Sr. Enterprise Risk Management Specialist
Job Description:
- Develop and refine ERM frameworks based on ISO 31000, COSO ERM, and other standards
- Conduct risk assessments, create mitigation plans, and evaluate control effectiveness
- Lead Risk and Control Self-Assessments (RCSAs) and operational risk monitoring
- Identify and analyze enterprise risks using scenario analysis and key risk indicators (KRIs)
- Align risk appetite with strategic objectives and design appropriate control measures
- Apply ISO 9001, ISO 27001, ISO 22301, and related standards to risk management processes
- Facilitate integration of ISO systems for quality, information security, and business continuity
- Ensure compliance with regulations (e.g., DOLE, DENR, DICT) and prepare compliance reports
- Maintain risk registers and provide governance updates
- Support business continuity planning and crisis response strategies
- Conduct workshops and simulations to improve incident readiness
- Analyze risk data and create visual reports using Power BI, Excel, and Tableau
- Generate dashboards and comprehensive reports for internal stakeholders
- Use Lean, Six Sigma, and Root Cause Analysis (RCA) to improve risk processes
- Lead initiatives to address inefficiencies and enhance operations
- Collaborate with departments and senior leaders to align risk efforts with organizational goals
- Communicate risk strategies clearly across all levels of the organization
- Perform additional duties as assigned to support departmental and organizational objectives
Job Requirements:
- Bachelor’s degree in Risk Management, Business Administration, Information Technology, Engineering, or related field
- 4–6 years of relevant experience, preferably in ICT or related industries.
- Strong background in ERM execution and compliance monitoring (can be aligned with the VITRO JD if intended for broader consistency).
- Familiarity with ISO 9001, ISO 31000, ISO 22301, COSO ERM frameworks.
- Internal audit background is an advantage.
- Proficiency in MS Office (Excel, PowerPoint, Word).
- Strong report writing and facilitation skills.
- Associate Professional in ERM (APERM) or equivalent ERM-related certification.