I
am writing to express my interest in the ERM position at your organization as
mentioned during our discussion offline and over the call. My name is
Hotel and Restaurant Service Technology from the Philippines and over eight
years of diverse experience in risk management, information security, and
consulting, I am excited about the opportunity to leverage my skills and
knowledge in your organization
My
career began as a call center agent in a business process outsourcing company,
where I quickly transitioned into Risk Management and Compliance (RMAC), and
then to Enterprise Risk Management (ERM). As part of a pioneering team in the
Philippines, I played an integral role in implementing and refining ERM
functions across multiple sectors and locations, particularly in health,
medical, and pharmaceutical lines of business. In 2019, I advanced to lead
operations at one of our major locations in Manila, overseeing three sites
across consumer and telecommunications. I managed and facilitated extensive audits,
including ISO 27001, SOC 1 and 2 audits, SSAE, and PCI DSS, among others. As a
Line of Business (LOB) and Site Risk Lead, I am required to report any updates
and open risks to senior management, as well as the current plans for
mitigating each risk.
During
my time in ERM, I was distinguished as a Top Performing Employee and received
an Excellence Award from our head of ERM. I spearheaded security i
management, business continuity planning (BCP) where I led in its
implementation, migration and update in line with the ISO22301 requirements and
facilitated BCP reviews and testing ensuring that an organization can maintain
critical functions during adverse events and minimize the impact on operations,
reputation, and bottom line, and various data privacy assessments.
Additionally, I obtained my certification as an ISO 27001 Lead Auditor and
completed numerous advanced training sessions in data privacy, cloud security,
and business continuity planning.
After
eight years with ERM, I joined SGV-EY Philippines in 2022 to fulfill my
ambition of becoming part of one of the Big Four audit firms. In my role within
Technology Consulting, I managed data privacy and third-party risk assessments,
transitioning from an enterprise-wide focus at Wipro to more targeted client
engagements at EY. This experience enhanced my leadership capabilities as I
coordinated teams, delivered client presentations, and conducted performance
evaluations for associates.
Currently,
I serve as an Information Security Officer in the Information Security Division
at Metrobank. Here, I assess and approve applications related to IT
infrastructure, engage with multiple stakeholders, and manage critical
functions such as data privacy, access control, and governance. My role demands
a strong adherence to regulatory standards and requires me to navigate complex
vendor relationships, ensuring data security while fostering open communication
and collaboration.
I
am enthusiastic about the possibility of contributing to your organization and
furthering the alignment of IT initiatives with business objectives. I believe
my background in risk management, business continuity combined with my
dedication to maintaining data security will be an asset to your team.
Thank
you for considering my application. I am looking forward to the opportunity to
further discuss how my skills and experiences align with the needs of your
team.
Onlinejobs.ph "ID Proof" indicates if "they are who they say they are".
It DOES NOT indicate skill level.
ID Proof scores are 0 - 99 with 99 being the best. It is calculated based on dozens of data points.
It's intended to help employers know who they're talking to is real, and not a fake identity.