GRC Analyst

MyPass Global

Manila

On-site

USD 65,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Healthcare Insurance
16 Paid Time Offs
8 Compensatory Time Offs
Learning & Development opportunities
Team outings

Job summary

MyPass Global is hiring a GRC Analyst to support policy, risk, CAPA, and ISMS governance across our third-party and internal controls. You will coordinate with stakeholders, manage Drata evidence, and help prepare for ISO audits.

Based in our Cebu IT Park office, you will contribute to training campaigns, system access reviews, and documentation in Confluence while supporting continuous improvement of compliance workflows.

Qualifications

  • GRC, risk or compliance roles within an organisation managing information security or regulatory obligations.
  • Ability to manage multiple compliance registers (policy, risk, CAPA) simultaneously.
  • Experience with GRC platforms like Drata, including control monitoring and evidence management.

Responsibilities

  • Policy Register Management: monitor lifecycles, coordinate reviews, publish policies, maintain registers.
  • Risk Register Support: coordinate risk reviews, schedule assessments, expedite evidence, report on completion.
  • Drata Control Readiness Oversight: monitor readiness, create Jira tickets, manage onboarding/offboarding evidence.
  • Third-Party Provider Register Management: maintain provider register, coordinate due diligence, track renewals.
  • CAPA Register Management: own CAPA in QT9, collect evidence, present for closure, manage workflows.
  • KnowBe4 Training Campaign Support: rollout training campaigns, ensure content validity, report completion.
  • System Access Reviews: coordinate rolling reviews, remediate issues with stakeholders.
  • Google Workspace Support: guidance on templates and shared drives; analyze needs for structure.
  • Project Support: assist Corporate Services initiatives with coordination and status reporting.
  • Process Documentation: document SOPs in Confluence and keep current.
  • Compliance and Audit Support: assist ISO 27001 certifications and surveillance.

Skills

GRC experience
Stakeholder coordination
Jira usage
Confluence
Drata familiarity
Google Workspace
CAPA management
ISO audits
Analytical thinking

Tools

Jira
Confluence
Drata
Google Workspace

Job description

Who are we?

MyPass Global is a multi-award-winning workforce compliance software company. Our cutting-edge technology helps companies in high-stakes industries reduce risk, save up to 70% on back-office costs, and create safer work environments through our digital workforce solutions. As we rapidly expand with offices worldwide, we are seeking the next generation of innovative MyPassers to join us in shaping the future of our industry.

Read more about us here

Role Outcome

The GRC Analyst supports the integrity and currency of MyPass's third-party provider, risk, policy, and CAPA registers, ensuring all entries are reviewed, updated, or progressed to closure on schedule with appropriate evidence. The role supports the Senior Corporate Services Manager's ISMS ownership and audit obligations, and provides broader coordination support across compliance platforms, training campaigns, system access, Google Workspace guidance, and process documentation.

Responsibilities
Policy Register Management
  • Monitor the policy lifecycle to ensure review deadlines are met
  • Coordinate the policy review and approval process across all business areas
  • Publish approved policies in Confluence and Drata
  • Maintain the controlled document register, published versions, and master files
  • Maintain controlled templates within the master files and Google Gallery
Risk Register Support
  • Coordinate the timely review of risks within Drata
  • Support the Senior Corporate Services Manager with risk assessment scheduling, expediting evidence with stakeholders, and preparing documentation for risk closure
  • Monitor and report on risk review completion status
Drata Control Readiness Oversight
  • Monitor and report on Drata control readiness, identifying failing or at-risk technical, operational, and people controls
  • Create and manage Jira tickets for control issues requiring remediation, coordinating with control owners through to resolution
  • Coordinate personnel compliance within Drata, including monitoring onboarding and offboarding status against required timeframes
  • Maintain the Drata evidence register, ensuring evidence is current, complete, and mapped to the correct controls
Third-Party Provider Register Management
  • Maintain the third-party provider register covering software vendors, IT service providers, and other third-party providers
  • Coordinate vendor due diligence and periodic performance reviews with relevant stakeholders
  • Ensure vendor contract records, renewals, and review evidence are current and accurately maintained
CAPA Register Management
  • Own the CAPA register within QT9, covering corrective actions arising from ISO audits, risk treatments, and incidents
  • Expedite the collection of evidence from stakeholders to support timely CAPA closure
  • Prepare and present evidence for review by the Senior Corporate Services Manager prior to closure, flagging any gaps or inconsistencies identified
  • Maintain CAPA reporting and manage CAPA workflows end to end
  • Support the internal audit programme, providing CAPA status and evidence to the Lead Auditor and internal auditors as required
KnowBe4 Training Campaign Support
  • Coordinate the rollout of new KnowBe4 training campaigns
  • Monitor the validity of training modules to ensure content remains current
  • Prepare and distribute KnowBe4 completion and compliance reports
System Access Reviews
  • Coordinate and undertake system access reviews on a rolling schedule across managed platforms
  • Support timely remediation of identified access issues with relevant stakeholders
Google Workspace Support
  • Provide guidance to users on Google Workspace functionality, including templates and shared drives
  • Undertake analysis of user needs for shared drives to inform structure and access decisions
Project Support
  • Provide project support as required across Corporate Services initiatives, including coordination, documentation, and status reporting
Process Documentation
  • Document GRC standard operating procedures in Confluence, keeping content current as processes evolve
Compliance and Audit Support
  • Support external audit processes, including ISO 27001 certification and surveillance audits
  • Maintain documentation, configurations, and evidence in accordance with ISMS requirements
Requirements
Core GRC and Compliance Experience
  • Demonstrated experience in GRC, risk, or compliance roles within an organisation managing information security or regulatory compliance obligations
  • Proven ability to manage and coordinate multiple compliance registers simultaneously, including policy, risk, and corrective action registers
  • Demonstrated experience working within a GRC platform such as Drata or equivalent, including control monitoring, evidence management, and compliance reporting
Audit and CAPA Support
  • Demonstrated experience supporting internal or external audit programmes, including evidence preparation and coordination
  • Experience managing or coordinating corrective action or CAPA workflows through to closure
Stakeholder Coordination
  • Proven ability to coordinate across multiple business areas to meet compliance deadlines without direct authority over stakeholders
  • Demonstrated experience expediting evidence or actions from stakeholders and escalating appropriately where timelines are at risk
Systems and Tooling
  • Experience using Jira or equivalent ticketing tools for issue tracking and remediation coordination
  • Working knowledge of Google Workspace, including shared drive structure and administration (highly desirable)
  • Experience documenting standard operating procedures in a platform such as Confluence
Personal Attributes
  • Demonstrated critical thinking and independent problem-solving in past roles, with evidence of identifying and resolving issues without being directed to do so
  • High attention to detail, particularly in reviewing and preparing compliance evidence
Information Security Accountabilities
  • Understand own contribution to the effectiveness of the ISMS
  • Understand own responsibilities within the ISMS (e.g. Acceptable Use of Assets Policy, Information Security Policy)
  • Understand the consequences of non-compliance with the requirements of the ISMS
  • Understand information security guidelines related to own job role
Life at MyPass
  • Accessible and friendly office in Cebu IT Park
  • Celebrate You - Anniversary gifts as early as your first work anniversary!
  • Be Healthy - Wellbeing policy with a strong focus on whatever makes you feel good from the inside out, and a company-sponsored Healthcare Insurance worth PHP 110,000.00.
  • Work-Life Balance - Enjoy the right to disconnect with our 16 Paid Time Offs and 8 Compensatory Time Offs!
  • Fuel Your Growth Journey - Unlocking your potential with a blend of in-person and online learning and development opportunities
  • Get Rewarded and Recognized - Your impact to the business is seen and recognized through our Monthly Value Awards
  • Be Comfortable - Casual Friday every day!
  • We Love to Have Fun - Team outings, weekly lunches, team events, the list goes on…
  • Generous Employee Referral Program - Rewards for referring top talent
Feel valuable

