Cyber Governance, Risk and Compliance Specialist

Reposted 8 Days Ago
Be an Early Applicant
Cebu City, Cebu, Central Visayas, PHL
In-Office
Senior level
Software • Financial Services
The Role
Manage and improve the organization's ISMS and cyber GRC program: develop policies, run risk assessments, maintain risk register, coordinate audits and third-party due diligence, prepare governance reports, and recommend process improvements to ensure regulatory and standards compliance.
Summary Generated by Built In

Overview of the Role

The Cyber Governance, Risk and Compliance (GRC) Specialist supports the organization's information security governance by managing security risks, maintaining the Information Security Management System (ISMS), managing & developing the Cyber awareness program, and ensuring compliance with applicable policies, standards, and regulatory requirements. The role also coordinates risk assessments, audits, governance reporting, and continuous improvement initiatives to strengthen the organization's overall security posture. 

Responsibilities:

  • Support the implementation, maintenance, and continual improvement of the organization's Information Security Management System (ISMS). 
  • Develop, review, and maintain information security policies, standards, procedures, and related governance documentation. 
  • Conduct information security risk assessments, develop & maintain the Information Security Risk Register, and monitor the implementation of risk treatment plans. 
  • Coordinate internal and external information security audits, track audit findings, and ensure timely remediation of identified issues. 
  • Conduct information security due diligence and risk assessments for third-party vendors, suppliers, and service providers. 
  • Prepare and present governance reports, risk metrics, compliance dashboards, and management reports for executive leadership and governance committees. 
  • Monitor emerging cybersecurity risks, regulatory changes, and industry best practices, and recommend improvements to governance, risk management, and compliance processes. 

Requirements
  • Minimum 5 years' experience in Information Security GRC, IT Risk, Information Security, IT Audit, or a related field. 
  • Bachelor's degree in Information Security, Computer Science, Information Systems, Risk Management, or a related field. Relevant professional certifications such as CISSP, CISM, CRISC, ISO/IEC 27001 Lead Implementer or Lead Auditor, CISA, CGRC, or equivalent are highly desirable. 
  • Demonstrated experience in developing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), preferably aligned with ISO/IEC 27001. 
  • Knowledge of security governance frameworks and standards such as ISO/IEC 27001, ISO 31000, NIST Cybersecurity Framework (CSF), CIS Controls, and applicable data protection and privacy regulations. 
  • Experience conducting information security risk assessments, facilitating risk treatment plans, and monitoring risk mitigation activities across the organization. 
  • Working knowledge of cybersecurity technologies, security operations, and incident management sufficient to assess risks, review reports, and provide governance oversight. 
  • Strong written and verbal communication skills, including the ability to prepare governance reports, policies, executive briefings, and presentations for senior management and governance committees. 
  • High level of integrity, professionalism, and commitment to confidentiality and ethical conduct. 

Benefits
  • 500K per incident HMO coverage + Dental & Optical benefits ​
  • 2-week paid Christmas vacation​
  • Electricity & Data subsidies​
  • 25K Educational Assistance ​
  • Training and equipment will be provided​
  • Fixed Schedule of Mon-Fri from 7 AM to 4 PM​

Skills Required

  • Minimum 5 years' experience in Information Security GRC, IT Risk, Information Security, IT Audit, or a related field.
  • Bachelor's degree in Information Security, Computer Science, Information Systems, Risk Management, or a related field.
  • Relevant professional certifications such as CISSP, CISM, CRISC, ISO/IEC 27001 Lead Implementer or Lead Auditor, CISA, CGRC, or equivalent.
  • Demonstrated experience developing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), preferably aligned with ISO/IEC 27001.
  • Knowledge of security governance frameworks and standards such as ISO/IEC 27001, ISO 31000, NIST CSF, CIS Controls, and applicable data protection and privacy regulations.
  • Experience conducting information security risk assessments, facilitating risk treatment plans, and monitoring risk mitigation activities.
  • Working knowledge of cybersecurity technologies, security operations, and incident management sufficient to assess risks and provide governance oversight.
  • Strong written and verbal communication skills, including preparing governance reports, executive briefings, and presentations.
  • High level of integrity, professionalism, commitment to confidentiality and ethical conduct.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Cebu City
969 Employees
Year Founded: 2013

What We Do

We are an Australian company that has operations in the Philippines that provides business growth, consulting, and delivery capabilities to more than 250 of the most innovative and disruptive financial services firms across Australia. Our consulting-led approach leverages services in strategy, process improvement, intelligent automation, data analytics, and operations. We specialise in supporting financial firms, accounting practices, and mortgage brokers.

Similar Jobs

Smartly Logo Smartly

Solutions Engineer

AdTech • Artificial Intelligence • Digital Media • Marketing Tech • Social Media • Software • Generative AI
Easy Apply
Remote or Hybrid
Philippines
805 Employees

UL Solutions Logo UL Solutions

Intern

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
Philippines
15000 Employees

CrowdStrike Logo CrowdStrike

Sales Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Philippines
11000 Employees

Smartly Logo Smartly

Designer

AdTech • Artificial Intelligence • Digital Media • Marketing Tech • Social Media • Software • Generative AI
Easy Apply
Remote or Hybrid
Philippines
805 Employees
5-5 Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account