Senior Governance, Risk, and Compliance (GRC) and Security Compliance Engineer
Doctor Anywhere- Posted 20 hours ago
- Be among the first 10 applicants
Job Description
About the role
Doctor Anywhere is one of Southeast Asia's largest technology-led healthcare companies. We run consumer telehealth, clinics, and integrations with insurers and payers across the region. Our platform holds patient data, so the standard we are held to by clients, partners and regulators is high, and it is rising.
We are rebuilding our governance, risk and compliance function around automation and evidence, and we are looking for a senior engineer-minded practitioner who will own it. You will inherit an ISO/IEC 27001 certified environment with a real policy library and a mature application security pipeline, and you will be given the mandate to modernise how compliance actually runs: a reusable answer library, AI-assisted first-draft responses with proper controls around them, and evidence pulled live from our cloud and identity systems instead of assembled by hand.
You will report to the Director of Security and Platform Engineering, and you will be the person the business relies on when an enterprise client, an insurance partner, an auditor or a regulator asks how we secure their data.
What you'll do
- Client trust response. Security questionnaires, RFP security sections, enterprise client audits and supplier due diligence. You will answer most technical questions yourself rather than relaying them to engineers.
- Compliance automation. Build the canonical answer library, own AI-assisted drafting with citation, confidence thresholds and mandatory human sign-off, and integrate read-only evidence collection from cloud, identity and network systems so evidence is generated rather than screenshotted.
- Certification and audit. Own the ISO/IEC 27001:2022 lifecycle end to end: scope, Statement of Applicability, internal audit programme, management review, external auditors and corrective action.
- Risk, policy and third party. Run the information security risk register as a decision-making tool, own the policy lifecycle and exception register, and assess the vendors and partners we integrate with.
- Incident response and regulatory notification. Own breach assessment and the notification decision across the jurisdictions we operate in, alongside Legal. In healthcare this is the highest consequence judgement in the role.
- Finding what is broken before someone else does. Go looking. Read the infrastructure code, pull the access review output, check that the alert a policy promises is actually configured. When you find a gap, bring it quantified, costed and sequenced.
What you'll bring
Must-haves
- 6 or more years in security governance, risk and compliance, including at least 2 years responding directly to enterprise or regulated clients.
- You have owned a certification or attestation, ISO/IEC 27001 or SOC 2, rather than supported one. You can describe the scope decisions you made, including one you would make differently.
- Real cloud fluency. You understand the architecture, its building components, and reason about what it exposes. You understand IAM, key management, network segmentation, logging and container security well enough to assess a control rather than describe it.
- Fluency with SIG, CAIQ, VSA or equivalent questionnaire frameworks, from the answering side.
- Technical credibility with engineers. You can disagree with a senior engineer about whether a control is effective, and be right often enough that they listen.
- An evidence-first instinct. Your default response to a control claim is to ask what proves it, and a policy document does not satisfy you.
- Written English strong enough to go to a client with light review.
- The judgement to say no to a client accurately, offer the compensating control, and keep the relationship intact.
Nice-to-haves
- Healthcare, insurance, payer or financial services background.
- Scripting or automation ability, Python or similar, comfortable with APIs. Not a requirement, but you will move considerably faster here with it.
- Hands-on with a compliance automation platform such as Vanta or Drata, including its limits.
- Practical experience applying AI tooling to compliance work, with the controls that responsible use requires.
- Privacy depth in Southeast Asia.
- Incident response experience where you made or advised a regulatory notification decision under time pressure.
- CISA, CISM, CRISC, ISO 27001 Lead Auditor or Lead Implementer, CIPP/A, CCSK or AWS Security Specialty.
And, whatever the role — our house DNA:
- A start-up attitude — you take full ownership of what you do, put the best tools (AI included) to work to move faster, and you're happy to step out of your comfort zone and take on new challenges.
- Comfortable with ambiguity and quick to learn — you experiment with AI to work smarter, not just harder, because we're not done growing, and heading into uncharted territory is part of the fun.
About Doctor Anywhere
Doctor Anywhere (DA) is a regional tech-enabled, omnichannel healthcare provider delivering care to 3 million users across 6 countries in Southeast Asia. Founded in 2017 with a mission to make healthcare simple, accessible, and efficient for all, DA leverages technology to enable individuals towards preventive, long-term health via holistic offerings — including our telehealth app, physical clinics and pharmacies, mental wellness, specialist consults, and an online health & wellness marketplace for supplements, healthy snacks, home-based health screening, and vaccinations.
DA's goal is to build a regional digital healthcare ecosystem, advanced by the 3,000 GPs and specialists within our regional network, over 1,500 corporate organisations, and 25 regional insurers we work with. Grounded in our motto Keep Going, Keep Growing, our team strives towards excellence, with innovation and collaboration at our core, and values the diversity of perspectives brought by every member. Join us in our mission to transform Southeast Asia's healthcare future!
Our values
Innovation is at the core of what we do and why we exist.
Our customers and patients are our number 1 priority.
We think and act positively and inspire others with our optimism.
We focus on becoming good to great and accomplishing more with less.
We do things right and do the right thing, knowing that the whole world is watching our actions.
We believe in being authentic and honest with one another, even if it makes us uncomfortable
We are committed to building a culture where everyone feels included and valued at work.
Your best career move, ever.
At Doctor Anywhere, we build for everyone — and we hire that way too. We welcome applicants of every background, and we know great people don't always tick every box. If this role excites you, we'd love to hear from you even if your experience doesn't line up perfectly. Not for you We have other opportunities that may interest you or someone you know. Visit our careers page — https://doctoranywhere.recruit.omnihr.co/careers — for more.





