GRC Specialist (Compliance)
On-siteBangkok, Bangkok, Thailand
Job Summary
Manage the end-to-end evidence collection lifecycle for ISO 27001, PDPA, and PCI-DSS by defining requirements, assigning tasks to control owners, and organizing repositories. Coordinate internal and external audit schedules, prepare interview materials, and produce dashboards providing instant visibility into compliance health. Track remediation actions from audit findings to verified closure, conduct control validation testing, and maintain the security exception register. Support vendor compliance assessments and collaborate with IT teams on control implementation. Maintain comprehensive documentation including audit reports, finding responses, and regulatory correspondence.
Required Qualifications
- 4+ years in information security, IT audit, or compliance operations
- Hands-on experience with audit evidence management — you've collected, organised, and presented evidence to external auditors
- Working knowledge of ISO 27001 controls and audit processes — you understand what auditors look for and how to prepare for assessments
- Strong project management and tracking skills — ability to manage multiple concurrent compliance workstreams with different deadlines
- Excellent attention to detail and organisational skills — you can manage hundreds of evidence items across multiple frameworks without dropping anything
- Fluent in Thai; reading English proficiency for compliance frameworks and documentation
Desired Qualifications
- ISO 27001 Internal Auditor certification or equivalent
- Experience with PDPA compliance operations or PCI-DSS evidence management
- Familiarity with GRC tools (ServiceNow GRC, OneTrust, or similar) for automating evidence collection and tracking
- Background in IT audit (Big Four or internal audit function) — understanding audit methodology and expectations
- Experience building compliance dashboards or automated reporting
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.