Governance, Risk & Compliance Manager

Posted 2 Days Ago
Be an Early Applicant
Pasig, Eastern Manila District, National Capital Region, PHL
Hybrid
Senior level
Professional Services • Consulting
The Role
Owns governance, risk, and compliance assurance, including internal control testing, compliance monitoring, enterprise risk registers, RCSA, KRIs, incident reporting, business continuity, and Risk Committee reporting. Serves as the Philippine Data Protection Officer, managing privacy assessments, breach response, data subject requests, and NPC requirements. Advises executives on risk acceptance, remediation, projects, vendors, and process changes while maintaining compliance with ISO 27001, SOC 2, GDPR, HIPAA, and applicable regulations.
Summary Generated by Built In

Satellite Office is looking for an experienced Governance, Risk & Compliance (GRC) Manager to join our Risk Management team in Ortigas.

The GRC Manager is responsible for the assurance phase of Satellite Office's risk management function, following the establishment of its policies, risk register, and process documentation.

The role independently tests that internal controls operate as designed, maintains the organisation's compliance posture across applicable regulatory, certification, and client-contractual requirements, and serves as the Company's Data Protection Officer (DPO) under the Philippine Data Privacy Act.

The GRC Manager additionally maintains the enterprise risk registers and administers the RCSA, reporting outcomes to the Risk Committee.

This is a hands-on role with exposure across internal controls, compliance, enterprise risk, data privacy and governance, with regular interaction with senior executives and governance committees.

What You'll Be DoingControl Testing (Audit Function)
  • Design and run an ongoing controls-testing program.

  • Assess both the design and the operating effectiveness of controls through transaction and evidence sampling, maintain formal workpapers, and assign a rating to each control tested.

  • Report control exceptions, remediation plans, and re-test results to the Risk Committee in accordance with the established reporting cycle.

  • Coordinate with control owners on the closure of identified gaps, while maintaining independence from the functions whose controls are subject to testing.

Compliance Management
  • Monitor adherence to all relevant laws pertinent to the operations of Satellite Office, internal policies and relevant industry standards such as ISO27001, SOC2, GDPR and HIPAA.

  • Monitor compliance with applicable regulatory and client-contractual requirements, including requirements for regulated clients and sector-specific obligations.

  • Develop, implement, and maintain compliance policies and procedures.

  • Maintain and monitor the Compliance Register and oversee and govern statutory reporting outside tax.

  • Monitor compliance findings and pending actions through to formal closure.

Data Protection Officer (DPO)
  • Serve as the Company's registered Data Protection Officer with the National Privacy Commission (NPC), maintain current NPC registration, and act as the official point of contact for the NPC and for data subjects.

  • Lead personal data breach response, including compliance with the 72-hour NPC notification requirement.

  • Conduct Privacy Impact Assessments (PIAs) for new or materially changed processes.

  • Administer data subject requests and deliver periodic privacy awareness training across the organisation.

Working knowledge of the Philippine Data Privacy Act and NPC requirements is required. Formal DPO training/certification is an advantage, with certification support available following appointment.

Enterprise Risk
  • Operationalize the Enterprise Risk Management (ERM) and Governance frameworks to align with Satellite Office’s mission and vision and strategic objectives.

  • Maintain the Enterprise risk registers on an annual refresh cycle, in coordination with the designated risk owners and the Business Process Manager.

  • Administer and further develop the KRI program established for the principal residual risks, and escalate early-warning indicators to the Risk Committee.

  • Lead the GRC component of Incident Reporting, ensuring that operational risk incidents are detected, reported, and mitigated within statutory and policy timelines.

  • Design Business Continuity and Crisis Management protocols.

  • Coordinate with other departments, including Legal and IT, for incident investigations and risk assessments.

Governance Support
  • Own the Risk Committee reporting and meeting cadence and apply the organisation's established risk appetite framework.

  • Act as a liaison to address compliance concerns or inquiries from stakeholders.

  • Ensure pending actions and committee reporting obligations are completed on schedule.

  • Assist in the development and delivery of GRC training programs on compliance, risks and governance policies and the creation of awareness initiatives to promote ethical and compliance by design practices.

  • Provide independent risk opinions and advisory input on projects, systems, vendors, and process changes, including sign-off on risk acceptance and escalation of residual exposures.

  • Present findings and risk insights directly and independently to senior executives and committees.

What We're Looking For

We're looking for an experienced GRC professional who can combine strong risk and compliance knowledge, independent assurance capability and confident stakeholder management.

You'll ideally bring:

  • Bachelor's degree in Accounting, Finance, Information Systems, Law or a related field.

  • 8+ years in risk and compliance management, internal audit, IT/compliance control testing, or GRC.

