IGT Solutions
General Manager - Risk and Compliance

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role Overview
Serve as a key leader in driving, shaping, and governing the organization’s Risk and Compliance framework, ensuring alignment with contractual requirements, internal controls, risk assessment, and enterprise-wide strategic objectives. Provide strategic oversight and direction to core Risk & Compliance initiatives, acting as an anchor member of the organization’s governance structure. Selected candidate will be leading Philippines and South Africa clusters.
Application / Tools Risk Assessment
- Oversee identification, assessment, and treatment of strategic, operational, financial, information security, and third-party risks.
- Maintain process risk register, KRIs, and risk appetite frameworks.
- Provide insights and risk heatmaps to leadership and stakeholder forums.
Security Certifications & Compliance Standards (ISO 27001, ISO 9001, PCI DSS, SOC 1 & 2, HIPAA)
- Lead, maintain, and enhance compliance with ISO 27001 & ISO 9001, and other global security frameworks like PCI DSS, SOC -1, SOC – 2 etc.
- Oversee ISMS governance, process risk assessments, internal audits, surveillance audits, and certification cycles.
- Ensure secure handling, processing, and storage of sensitive data in line with applicable standards.
- Collaborate with internal stakeholders and external auditors to ensure control effectiveness.
- Maintain evidence repositories, Statement of Applicability (SoA), risk treatment plans (RTP), and continuous improvement logs.
- Drive annual certification, recertification, and readiness assessments.
- Ensure closure of non-conformities and alignment with regulatory and industry requirements.
Internal Controls & Assurance Specific to NPC (National Privacy Commission, Philippines)
- Strengthen the organization’s internal control environment on NPC guidelines.
- Employee will act as a Data Protection Officer for Philippines location.
- Conduct process-level DPIA’s, control testing, and remediation tracking.
- Ensure readiness for internal, external, and regulatory audits.
Audit Governance (Internal, External & Regulatory)
- Coordinate internal audits, external audits, and compliance audits.
- Manage end-to-end audit lifecycle: planning, fieldwork, evidence, closure, CAPA validation.
- Prepare consolidated audit reports for leadership review.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Incident, Breach & Root Cause Management
- Lead investigation for incident/breach management including detection, escalation, containment, and RCA.
- Provide timely and transparent reporting to leadership.
Third-Party (Client & Vendor Risk Management)
- Lead end to end client audits & maintain contractual compliance.
- Implement and maintain third-party due diligence, vendor reviews, and ongoing monitoring.
- Ensure all high-risk vendors are assessed for security, compliance, and contractual controls.
- Oversee remediation and compliance certification requirements for vendors.
Data Privacy
- Drive privacy compliance with laws and frameworks (e.g., GDPR principles).
- Ensure coverage of DFD, ROPA & DPIA’s vis-à-vis GDPR.
- Lead data lifecycle governance, retention controls, and breach response readiness.
Reporting, Analytics & GRC Tool Enablement
- Build and own dashboards for risk, compliance, security certification status, KRIs, audits, and incidents.
- Ensure high data quality, automation, and real-time governance.
- Optimize GRC tools for reporting, workflow automation, and maturity uplift.
Culture, Training & Awareness
- Build organizational competency in risk and compliance.
- Deliver training programs in ethics, privacy, cyber hygiene, security standards, and compliance.
- Promote speak-up, transparent reporting, and non-retaliation culture.
Relevant Experience
- 15+ years of progressive experience in Risk Management, Compliance, Internal Controls, Corporate Governance, or Business Excellence within mid-to-large-scale organizations.
- Demonstrated experience in leading Enterprise Risk Management (ERM) programs, including risk identification, assessment, treatment planning, KRI development, and governance reporting.
- Proven expertise in managing regulatory compliance frameworks, statutory obligations, internal/external audits, and regulatory inspections.
- Hands-on experience implementing and maintaining security and compliance certifications, including:
- ISO 27001 (ISMS implementation, audit readiness, SoA, RTP, recertification cycles)
- PCI DSS compliance (assessment support, evidence readiness, ASV scans, hardening)
- SOC 1 & SOC 2 Type I/II (control mapping, walkthroughs, evidence coordination)
- HIPAA compliance for PHI environments (privacy/security safeguards, breach readiness)
- Strong background in designing and strengthening internal control frameworks, conducting control testing, and resolving audit findings with a focus on eliminating repeat issues.
- Prior responsibility for third-party risk management, vendor assessments, contract compliance, and continuous monitoring of high-risk suppliers.
- Exposure to data privacy, including DPIA, data lifecycle controls, consent management, and privacy compliance (e.g., NPC Act, GDPR-aligned practices).
- Experience working closely with Information Security, including vulnerability management, security hardening, access reviews, and cyber awareness initiatives.
- Demonstrated leadership in policy creation, risk governance, process standardization, and continuous improvement initiatives aligned with Business Excellence.
- Experience managing cross-functional teams, senior stakeholder engagement, and presenting insights to leadership, Board, and Audit Committees.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Why Join Atain?
At Atain, learning is a strategic driver of business success. This role offers the opportunity to build a future-ready workforce, influence organizational culture, and lead transformational learning initiatives that directly impact business growth and employee success.
It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, colour, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills