Hiring.Camp

IT Risk and Security Compliance Specialist

Respond.io

·

2 weeks ago

Location
Kuala Lumpur, MY
Type
Full-time
Department
Legal
Education
Master
Clearance
Required
Source
Breezy HR

Description

Location: Kuala Lumpur, Malaysia

Role:IT Risk and Security Compliance Specialist

Department: Backend

About Respond.io

Founded in Hong Kong in early 2017, respond.io is an AI-powered business messaging platform that helps companies manage customer conversations across chat, calls and email — all in one place.

Trusted by businesses in over 127 countries and recognized by G2 and SME100, respond.io enables fast-growing companies around the world to capture, convert, and retain customers at scale.

We operate as a globally distributed team with employees based around the world, contributing to a diverse and inclusive culture. Join us, and be part of a team that is shaping the future of customer conversation management!

Our Culture

At respond.io, we move fast, work smart, and always keep our customers at the heart of what we do. Here’s what we stand for:

  • Solve Customer Problems: Every effort must solve real customer pain points. No guesswork—just real feedback and clear value!
  • The 80/20 Rule: We focus on 20% of actions that create 80% of the value. Simple is powerful—it gets us moving fast.
  • 100% Alignment, 80% Accuracy: We aim 100% team alignment and 80% accuracy. Perfect plans can wait—clear goals come first.
  • Be Direct: We give honest feedback, and tackle problems head-on. Clarity moves us forward!
  • Own It and Support Each Other: We step up, help out, and drive outcomes—together.
  • Build Human Connections: Work is better when we trust, care, and celebrate wins together. We’re a team!

Role Description

At respond.io, compliance is an engineering discipline, not a paperwork exercise. We are hiring a IT Risk and Security Compliance Specialist to own our governance layer end to end: our continuous compliance platform, our external audit pipeline (ISO 27001, GDPR), SaaS vendor risk, and enterprise customer trust. You will be the control owner and the primary audit subject for our security certifications, and the translator who turns abstract framework controls into requirements our engineers can implement without confusion.

What You Will Be Doing

Continuous Compliance Architecture

  • Own, scale, and optimize our compliance automation platform.
  • Orchestrate automated evidence collection, control validation, and policy-to-framework mapping so evidence holds up in audit without manual scrambles.
  • Continuously verify endpoint fleet compliance scores and drive them up over time.
  • Apply AI-driven tooling to automate compliance checks, control monitoring, evidence collection, and policy drafting.

Signal Routing & Operations

  • Monitor continuous compliance drift alerts; isolate and eliminate false positives so engineers only ever see real work.
  • Write tight, well-scoped remediation issues and route them into engineering backlogs via Linear, sized so a developer can pull one into a single cycle without clarification.
  • Track remediation milestones, identify blockers, and escalate early and clearly.

Governance & Enterprise Trust

  • Command our external audit pipeline: drive ISO 27001 and GDPR audits end to end (scoping, auditor management, evidence delivery, findings remediation, retest) and own our multi-month SOC 2 Type 2 readiness window.
  • Act as the control owner and main audit subject for our technology controls.
  • Serve as the technical expert behind enterprise customer security questionnaires and due-diligence reviews.
  • Run continuous security gap assessments against current and upcoming EU/US mandates to keep us ahead of regulation, not behind it.

SaaS Vendor Risk Management

  • Gatekeep our third-party stack: run formal SaaS security vetting, perform Data Privacy Impact assessments on incoming vendors, and maintain the vendor risk register.
  • Author and maintain corporate governance and security policy definitions, and keep policies synchronized with enforced configuration (the policy-to-configuration handshake).

Security Incident Response

  • Act as the regulatory and communication anchor during incidents: breach disclosure tracking (e.g., GDPR 72-hour constraints), post-mortem logging, and external compliance reporting, in partnership with the technical responder.

Qualifications

  • 3-5+ years in GRC or security compliance roles, with a proven track record implementing and maintaining ISO 27001 and GDPR, and managing operational audit timelines for SOC 2 Type 2.
  • Compliance automation native: strong hands-on experience with API-driven platforms like Sprinto, Drata, or Vanta. You prefer live continuous evidence pipelines over manual screenshots, and you've administered one at scale (ideally including a platform migration).
  • Technical fluency: you don't need to write production code, but you must understand how modern microservice environments, AWS IAM, GitHub Actions, CI/CD, and identity layers (SSO/MFA) actually work, so your controls stay pragmatic and enforceable.
  • Audit management: experience running external auditors end to end, covering scoping, evidence, findings triage, remediation tracking, and cross-functional stakeholder engagement.
  • Masterful agile translator: the rare ability to read an abstract compliance control or rigorous enterprise requirement and turn it into a clear, actionable, well-scoped engineering issue.
  • Clear written and spoken English: able to hold your own with auditors, enterprise customers' security teams, and backend engineers alike.
  • Certifications such as ISO 27001 Lead Auditor/Implementer, CISA, CRISC, or CISSP.