  • Experience in BPO, financial services or another regulated industry. BPO experience is particularly relevant.

  • Professional certification preferred: CPA, CIA or CISA.

  • ISO 27001 Lead Auditor certification is preferred.

  • Strong knowledge of regulatory requirements and risk management frameworks.

  • Experience with US regulatory requirements. Australian regulatory knowledge is advantageous.

  • Working knowledge of the Philippine Data Privacy Act and NPC requirements.

  • Hands-on experience with a GRC platform such as Sprinto, Vanta or similar. Experience with Sprinto is advantageous, but the ability to learn a GRC platform is important.

  • Demonstrated project management experience — able to plan, scope, and deliver GRC initiatives on schedule and across multiple stakeholders.

  • Experience issuing independent risk opinions and advisory input on projects, systems, vendors, and process changes.

  • Comfortable presenting findings directly and independently to senior executives and committees.

  • Strong communication and stakeholder management skills, with the confidence to engage with senior leadership and challenge constructively where required.

What Will Set You Apart

You'll stand out if you have:

  • Experience in BPO and/or financial services, particularly in a regulated environment.

  • Experience with control testing, RCSA, KRIs and enterprise risk registers.

  • Experience supporting SOC 2, ISO 27001, GDPR, HIPAA or similar assurance requirements.

  • Previous experience as a DPO or significant hands-on privacy compliance experience.

  • Experience with Sprinto, Vanta or similar GRC platforms.

  • Experience presenting directly to ExCo, Risk Committees, Boards or similar governance forums.

  • A practical approach to risk management and the ability to work across multiple stakeholders to drive remediation and closure.

Why Join Satellite Office?

This is an opportunity to take ownership of a broad GRC portfolio and have meaningful exposure across the organisation.

You'll work closely with senior leadership and the Risk Committee while helping strengthen Satellite Office's risk, compliance, controls, privacy and governance frameworks.

If you're an experienced GRC professional who enjoys working independently, engaging with senior stakeholders and turning risk and compliance requirements into practical outcomes, we'd love to hear from you.

Apply now and join Satellite Office as our next Governance, Risk & Compliance Manager.

Skills Required

  • Bachelor's degree in Accounting, Finance, Information Systems, Law, or a related field
  • 8+ years of experience in risk and compliance management, internal audit, IT/compliance control testing, or GRC
  • Experience in BPO, financial services, or another regulated industry
  • Strong knowledge of regulatory requirements and risk management frameworks
  • Experience with US regulatory requirements
  • Working knowledge of the Philippine Data Privacy Act and National Privacy Commission requirements
  • Hands-on experience with a GRC platform such as Sprinto, Vanta, or similar
  • Project management experience delivering GRC initiatives across multiple stakeholders
  • Experience issuing independent risk opinions and advisory input
  • Ability to present findings independently to senior executives and committees
  • Strong communication and stakeholder management skills
  • CPA, CIA, or CISA certification
  • ISO 27001 Lead Auditor certification
  • Australian regulatory knowledge
  • Experience with control testing, RCSA, KRIs, and enterprise risk registers
  • Experience supporting SOC 2, ISO 27001, GDPR, HIPAA, or similar assurance requirements
  • Previous DPO experience or significant hands-on privacy compliance experience
  • Experience with Sprinto, Vanta, or similar GRC platforms
  • Experience presenting to ExCo, Risk Committees, Boards, or similar governance forums
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,000 Employees
Year Founded: 2013

What We Do

Satellite Office is a premium offshoring and staff-outsourcing provider that helps businesses build dedicated, high-performing teams in the Philippines. It recruits and supports talent across customer service, sales, IT and software development, finance, marketing, creative design, and back-office operations. Its end-to-end services include recruitment, onboarding, HR, payroll, technology infrastructure, facilities, and ongoing account management for international clients from offices in Australia, the United States, and the Philippines.

Similar Jobs

Optum Logo Optum

Communication Specialist

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Makati City, Metro Manila, National Capital Region, PHL
160000 Employees
Remote or Hybrid
2 Locations
289097 Employees

Pfizer Logo Pfizer

Senior Medical Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office
Makati City, Metro Manila, National Capital Region, PHL
121990 Employees

Wells Fargo Logo Wells Fargo

Associate Operations Processor

Fintech • Financial Services
Hybrid
Taguig City, Metro Manila, National Capital Region, PHL
205000 Employees

Similar Companies Hiring

Fora Thumbnail
Agency • On-Demand • Professional Services • Sales • Software • Travel • Hospitality
New York, NY
250 Employees
Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
150 Employees
Northslope Thumbnail
Artificial Intelligence • Information Technology • Software • Analytics • Consulting • Generative AI
London, GB
100 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account