Information Risk Manager for Business Continuity and Disaster Recovery

apartmentManulife placeQuezon City scheduleFull-time calendar_month 

Global Information Risk Management (GIRM) is an independent risk function that provides risk and controls guidance to a variety of stakeholders that information risks are appropriately managed and in alignment with risk appetite. GIRM is responsible for providing independent oversight of policies, procedures and standards concerning the measurement, monitoring, control and reporting of information risks.

Manulife is seeking an Information Risk Manager for Business Continuity and Disaster Recovery to lead the execution of independent second‑line challenge and oversight activities across technology, data, and operational risk. This role provides expert-level analysis, challenge, and governance scrutiny to ensure first‑line risk practices meet Manulife’s risk appetite, standards, and regulatory expectations.

Position Responsibilities:

  • Provide independent second line challenge of first line risk assessments, controls, and risk decisions.
  • Assess adequacy of technology, data, and operational risk practices against standards and regulatory expectations.
  • Develop clear, evidence‑based second line risk opinions and escalate material issues with recommendations.
  • Perform deep‑dive RCSA reviews and challenge risk ratings, control assertions, and completeness of assessments.
  • Identify underassessed risks, weak controls, and cross‑assessment inconsistencies.
  • Review major technology initiatives and platform changes for risk impacts and sufficiency of mitigation plans.
  • Evaluate risks associated with architecture changes, new solutions, and implementation activities.
  • Review incidents, classifications, RCA quality, and recurrence prevention measures.
  • Assess and challenge risk acceptances and corrective action plans for feasibility and urgency.
  • Validate CAP closure evidence as part of second line review.
  • Review business continuity plans, DR test results, and resilience capabilities, challenging gaps and assumptions.

Required Qualifications:

  • 3 to 5 years of experience in Information Risk, Technology Risk, or Cyber Risk
  • In-depth knowledge in information systems architecture, infrastructure and application recovery, and DR testing methodologies.
  • Experience in Business Continuity and Disaster Recovery, and operational risk assessment tools such as RCSA, Incidents and Losses, Root Cause Analysis, Scenario Analysis
  • Experience performing independent second‑line oversight or audit-style review activities.
  • Strong understanding of technology, data, cloud, infrastructure, and operational resilience risks.
  • Ability to evaluate complex risk scenarios and form well‑supported second‑line opinions.
  • Familiarity with GRC platforms such as Archer, ServiceNow, or Fusion.
  • Knowledge of regulatory frameworks and standards (ISO, NIST, COBIT, CSA/CCM, OSFI, etc.).
  • Exposure to Generative AI, Agentic AI, automation tools, or continuous monitoring technologies.

When you join our team:

  • We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.
placeTaguig, 15 km from Quezon City
Develop and implement business continuity plans to ensure operational resilience across all sites.  •  Conduct comprehensive risk assessments and business impact analyses (BIA).  •  Manage crisis situations by leading response efforts and ensuring...
apartmentDSV International Shared Services Inc.placeParañaque, 18 km from Quezon City
preferable both on-premises and Cloud (SaaS, PaaS)  •  Practical experiences and knowledge of business continuity, disaster recovery tests, and continuous improvements  •  Knowledge of IT Governance like COBIT, and IT Security like ISO27001 is an advantage...
business_centerHigh salary

Information technology officer

placeLas Piñas, 23 km from Quezon City
on security incidents, system vulnerabilities, and mitigation actions  11.  Collaborate with IT, HR, and other departments to safeguard sensitive information and ensure business continuity  12.  Participate in disaster recovery and business continuity planning...