We’re big on culture. So much so that the team we've carefully curated are not only high-performers, they're also excellent humans. We foster an environment that is open, respectful and collaborative, where the status quo is challenged and both success and failure are celebrated.

MyPass champions diversity at all levels of the company, and we live by our core values that set us apart. We cultivate an inclusive culture and do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We are dedicated to creating a workplace where everyone feels valued, respectful, and empowered to bring their authentic selves to work. Our mantra is to make things happen, every single day.

Our company values
Bring out the best

We connect and empower people to build a safer future. We strive to create a positive and enduring impact, no matter how small.

Challenge the norm

We pursue innovation by practising curiosity and always asking ‘why’. We challenge assumptions by seeking opportunities for growth and improvement.

Treat people well

We treat our customers, employees and partners as equals. We foster meaningful relationships through trust, compassion and respect.

Walk the walk

We are accountable for our goals, actions and collective vision. We work with integrity and are true to our word.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

MyPass Global • United States

On-site
USD 80,000 - 110,000
Healthcare Insurance
Paid Time Off
Professional development
Senior Security Assurance Analyst
Senior Security Assurance Analyst

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 190,000
Medical, dental, and vision insurance
Mental health benefits
401(k) plan with company match
+2
Senior Security Assurance Lead - Global Compliance & Audit
Senior Security Assurance Lead - Global Compliance & Audit

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 190,000
Medical, dental, and vision insurance
Mental health benefits
401(k) plan with company match
+2
Microsoft 365 Administrator
Microsoft 365 Administrator

PrePass • Phoenix (AZ)

On-site
USD 90,000 - 130,000
Medical Benefits
Dental Benefits
Vision Benefits
+4
Sr. Identity and Access Management Analyst
Sr. Identity and Access Management Analyst

Justworks • New York (NY)

On-site
USD 100,000 - 130,000
Wellness program offerings
Company retreats
Diverse and inclusive culture
GRC Engineer
GRC Engineer

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 250,000
Healthcare coverage
Vision & dental coverage
HSA & FSA
+7
GRC Analyst: Policy, Risk & CAPA Orchestrator
GRC Analyst: Policy, Risk & CAPA Orchestrator

Medium • Manila (AR)

On-site
USD 65,000 - 90,000
Healthcare Insurance
16 Paid Time Offs
8 Compensatory Time Offs
+2
Security GRC Analyst
Security GRC Analyst

Socket.dev • United States

Remote
USD 90,000 - 120,000
Health insurance
401(k) with company match
Paid time off
Cybersecurity Compliance Analyst
Cybersecurity Compliance Analyst

Docebo • United States

Hybrid
USD 90,000 - 130,000
Health benefits
Paid vacation days
Docebo Days
+1
GRC & Compliance Specialist — ISMS & Audit Ready
GRC & Compliance Specialist — ISMS & Audit Ready

MyPass Global • United States

On-site
USD 80,000 - 110,000
Healthcare Insurance
Paid Time Off
Professional development