Compliance Implementation Associate-Cebu
Iqor- Posted 10 hours ago
- Be among the first 10 applicants
Job Description
Job Summary:
The Compliance Implementation Associate supports the day-to-day execution of compliance, audit, risk governance, regulatory documentation, and Integrated Management System activities. The role helps maintain audit readiness and supports the implementation of controls aligned with ISO 27001, PCI DSS 4.0, HIPAA/HITRUST and SOC 2 Type II.
Working under the guidance of the Compliance Implementation Senior Team Lead, the Associate coordinates with process owners and cross-functional stakeholders, maintains accurate evidence and records, tracks compliance and risk actions, and escalates gaps or delays. The role contributes to consistent compliance execution and continuous improvement of the organization's risk and compliance posture.
Responsibilities:
Compliance Monitoring and Audit Support
- Support internal and external compliance audits covering ISO 27001, ISO 22301, PCI DSS 4.0, SOC 2 Type II, and applicable internal requirements.
- Collect, organize, validate, and maintain audit evidence in coordination with control owners and relevant departments.
- Perform scheduled compliance checks using approved procedures, checklists, and control requirements.
- Document observations, audit findings, and potential control gaps accurately and escalate them to the Senior Team Lead.
- Track corrective actions and follow up with assigned owners to support timely closure.
Compliance Records and Documentation
- Maintain complete, accurate, and current records of compliance activities, requests, assessments, and supporting evidence.
- Apply document control requirements, including approved naming conventions, version control, retention, and access restrictions.
- Prepare status reports, trackers, and supporting materials for audits, management reviews, and compliance meetings.
- Protect confidential and sensitive information in accordance with company policies and applicable requirements.
Policy and Procedure Support
- Assist in drafting, reviewing, formatting, publishing, and updating compliance policies, procedures, and related guidance.
- Coordinate reviews and approvals with document owners and maintain records of required acknowledgements.
- Support policy communication, awareness activities, and monitoring of employee adoption.
Compliance Request Processing
- Review customer and internal requests for completeness against established policies, procedures, and compliance criteria.
- Process requests within assigned authority and service-level targets while maintaining an accurate audit trail.
- Refer incomplete, non-compliant, unusual, or high-risk requests to the Senior Team Lead or appropriate risk owner for decision.
Risk Governance Support
- Support risk assessment activities for new-client onboarding in coordination with Client Services and relevant departments.
- Assist risk owners in identifying operational, information security, compliance, and client-specific risks.
- Gather information needed to assess impact and likelihood using approved risk criteria and the organization's risk appetite.
- Document risk treatment decisions, action owners, timelines, and success criteria in the appropriate risk register or tracker.
- Monitor risk treatment action plans, follow up on overdue items, and escalate gaps or delays.
- Maintain evidence of implemented controls and support reviews of control effectiveness.
Integrated Management System Support
- Support the implementation, maintenance, monitoring, and continual improvement of the Integrated Management System.
- Coordinate information and action items with stakeholders for SWOT analysis, stakeholder analysis, risk assessments, and management reviews.
- Assist with business impact analysis activities that support business continuity and operational resilience.
- Track objectives, targets, and programs and help prepare progress updates for the Compliance team.
- Maintain IMS records and supporting documentation in a state of audit readiness.
Stakeholder Coordination and Continuous Improvement
- Coordinate with departments and control owners to obtain required information, evidence, approvals, and action updates.
- Respond to routine compliance questions within established guidance and refer matters requiring interpretation or approval.
- Identify recurring documentation or process issues and recommend practical improvements to the Senior Team Lead.
- Participate in compliance training, awareness sessions, team meetings, and improvement initiatives.
Qualification Requirements:
Education:
- Bachelor's degree in Industrial Engineering, Computer Engineering, Information Technology, Business Administration, Accounting, or a related field; equivalent relevant experience may be considered.
Experience:
- One to two years of experience in compliance, internal audit, information security, risk management, quality management, document control, or a related function is preferred.
- Exposure to audit preparation, evidence collection, policy administration, risk registers, or corrective-action tracking is preferred.
- Familiarity with one or more of the following is an advantage: ISO 27001, PCI DSS 4.0, SOC 2 Type II, HIPAA/HITRUST or an Integrated Management System.
- Relevant internship experience may be considered for candidates with strong analytical, documentation, and coordination skills.
Knowledge and Skills:
- Basic understanding of compliance, audit, risk management, information security, or quality management principles.
- Strong attention to detail and the ability to maintain accurate, well-organized records and evidence.
- Effective written and verbal communication skills, including the ability to follow up professionally with stakeholders.
- Analytical and problem-solving skills, with the judgement to recognize and escalate potential compliance risks.
- Ability to manage multiple tasks, meet deadlines, and work effectively with limited supervision after receiving guidance.
- Proficiency in Microsoft Office or comparable productivity tools; experience with document repositories, ticketing systems, or governance, risk, and compliance tools is an advantage.
- Commitment to confidentiality, integrity, accountability, and continuous learning.
More Info
Key Skills
audit preparation
PCI DSS 4.0
SOC 2 Type II
Integrated Management System
