Search Jobs

Search by job, company or skills

Compliance Implementation Associate, Senior Team Lead-Cebu

Compliance Implementation Associate, Senior Team Lead-Cebu

Iqor
  • Posted 7 hours ago
  • Be among the first 10 applicants

Job Description

Job Overview

The Compliance Implementation Associate – Senior Team Lead leads the day-to-day delivery of compliance, audit, risk governance, regulatory documentation, and Integrated Management System (IMS) activities. The role supervises Compliance Implementation Associates and Implementation Auditors and serves as the Lead Implementation Auditor for the organization's audit program.

The position is responsible for audit readiness, control effectiveness, corrective actions, and compliance with ISO 27001, ISO 22301, HIPAA/HITRUST, PCI DSS 4.0, SOC 2 Type II, and applicable internal, regulatory, and contractual requirements.

Key Responsibilities

Team Leadership

  • Lead, coach, and supervise Compliance Implementation Associates and Implementation Auditors.
  • Assign priorities, delegate work, manage workloads, and monitor quality and deadlines.
  • Provide technical guidance on compliance, audit, evidence management, risk documentation, and stakeholder coordination.
  • Review team outputs for accuracy, completeness, and compliance.

Audit Program Management

  • Serve as Lead Implementation Auditor and oversee audit planning, execution, reporting, follow-up, and continual improvement.
  • Develop and manage risk-based audit plans, scopes, schedules, checklists, sampling, and resource assignments.
  • Lead or oversee audits covering ISO 27001, ISO 22301, HIPAA/HITRUST, PCI DSS, SOC 2 Type II, internal policies, and applicable requirements.
  • Evaluate control design, implementation, and operating effectiveness.
  • Review audit evidence, working papers, findings, and reports before issuance.
  • Present significant findings, risks, and recommendations to management.

Nonconformance & Corrective Actions

  • Review and approve audit findings, nonconformities, observations, and improvement opportunities.
  • Evaluate root cause analyses and corrective action plans.
  • Monitor remediation progress and validate effectiveness before closure.
  • Escalate overdue, recurring, ineffective, or high-risk actions.

Compliance & Document Management

  • Ensure compliance records, audit evidence, assessments, and approvals are complete, accurate, current, and retrievable.
  • Maintain document control, including ownership, versioning, retention, access, and approvals.
  • Prepare compliance dashboards, audit updates, and management reports.
  • Develop and maintain compliance policies, procedures, standards, and related guidance.

Compliance Request Review

  • Oversee compliance reviews of customer and internal requests.
  • Evaluate escalated requests against policies, procedures, contractual obligations, and compliance requirements.
  • Approve, reject, return, or escalate requests within delegated authority.
  • Monitor request volumes, service levels, and recurring compliance issues.

Risk Governance & IMS

  • Facilitate risk assessments for new clients and organizational initiatives.
  • Coordinate with risk owners to identify, assess, treat, and monitor operational and information security risks.
  • Track risk treatment plans, mitigation activities, and control effectiveness.
  • Support the implementation, maintenance, and continual improvement of the IMS.
  • Assist with SWOT analysis, stakeholder analysis, business impact analysis, risk assessments, and organizational objectives, targets, and programs (OTP).
  • Maintain risk and IMS evidence for audits and management reviews.

Stakeholder Engagement & Continuous Improvement

  • Act as a key contact for assigned compliance implementation activities.
  • Coordinate deliverables across departments and provide practical compliance guidance.
  • Identify recurring control, documentation, and process gaps and lead improvement initiatives.
  • Support compliance training, awareness, and communication activities.
  • Escalate significant legal, regulatory, compliance, or risk matters appropriately.

Qualifications

Education

  • Bachelor's degree in Industrial Engineering, Computer Engineering, IT, Administration, Compliance, Information Security, Risk Management, Quality Management, or a related field; equivalent experience may be considered.

Experience

  • 3–5 years of relevant experience in compliance, internal audit, management systems, information security, risk management, quality management, or related functions.
  • Experience leading or supervising audit/compliance teams.
  • Hands-on experience across the audit lifecycle, including planning, fieldwork, evidence collection, reporting, findings, corrective actions, and closure.
  • Experience with ISO implementation, internal audits, readiness assessments, and risk management.
  • Experience coordinating with process owners, management, auditors, and cross-functional stakeholders.

Knowledge & Skills

  • Strong knowledge of audit principles and the audit lifecycle, preferably aligned with ISO 19011.
  • Working knowledge of ISO 27001 and ISO 22301.
  • Understanding of PCI DSS, SOC 2 Type II, HIPAA/HITRUST, and applicable regulatory and contractual requirements.
  • Ability to integrate multiple compliance and management system requirements into an IMS framework.
  • Strong analytical, problem-solving, risk assessment, and control evaluation skills.
  • Ability to evaluate root cause analyses, corrective actions, and remediation evidence.
  • Strong written and verbal communication skills.
  • Strong judgment, organization, stakeholder management, and ability to manage multiple priorities.

Certifications

  • ISO Lead Auditor or Lead Implementer certification (ISO 27001, ISO 22301, ISO 9001, or similar) strongly preferred.
  • CISA, CRISC, CISSP, CBCP, or PCI DSS-related certifications are an advantage.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

About Company

Similar Jobs

1-3 yrs
Philippines, Central Visayas
Skills:
Iso 27001Microsoft OfficeHipaarisk managementHITRUSTaudit preparationPCI DSS 4.0SOC 2 Type IIDocument ControlIntegrated Management System