
Posted 1 day ago
Governance, Risk & Compliance Manager
AI Summary
Manages the assurance phase of risk management by testing internal controls, maintaining compliance across regulatory and client requirements, serving as the Data Protection Officer, and operating the enterprise risk registers and RCSA program.
About this role
Satellite Office is looking for an experienced Governance, Risk & Compliance (GRC) Manager to join our Risk Management team in Ortigas.
The GRC Manager is responsible for the assurance phase of Satellite Office's risk management function, following the establishment of its policies, risk register, and process documentation.
The role independently tests that internal controls operate as designed, maintains the organisation's compliance posture across applicable regulatory, certification, and client-contractual requirements, and serves as the Company's Data Protection Officer (DPO) under the Philippine Data Privacy Act.
The GRC Manager additionally maintains the enterprise risk registers and administers the RCSA, reporting outcomes to the Risk Committee.
This is a hands-on role with exposure across internal controls, compliance, enterprise risk, data privacy and governance, with regular interaction with senior executives and governance committees.
What You'll Be Doing
Control Testing (Audit Function)
Design and run an ongoing controls-testing program.
Assess both the design and the operating effectiveness of controls through transaction and evidence sampling, maintain formal workpapers, and assign a rating to each control tested.
Report control exceptions, remediation plans, and re-test results to the Risk Committee in accordance with the established reporting cycle.
Coordinate with control owners on the closure of identified gaps, while maintaining independence from the functions whose controls are subject to testing.
Compliance Management
Monitor adherence to all relevant laws pertinent to the operations of Satellite Office, internal policies and relevant industry standards such as ISO27001, SOC2, GDPR and HIPAA.
Monitor compliance with applicable regulatory and client-contractual requirements, including requirements for regulated clients and sector-specific obligations.
Develop, implement, and maintain compliance policies and procedures.
Maintain and monitor the Compliance Register and oversee and govern statutory reporting outside tax.
Monitor compliance findings and pending actions through to formal closure.
Data Protection Officer (DPO)
Serve as the Company's registered Data Protection Officer with the National Privacy Commission (NPC), maintain current NPC registration, and act as the official point of contact for the NPC and for data subjects.
Lead personal data breach response, including compliance with the 72-hour NPC notification requirement.
Conduct Privacy Impact Assessments (PIAs) for new or materially changed processes.
Administer data subject requests and deliver periodic privacy awareness training across the organisation.
Working knowledge of the Philippine Data Privacy Act and NPC requirements is required. Formal DPO training/certification is an advantage, with certification support available following appointment.
Enterprise Risk
Operationalize the Enterprise Risk Management (ERM) and Governance frameworks to align with Satellite Office’s mission and vision and strategic objectives.
Maintain the Enterprise risk registers on an annual refresh cycle, in coordination with the designated risk owners and the Business Process Manager.
Administer and further develop the KRI program established for the principal residual risks, and escalate early-warning indicators to the Risk Committee.
Lead the GRC component of Incident Reporting, ensuring that operational risk incidents are detected, reported, and mitigated within statutory and policy timelines.
Design Business Continuity and Crisis Management protocols.
Coordinate with other departments, including Legal and IT, for incident investigations and risk assessments.
Governance Support
Own the Risk Committee reporting and meeting cadence and apply the organisation's established risk appetite framework.
Act as a liaison to address compliance concerns or inquiries from stakeholders.
Ensure pending actions and committee reporting obligations are completed on schedule.
Assist in the development and delivery of GRC training programs on compliance, risks and governance policies and the creation of awareness initiatives to promote ethical and compliance by design practices.
Provide independent risk opinions and advisory input on projects, systems, vendors, and process changes, including sign-off on risk acceptance and escalation of residual exposures.
Present findings and risk insights directly and independently to senior executives and committees.
What We're Looking For
We're looking for an experienced GRC professional who can combine strong risk and compliance knowledge, independent assurance capability and confident stakeholder management.
You'll ideally bring:
Bachelor's degree in Accounting, Finance, Information Systems, Law or a related field.
8+ years in risk and compliance management, internal audit, IT/compliance control testing, or GRC.
Experience in BPO, financial services or another regulated industry. BPO experience is particularly relevant.
Professional certification preferred: CPA, CIA or CISA.
ISO 27001 Lead Auditor certification is preferred.
Strong knowledge of regulatory requirements and risk management frameworks.
Experience with US regulatory requirements. Australian regulatory knowledge is advantageous.
Working knowledge of the Philippine Data Privacy Act and NPC requirements.
Hands-on experience with a GRC platform such as Sprinto, Vanta or similar. Experience with Sprinto is advantageous, but the ability to learn a GRC platform is important.
Demonstrated project management experience — able to plan, scope, and deliver GRC initiatives on schedule and across multiple stakeholders.
Experience issuing independent risk opinions and advisory input on projects, systems, vendors, and process changes.
Comfortable presenting findings directly and independently to senior executives and committees.
Strong communication and stakeholder management skills, with the confidence to engage with senior leadership and challenge constructively where required.
What Will Set You Apart
You'll stand out if you have:
Experience in BPO and/or financial services, particularly in a regulated environment.
Experience with control testing, RCSA, KRIs and enterprise risk registers.
Experience supporting SOC 2, ISO 27001, GDPR, HIPAA or similar assurance requirements.
Previous experience as a DPO or significant hands-on privacy compliance experience.
Experience with Sprinto, Vanta or similar GRC platforms.
Experience presenting directly to ExCo, Risk Committees, Boards or similar governance forums.
A practical approach to risk management and the ability to work across multiple stakeholders to drive remediation and closure.
Why Join Satellite Office?
This is an opportunity to take ownership of a broad GRC portfolio and have meaningful exposure across the organisation.
You'll work closely with senior leadership and the Risk Committee while helping strengthen Satellite Office's risk, compliance, controls, privacy and governance frameworks.
If you're an experienced GRC professional who enjoys working independently, engaging with senior stakeholders and turning risk and compliance requirements into practical outcomes, we'd love to hear from you.
Apply now and join Satellite Office as our next Governance, Risk & Compliance Manager.
Skills
Explore related jobs
More jobs at Satellite Office
Similar Business Continuity jobs
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.