About the Role
Raphie is hiring an IT, Risk and Compliance Senior Manager to directly own IT infrastructure and security, data privacy and compliance programs, regulatory administration (PAGCOR and other applicable regulators), and enterprise risk reporting for our Manila operations. This is a hands-on, individual contributor role; the Senior Manager title reflects the seniority and end-to-end ownership of the position, not a people-management mandate. You will build and run the function yourself, working directly with executive leadership, auditors, vendors, and regulators, and will grow a team under you as scope and headcount justify it.
Key Responsibilities
IT & Cybersecurity
- Oversee IT infrastructure, endpoints, identity and access management, and incident response for the Manila operation.
- Set priorities and service expectations across employee technology, IT support, networks, and infrastructure.
- Establish processes for employee onboarding/offboarding, access administration, asset management, and cybersecurity controls.
- Oversee the coordination of IT incidents, vulnerabilities, service issues, and operational risks.
- Manage key IT and cybersecurity vendors, budgets, contracts, renewals, and improvement initiatives.
- Provide executive leadership with clear reporting on IT performance, material risks, and investment priorities.
Compliance, Privacy & Customer Assurance
- Own and maintain the SOC 2 Type II compliance program, including audits, policies, evidence, employee training, and access reviews.
- Coordinate GDPR and broader data-privacy obligations with internal stakeholders, legal counsel, and external specialists.
- Own customer security questionnaires, RFP responses, procurement reviews, and related security diligence.
- Ensure compliance findings, customer requirements, and remediation activities are assigned, tracked, and completed.
- Develop consistent, reusable documentation that supports efficient customer and audit responses.
Regulatory Administration & Enterprise Risk
- Administer the company's regulatory licenses and obligations — including PAGCOR and other applicable gaming, data-privacy, and financial-crime regulators — covering submissions, filings, renewals, and supporting documentation.
- Identify which regulatory bodies apply to the business beyond PAGCOR (e.g., the National Privacy Commission for data privacy, AMLC for anti-money-laundering obligations, and any regulators in other jurisdictions the company operates in) and maintain a current view of obligations under each.
- Serve as the primary point of contact for PAGCOR and other relevant regulators, and coordinate required information across the business and with external advisers.
- Identify, assess, and report material company-wide risks — operational, regulatory, technology, cybersecurity, and vendor — to executive leadership.
- Maintain a risk register with clear owners, mitigation plans, and timelines for significant risks.
- Support business-continuity planning and coordination of significant company-wide incidents.
Team Building & Growth
- As the function scales, hire, onboard, and lead direct reports across IT and/or compliance disciplines.
- Establish repeatable processes and documentation that support delegation as headcount grows.
Qualifications
- 5+ years of experience in IT operations and/or security, with meaningful exposure to compliance or regulatory work (or an equivalent combination of experience).
- SOC 2 Type II Certified and Hands-on experience GDPR compliance frameworks.
- Experience in a regulated industry (gaming, financial services, or BPO); direct experience with PAGCOR, other gaming regulators, data-privacy authorities (e.g., NPC), or AML regulators (e.g., AMLC) is a strong plus.
- Comfortable operating as a solo individual contributor — building process from scratch — with the ambition and capability to grow into a people-leader role.
- Strong written and verbal communication skills; able to work directly and credibly with executive leadership, external auditors, and regulators.