What's in it for you

  • You will become part of an amazing culture with smart, collaborative teammates who actually care about each other's growth and success.
  • You will grow more here than you would anywhere else, that is a promise.
  • Virtual events like talent shows, Among Us nights, and online game sessions to keep the fun going, no matter where you are!
  • We offer a highly competitive compensation package.
  • You'll receive a mental health allowance to support your health and wellness needs.
  • Flexible working environment and working hours that fit your lifestyle, wherever you're based.

Skills

AWSCI/CDGitHubSOCRisk ManagementComplianceSOC 2GDPRISO 27001CISSP

Similar Jobs

30

Director, Cybersecurity and IT Risk Management

SourceAmerica · Vienna, VA

2 days ago

IT Risk and Security Engineer - Governance & Administration

Depository Trust Company · Hyderabad, India

2 days ago

Manager - IT Risk and Governance

Prudential · EIB | Kuala Lumpur - Menara Prudential 22/F (TRX), Malaysia

3 days ago

Sr. Lead, IT Risk and Controls – KRI Development, Metrics & Automation

NT Careers · Chicago, IL, United States of America · Hybrid

2 weeks ago

SSBI IT Governance, IT Risk and IT Outsourcing Vice President

Statestreet · Gdansk, Poland +1

1 month ago

IT Risk and Compliance Analyst

Greenberg Traurig · Miramar, United States of America · Hybrid

1 month ago

Director IT Risk and Security Management

Depository Trust Company · Tampa, FL, United States, US

1 month ago

Director IT Risk and Compliance

BJ’s Wholesale Club · BJ's Club Support Center Marlborough, MA #5997, United States of America

1 month ago

IT Risk and Controls Manager

Guidehouse is · Client Office: Springfield, VA, United States of America +1

2 months ago

Lead IT Risk and Security Engineer

Depository Trust Company · Jersey City, NJ, United States, US

3 months ago

Lead IT Risk and Security Engineer

Depository Trust Company · Jersey City, NJ, United States, US

3 months ago

IT Risk and Security Engineer

Depository Trust Company · Hyderabad, India

3 months ago

IT Governance, Risk and Compliance Specialist

Abaxx Technologies · Singapore, Singapore, Singapore

3 days ago

IT Governance, Risk and Control Specialist

Encore · West Malling - 1 Kings Hill, United Kingdom +1 · Remote

6 days ago

Principal IT Governance and Risk Consultant

Pseg · Bethpage, New York, US · Remote, Hybrid, Onsite

1 week ago

IT and Cybersecurity Risk Manager

Hrhub · Porto, Portugal · Onsite

3 weeks ago

IT GRC Risk and Automation Analyst

Logitech · Chennai, India +1 · Hybrid

3 weeks ago

Manager, IT Governance, Risk and Compliance

Petvalu · 0001 – Markham Office, Canada · Hybrid

1 month ago

Head of IT Governance, Risk, and Compliance (GRC)

"LabConnect, LLC" · Remote - US, 2304 Silverdale Drive, Johnson City, Tennessee, United States of America · Remote

1 month ago

IT Governance and Risk Assessment Officer

Global Water Solutions · Woking, United Kingdom

2 months ago

IT Governance and Risk Assessment Officer

Global Water Solutions · Boksburg Gauteng, South Africa, South Africa

2 months ago

IT and Cybersecurity Risk Manager

Hrhub · Paris, France

2 months ago

Manager - IT Governance, Risk and Compliance

Plexus · Neenah, WI,US, US

2 months ago

Deputy Head of Risk and Audit, IT

Citicclsa · Hong Kong - One Island East

2 months ago

Head IT Governance and Risk Asia

Juliusbaer · Singapore

4 months ago

Senior IT Governance, Risk, and Compliance Analyst - Research Cybersecurity

Euv Emory · Atlanta, GA, US

1+ year ago

Senior IT Governance, Risk, and Compliance Analyst - Research Cybersecurity

Staff Emory · Atlanta, GA, US

1+ year ago

IT Governance, Risk and Compliance Consultant (Contract Contingent)

ProSidian Consulting · Arlington, VA, United States

1+ year ago

Manager, IT Security, Governance, Risk and Compliance

Burlington · 00505 - Edgewater Park Corporate Office, United States of America · Hybrid

5 months ago

Governance, Risk, and Compliance Manager (IT)

Weaver · DALLAS, TX +2

6 months ago