Data and Security Engineer (MY)
Data and Security Engineer (MY)
supermom business- Posted 15 hours ago
- Be among the first 10 applicants
Job Description
About Supermom And Why This Role Exists
Supermom connects modern mothers in Southeast Asia to parenting brands, powered by data and AI. Our community platform serves millions of mothers across Singapore, Malaysia and Indonesia. As we move to SM 3.0, a data and AI-first parenting intelligence platform, trust in how we handle mothers data becomes core to the product. A majority of revenue comes from data monetisation, including lead generation for brands, so privacy and security are commercial necessities, not back-office tasks. Data privacy, cybersecurity and compliance workstreams are crucial and this role is the internal owner who drives that work to completion, then keeps the controls running. You will work across our stack: V2 (B2C website, customer database, marketing automation), BigQuery on Google Cloud, Meiro CDP (segmentation and activation across paid ads, WhatsApp and email), HubSpot (B2B CRM) and Xero (finance).
Ongoing Responsibilities
After the mandate, you own the controls that keep Supermom compliant and secure as SM 3.0 scales.
Security Engineering
This is an engineering role, not a legal one: you own the facts, the systems and the delivery, while outside counsel owns legal conclusions.
You lead
We need someone who has already taken a scale-up through a security and privacy programme, and can do the hands-on work themselves.
Must have
Supermom connects modern mothers in Southeast Asia to parenting brands, powered by data and AI. Our community platform serves millions of mothers across Singapore, Malaysia and Indonesia. As we move to SM 3.0, a data and AI-first parenting intelligence platform, trust in how we handle mothers data becomes core to the product. A majority of revenue comes from data monetisation, including lead generation for brands, so privacy and security are commercial necessities, not back-office tasks. Data privacy, cybersecurity and compliance workstreams are crucial and this role is the internal owner who drives that work to completion, then keeps the controls running. You will work across our stack: V2 (B2C website, customer database, marketing automation), BigQuery on Google Cloud, Meiro CDP (segmentation and activation across paid ads, WhatsApp and email), HubSpot (B2B CRM) and Xero (finance).
Ongoing Responsibilities
After the mandate, you own the controls that keep Supermom compliant and secure as SM 3.0 scales.
Security Engineering
- Run identity and access management across Google Cloud, BigQuery, V2, Meiro, HubSpot and Xero: least privilege, SSO and MFA, joiner-mover-leaver reviews each quarter.
- Maintain logging, monitoring and alerting; own the incident response plan and run a tabletop exercise at least twice a year.
- Manage vulnerability scanning, patching SLAs and an annual external penetration test.
- Review security of new vendors, integrations and AI features, including AIMA, before launch.
- Keep the data map and record of processing current as products change.
- Build privacy by design into V2 and BigQuery: consent flags that flow through to Meiro activation, retention and deletion jobs, pseudonymisation of analytics tables.
- Handle data subject requests (access, correction, deletion, withdrawal of consent) within statutory timelines.
- Run data protection impact assessments for new data products, lead-generation formats and Pulse offerings.
- Own breach assessment and notification readiness for each market's regulator.
- Design and maintain secure BigQuery pipelines, with column-level access controls and masking of personal data.
- Ensure data shared with brand clients is aggregated or covered by a valid consent and contract, in line with our rule that personal data is never exposed beyond its permitted use.
- Document data lineage from collection in V2 to activation in Meiro and reporting in BigQuery.
- Keep the third-party register and DPAs current; re-vet key partners each year with outside counsel.
- Monitor the KOM reward programme against the agreed design and flag changes that could reintroduce regulatory risk.
- Train staff each year on data handling, phishing and security basics, with extra sessions for sales and community teams.
This is an engineering role, not a legal one: you own the facts, the systems and the delivery, while outside counsel owns legal conclusions.
You lead
- Security audit, risk register, remediation - Scoping, execution, remediation plan
- End to end data map, record of processing, consent tooling
- Legal applicability and gap assessment - Technical facts and remediation
- Privacy policy and client templates - Technical inputs, implementation
- KOM reward programme - Programme documentation, system changes
- Employee data - Systems and access mapping
- Cyber insurance - Risk profile and control evidence
- Counsel selection - Criteria, briefing pack, onboarding
We need someone who has already taken a scale-up through a security and privacy programme, and can do the hands-on work themselves.
Must have
- 10+ years in security engineering, data engineering or privacy engineering, with at least 2 years owning a compliance programme end to end.
- Hands-on Google Cloud security and BigQuery experience: IAM, VPC controls, logging, data access policies and masking.
- Has run a security risk assessment and remediation plan against a recognised framework (ISO/IEC 27001, SOC 2, NIST CSF or CIS Controls).
- Working knowledge of Singapore's PDPA and at least one of Malaysia's PDPA or Indonesia's PDP Law, including consent, cross-border transfer and breach notification rules.
- Has built data inventories, records of processing and DPIAs, and worked alongside external counsel.
- Experience with SaaS vendor risk: DPAs, security questionnaires, sub-processor reviews.
- Clear written English; able to report progress to a Board and investor. Bahasa Malaysia or Bahasa Indonesia is a plus.
- Certifications such as CISSP, CISM, CIPP/A, CIPM, CIPT or Google Professional Cloud Security Engineer.
- Experience with CDPs (Meiro or similar), marketing automation and consent management platforms.
- Exposure to rewards, loyalty or creator payment programmes and the stored value or e-money rules around them.
- Background in a consumer platform, adtech, or a data business serving brands.
- Experience preparing a company for ISO 27001 or SOC 2 certification.
More Info
Job Type:
Industry:
Employment Type:
Key Skills
records of processing
data inventories
security questionnaires
NIST CSF
CIS Controls
SOC 2
remediation plan
VPC controls
data access policies
DPIAs
SaaS vendor risk
sub-processor reviews
ISO IEC 27001
security risk assessment
DPAs
