Senior GRC Specialist, APAC
On-siteShanghai, Shanghai, China
Job Summary
Anchor the regional security compliance team by serving as the primary contact for government and regulatory bodies, managing external perceptions of enterprise security. Design and implement security policies that balance regional standards with global industry norms while executing necessary security controls and monitoring activities. Develop and maintain comprehensive documentation, including standards, policies, reporting metrics, and evidence artifacts to support internal and external stakeholders. Leverage AI and automation to streamline everyday compliance work, reporting, and communications. Operate as an independent subject matter expert who iterates on compliance challenges rather than treating them as static checkboxes. This role supports individual regional entities and the global Information Security team, requiring a candidate with deep knowledge of frameworks like PCI-DSS, ISO 27001, and SOC2, ideally within the fintech industry. Based in Shanghai or Singapore.
Required Qualifications
- Deep knowledge of relevant compliance, regulatory and control frameworks such as PCI-DSS, ISO 27001, SOC2 and similar standards
- A strong familiarity with Information Security concepts, practices, and solutions
- Working knowledge of policy creation and maintenance, especially in the context of security
- A working understanding of complex cloud environments and the way they impact modern security and compliance operations
- An understanding of financial services or payments, especially prior work experience with the fintech industry
Desired Qualifications
- 4+ years of cybersecurity experience
- Proven experience working and executing independently
- Experience working in the fintech industry specifically
- An industry-leading security degree or certification
- Examples include a BS or MS in Cybersecurity
- A CISSP, CEH, CISA, etc.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.