Governance Risk and Compliance I Analyst II

PhilippinesPhilippines·Mandaluyong Citymid
Legal & ComplianceCompliance
0 views0 saves0 applied

Quick Summary

Overview

Job Title: Governance Risk and Compliance Analyst II Division: Governance, Risk & Compliance – IT Security Position Summary The GRC Analyst will act as a key contributor to Vertiv’s Governance, Risk,

Technical Tools
Legal & ComplianceCompliance

Job Title: Governance Risk and Compliance Analyst II

Division: Governance, Risk & Compliance – IT Security

Position Summary

The GRC Analyst will act as a key contributor to Vertiv’s Governance, Risk, and Compliance initiatives, driving risk assessments, security reviews, audit readiness, and third-party risk management efforts. This role supports continuous improvement of the risk register and policy exception processes, partners with cross-functional stakeholders, and helps develop a scalable security and compliance posture across the organization.

Key Responsibilities

• Lead IT risk assessments, mitigation planning, and control monitoring activities.

• Oversee risk register updates and coordinate with risk owners and SMEs to track mitigation actions.

• Drive third-party risk reviews and assessments using OneTrust and SecurityScorecard, escalating high-risk vendors for action.

• Conduct contract reviews focused on information security terms and recommend necessary revisions.

• Respond to customer security questionnaires with input from SMEs using Loopio.

• Supervise compliance training rollouts (e.g., phishing campaigns, annual security awareness training).

• Review and recommend changes to IT security policies and standards aligned with ISO 27001, NIST CSF, and other frameworks.

• Generate and present GRC dashboards and KPIs to leadership to inform risk posture and team performance.

• Act as an escalation point for GRC process inquiries and ticket-related exceptions.

• Mentor junior analysts and support GRC program maturity through playbooks, SOPs, and process documentation.

Qualifications

• Bachelor’s degree in information systems, Cybersecurity, or a related field.

• 5+ years of experience in GRC, IT Risk Management, or Information Security.

• Strong understanding of ITGC, SOX, ISO 27001, NIST CSF, and data privacy regulations (e.g., HIPAA, GDPR).

• Experience with GRC platforms such as ServiceNow GRC, OneTrust, and SecurityScorecard.

• Strong documentation and analytical skills with experience preparing audit-ready evidence.

• Certifications such as CISA, CISSP, ISO 27001 Lead Implementer or Auditor (preferred).

• Excellent communication and stakeholder management skills across global teams.

• Strong organizational skills and ability to manage multiple deliverables independently.

Location & Eligibility

Where is the job
Mandaluyong City, Philippines
On-site at the office
Who can apply
PH

Listing Details

Posted
September 2, 2026
First seen
September 26, 2026
Last seen
September 30, 2026

Posting Health

Days active
3
Repost count
0
Trust Level
19%
Scored at
September 30, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Governance Risk and Compliance I Analyst II