- Establish and maintain the security and privacy compliance framework for the regions in scope: conduct risk assessment and drive gap remediation for newly launched markets, and monitor regulatory developments related to cyber security, data security and AI security.
- Serve as the cloud platform's interface with local regulators, supporting regulatory audits and security inspections as well as inquiries from the regulators.
- Maintain and expand the security certifications required for market entry, prioritising new certifications based on commercial value and urgency.
- Act as the primary contact for enterprise customer requests related to security compliance and privacy, delivering compliance support that covers vendor due diligence, contract security clause review, audit requests and customer meetings, maintaining customer-facing compliance materials for the region, and developing compliance solutions based on customers' requirements.
- Lead independent assessments with reference to the industry standards and guidelines of regulated sectors, e.g. financial services, public sector, and support key customers through cloud adoption.
Job Requirements
- Bachelor's degree in information security, computer science or a related field, or equivalent practical experience.
- 8+ years of experience in security compliance, data compliance, technology risk or compliance advisory, with working knowledge of data protection legislation and cross-border data transfer requirements; experience gained in a Big 4 firm, or in the IT audit or technology risk function of a financial institution, is preferred.
- Experience building compliance frameworks based on local laws and regulations and driving the remediation of identified gaps through to closure.
- Experience leading independent assessments against financial services supervisory requirements, including regulatory filings for cloud adoption.
- Experience engaging regulators and enterprise customers directly as the accountable compliance representative.
- Experience with mainstream AI governance and compliance frameworks.
- Experience obtaining or implementing recognised security certifications and frameworks for cloud services, such as ISO 27001, NIST CSF and SOC 2.
- Professional fluency in English and Cantonese, both written and spoken. Working proficiency in Arabic, Spanish or Portuguese is a plus.
- Experience managing multiple workstreams and setting priorities in a fast-moving, multi-market environment.