risk & Compliance Officer - BGC - Manila

Location : BGC - Manila


Role Overview

We are seeking a highly motivated Technology Risk & Compliance Officer to strengthen our technology governance, risk management, cybersecurity compliance, and regulatory adherence programs. This role will be responsible for identifying, assessing, monitoring, and mitigating technology risks while ensuring compliance with internal policies, industry standards, and regulatory requirements.


The ideal candidate possesses strong knowledge of IT risk management, cybersecurity controls, regulatory frameworks, audit processes, and technology governance. The role will work closely with IT, Information Security, Internal Audit, Legal, Compliance, and Business stakeholders to ensure technology operations remain secure, compliant, and resilient.


Key Responsibilities

Technology Risk Management


  • Identify, assess, and evaluate technology-related risks across applications, infrastructure, cloud environments, and third-party services.

  • Maintain and enhance the Technology Risk Management (TRM) framework.

  • Conduct risk assessments for projects, systems, cloud implementations, and technology changes.

  • Track risk remediation plans and monitor risk treatment activities.

  • Develop and maintain technology risk registers and reporting dashboards.

  • Facilitate risk reviews and challenge sessions with technology and business teams.


Compliance & Governance


  • Ensure compliance with regulatory requirements, internal policies, and technology governance standards.


Support Implementation And Monitoring Of Compliance Frameworks Such As


  • ISO 27001

  • ISO 42001

  • NIST Cybersecurity Framework

  • COBIT

  • SOC 2

  • PCI DSS

  • GDPR/PDPA

  • MAS TRM Guidelines (where applicable)

  • Maintain governance processes for technology policies, standards, and procedures.

  • Conduct compliance reviews and self-assessments.


Audit & Control Management


  • Coordinate internal, external, regulatory, and client audits.

  • Manage audit findings and ensure timely remediation of control gaps.

  • Review effectiveness of IT General Controls (ITGCs).

  • Evaluate design and operational effectiveness of key technology controls.

  • Support control testing and evidence collection activities.


Third-Party & Vendor Risk Management


  • Conduct technology and cybersecurity risk assessments for vendors and service providers.

  • Review third-party compliance reports, including SOC reports and certifications.

  • Monitor vendor risk remediation activities and contractual compliance obligations.

  • Support ongoing due diligence and risk monitoring for critical vendors.


Cybersecurity Risk & Control Oversight


  • Partner with Information Security teams to evaluate cybersecurity risks.

  • Review security controls related to identity management, access control, cloud security, vulnerability management, and data protection.

  • Assist in ensuring adherence to cybersecurity policies and standards.

  • Monitor emerging threats, vulnerabilities, and regulatory developments.


Regulatory and Reporting Responsibilities


  • Prepare risk and compliance reports for senior management and governance committees.

  • Track key risk indicators (KRIs) and compliance metrics.

  • Support regulatory submissions, assessments, and inspections.

  • Maintain compliance documentation and evidence repositories.


Required Qualifications

Education

Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business, or related discipline.


Experience

5+ years of experience in Technology Risk, IT Audit, IT Compliance, Information Security, or Governance Risk & Compliance (GRC).


Experience working in regulated industries such as banking, insurance, healthcare, telecommunications, or technology services is preferred.


Technical Knowledge


  • Strong Understanding Of IT Risk Management Frameworks

  • Cybersecurity Controls

  • Regulatory Compliance Requirements

  • IT Governance Processes

  • Risk Assessment Methodologies

  • Cloud Risk Management

  • IT General Controls (ITGC)

  • Business Continuity & Disaster Recovery

  • Vendor Risk Management


Preferred Certifications


  • CISA (Certified Information Systems Auditor)

  • CRISC (Certified in Risk and Information Systems Control)

  • CISSP (Certified Information Systems Security Professional)

  • CISM (Certified Information Security Manager)

  • ISO 27001 Lead Implementer/Auditor

  • CGEIT (Certified in the Governance of Enterprise IT)

  • Certified Risk Management Professional (CRMP)


Key Competencies

Risk & Control Management


Technology risk assessment


Control design and evaluation


Regulatory compliance monitoring


Issue and remediation management


Analytical Skills


  • Strong problem-solving and critical thinking skills

  • Ability to analyze complex risk scenarios

  • Data-driven decision making


Communication & Stakeholder Management


  • Excellent verbal and written communication skills

  • Ability to communicate risk matters to technical and non-technical audiences

  • Experience engaging with auditors, regulators, and senior management


Organizational Skills


  • Ability to manage multiple initiatives simultaneously

  • Strong attention to detail

  • Effective documentation and reporting skills


Preferred Experience


  • Experience with GRC platforms such as ServiceNow GRC, Archer, MetricStream, LogicGate, or OneTrust.

  • Experience managing compliance programs in cloud environments (Azure, AWS, GCP).

  • Familiarity with AI Governance, Data Privacy, and Emerging Technology Risk.

  • Experience supporting digital transformation and cloud migration initiatives.

  • Knowledge of DevSecOps and secure software development practices.


Success Measures

The Successful Candidate Will


  • Reduce technology and compliance risks through proactive risk management.

  • Improve audit and regulatory examination outcomes.

  • Ensure timely closure of risk and audit findings.

  • Strengthen governance, controls, and compliance posture.

  • Achieve high levels of stakeholder confidence and regulatory readiness.

  • Enable secure adoption of new technologies and digital initiatives.


Ideal Candidate Profile

A proactive risk professional who combines strong technology knowledge with governance and compliance expertise, capable of balancing regulatory requirements, operational effectiveness, and business objectives while fostering a culture of risk awareness and accountability.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Governance, Risk and Compliance Manager
IT Governance, Risk and Compliance Manager

OwnBank • Taguig

On-site
PHP 1,800,000 - 2,600,000
Technology Risk & Governance Manager
Technology Risk & Governance Manager

Our Clients • Makati

Hybrid
PHP 1,200,000 - 2,100,000
Technology Controls Senior Analyst
Technology Controls Senior Analyst

Vault Outsourcing OPC • Muntinlupa

On-site
PHP 600,000 - 900,000
Risk Compliance Officer
Risk Compliance Officer

Concentrix • Philippines

On-site
PHP 600,000 - 1,200,000
IT Senior Risk Associate (GRC)
IT Senior Risk Associate (GRC)

Anchored Solutions MNL, Inc. • Metro Manila

On-site
PHP 700,000 - 1,300,000
Technology and Cybersecurity Governance Manager
Technology and Cybersecurity Governance Manager

Create Synergies Inc. • Philippines

Hybrid
PHP 1,200,000 - 1,800,000
IT Governance, Risk & Compliance (GRC) Analyst
IT Governance, Risk & Compliance (GRC) Analyst

Satellite Office • Taguig

On-site
PHP 420,000 - 660,000
Technology Controls Manager
Technology Controls Manager

Vault Outsourcing OPC • Muntinlupa

On-site
PHP 900,000 - 1,500,000
Compliance Head (Cybersecurity)
Compliance Head (Cybersecurity)

Smart Communications, Inc. • Makati

On-site
PHP 1,200,000 - 1,800,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

Seven Seven Global Services, Inc. • Metro Manila

On-site
PHP 1,200,000 - 2,100,000