Role Summary
We are looking for a hands-on Information Security & Compliance to design, implement, and own the security and compliance framework across EPOS's regional operations. This is an individual-contributor role for someone who has personally led an organization through certifications such as ISO 27001, PCI-DSS, or equivalent — not just studied them. You will work closely with Engineering, IT, and cross-country teams (Malaysia and Vietnam) to embed security and compliance into how the company builds and operates its product, and to prepare the organization for external audits and certification.
Key Responsibilities
- Certification & Standards Readiness: Lead end-to-end preparation for ISO 27001 (ISMS) and PCI-DSS certification — gap analysis, control implementation, documentation, internal audit, and coordination with external certification bodies/QSAs.
- Policy & Process Standardization: Design, document, and roll out information security policies, procedures, and controls that are practical for an engineering-driven SaaS organization, not just paper compliance.
- Risk Management: Run periodic risk assessments (technical and process-level), maintain a risk register, and drive remediation with Engineering/IT owners.
- IT Compliance & Audit: Support broader IT compliance needs beyond security — vendor/third-party risk reviews, access control audits, data handling reviews, and coordination with legal/regulatory requirements (e.g., PDPA Malaysia, relevant data protection regulations in other markets).
- Data Protection & Governance: Own data classification and handling policies; define rules for cross-border data transfer and residency between Malaysia and Vietnam; establish data retention/disposal standards; ensure third-party/vendor data processing agreements meet compliance requirements; align practices with PDPA (Malaysia), Decree 13/2023 (Vietnam), and GDPR where applicable for EU customers.
- Cross-Border Coordination: Act as the standardization point between Malaysia and Vietnam operations, ensuring consistent security/compliance practices across both engineering hubs.
- Technical Collaboration: Work directly with the CTO/Head of Engineering and engineering leads to assess system architecture, infrastructure, and application security posture relevant to certification scope.
- Security Awareness: Design and run training/awareness programs so security and compliance practices are understood and followed company-wide, not just by a central team.
- Incident Readiness: Establish incident response processes and playbooks aligned with certification requirements.
- Audit Liaison: Serve as the primary point of contact for external auditors, certification bodies, and customer security due-diligence requests.
What We're Looking For
- 5–8+ years of experience in information security, IT compliance, or GRC (Governance, Risk & Compliance) roles, ideally in a tech/SaaS or fintech-adjacent environment.
- Demonstrated hands-on experience having led an organization to achieve ISO 27001, PCI-DSS, or comparable certifications — this practical track record matters more than certificates held.
- Solid technical understanding of IT systems, cloud infrastructure, and application security fundamentals, sufficient to work directly with engineering teams.
- Experience building security/compliance programs from the ground up or standardizing them across multiple entities/countries.
- Strong stakeholder management skills — able to work cross-functionally with Engineering, Legal, HR, and external auditors.
- Fluent English (written and spoken) required; Mandarin Chinese is a strong plus given collaboration with Ant International-affiliated stakeholders.
- Relevant certifications (CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, PCI-DSS ISA/QSA) are a plus but not mandatory if practical experience is strong.