Назад
Company hidden
12 часов назад

IT Risk and Security Compliance Specialist

Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Malaysia/China
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT Risk and Security Compliance Specialist (GRC/ISO 27001): Owning continuous compliance automation, external audit pipelines, SaaS vendor risk, and enterprise security reviews with an accent on ISO 27001, GDPR, SOC 2 Type 2 readiness, and evidence automation. Focus on translating security controls into actionable engineering issues, monitoring compliance drift, managing audit remediation, and coordinating incident-related regulatory reporting.

Location: Kuala Lumpur, Malaysia. Flexible working environment and working hours are mentioned.

Company

hirify.global is an AI-powered business messaging platform for managing customer conversations across chat, calls, and email.

What you will do

  • Own, scale, and optimize the continuous compliance automation platform.
  • Orchestrate automated evidence collection, control validation, policy-to-framework mapping, and endpoint compliance monitoring.
  • Monitor compliance drift alerts, eliminate false positives, and route clearly scoped remediation issues into engineering backlogs via Linear.
  • Lead ISO 27001 and GDPR audits end to end and own the SOC 2 Type 2 readiness window.
  • Manage SaaS security vetting, Data Privacy Impact Assessments, vendor risk registers, and governance policies.
  • Coordinate regulatory incident response activities, including breach disclosure tracking, post-mortems, and external compliance reporting.

Requirements

  • 3–5+ years of experience in GRC or security compliance roles.
  • Proven experience implementing and maintaining ISO 27001 and GDPR requirements and managing SOC 2 Type 2 audit readiness.
  • Hands-on experience administering API-driven compliance platforms such as Sprinto, Drata, or Vanta.
  • Technical fluency with microservices, AWS IAM, GitHub Actions, CI/CD, SSO, and MFA.
  • Experience managing external auditors, evidence delivery, findings remediation, and cross-functional stakeholders.
  • Clear written and spoken English, with the ability to work with auditors, enterprise security teams, and backend engineers.

Nice to have

  • ISO 27001 Lead Auditor or Lead Implementer, CISA, CRISC, or CISSP certification.
  • Experience with compliance platform migration and AI-driven compliance tooling.

Culture & Benefits

  • Collaborative, direct, and ownership-oriented working culture.
  • Flexible working environment and working hours.
  • Virtual team events and online social activities.
  • Competitive compensation package.
  • Mental health allowance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →