KMC Careers Logo

IT, RISK AND COMPLIANCE SENIOR MANAGER

Mandaluyong, PhilippinesHybrid (3D onsite/2D WFH)Legal & CompliancePosted Sep 23

Make your next big career move by applying as KMC Solutions’ next IT, RISK AND COMPLIANCE SENIOR MANAGER

The Client is hiring an IT, Risk and Compliance Senior Manager to directly own IT infrastructure and security, data privacy and compliance programs, regulatory administration, and enterprise risk reporting for our Manila operations. This is a hands-on, individual contributor role; the "Senior Manager" title reflects the seniority and end-to-end ownership of the position, not a people-management mandate. You will build and run the function yourself, working directly with executive leadership, auditors, vendors, and regulators, and will grow a team under you as scope and headcount justify it.

On top of your salary, here are the exciting benefits you can look forward to:

  • Health Insurance/HMO
  • Enjoy unlimited MadMax Coffee
  • Diverse learning & growth opportunities
  • Accessible Cloud HR platform (Sprout)
  • Above standard leaves

The main responsibilities of a IT, RISK AND COMPLIANCE SENIOR MANAGER include:

IT & Cybersecurity

     Oversee IT infrastructure, endpoints, identity and access management, and incident response for the Manila operation.

     Set priorities and service expectations across employee technology, IT support, networks, and infrastructure.

     Establish processes for employee onboarding/offboarding, access administration, asset management, and cybersecurity controls.

     Oversee the coordination of IT incidents, vulnerabilities, service issues, and operational risks.

     Manage key IT and cybersecurity vendors, budgets, contracts, renewals, and improvement initiatives.

     Provide executive leadership with clear reporting on IT performance, material risks, and investment priorities.

Compliance, Privacy & Customer Assurance

     Own and maintain the SOC 2 Type II compliance program, including audits, policies, evidence, employee training, and access reviews.

     Coordinate GDPR and broader data-privacy obligations with internal stakeholders, legal counsel, and external specialists.

     Own customer security questionnaires, RFP responses, procurement reviews, and related security diligence.

     Ensure compliance findings, customer requirements, and remediation activities are assigned, tracked, and completed.

     Develop consistent, reusable documentation that supports efficient customer and audit responses.

Regulatory Administration & Enterprise Risk

     Administer the company's regulatory licenses and obligations — including PAGCOR and other applicable gaming, data-privacy, and financial-crime regulators — covering submissions, filings, renewals, and supporting documentation.

     Identify which regulatory bodies apply to the business beyond PAGCOR (e.g., the National Privacy Commission for data privacy, AMLC for anti-money-laundering obligations, and any regulators in other jurisdictions the company operates in) and maintain a current view of obligations under each.

     Serve as the primary point of contact for PAGCOR and other relevant regulators, and coordinate required information across the business and with external advisers.

     Identify, assess, and report material company-wide risks — operational, regulatory, technology, cybersecurity, and vendor — to executive leadership.

     Maintain a risk register with clear owners, mitigation plans, and timelines for significant risks.

     Support business-continuity planning and coordination of significant company-wide incidents.

Team Building & Growth

     As the function scales, hire, onboard, and lead direct reports across IT and/or compliance disciplines.

     Establish repeatable processes and documentation that support delegation as headcount grows.

To apply, you must be an expert on the following requirements:

     5+ years of experience in IT operations and/or security, with meaningful exposure to compliance or regulatory work (or an equivalent combination of experience).

     SOC 2 Type II Certified and Hands-on experience GDPR compliance frameworks.

     Experience in a regulated industry (gaming, financial services, or BPO); direct experience with PAGCOR, other gaming regulators, data-privacy authorities (e.g., NPC), or AML regulators (e.g., AMLC) is a strong plus.

     Comfortable operating as a solo individual contributor — building process from scratch — with the ambition and capability to grow into a people-leader role.

     Strong written and verbal communication skills; able to work directly and credibly with executive leadership, external auditors, and regulators.

It will also be favorable if you are knowledgeable in:

Additional relevant knowledge or experience related to the above requirements will be considered an advantage.

Legal & Compliance

Applying takes about a minute

Know someone for this?

Refer them in a few clicks and track their progress from your referrals dashboard.