Staff GRC Specialist, APAC
On-siteShanghai, Shanghai, China
Job Summary
Act as the regional anchor for the security compliance team, managing implementation and monitoring of security controls while integrating with the global effort. Serve as a trusted contact for regulatory bodies, customers, partners, and vendors to control external perceptions of enterprise security. Develop and maintain security documentation, including standards, policies, reporting metrics, and evidence artifacts for internal and external stakeholders. Implement AI and automation to streamline everyday compliance work, reporting, and communications. Execute necessary security tasks in your designated region with autonomy, balancing traditional regulatory requirements with innovative industry norms. This role supports individual regional entities and the greater global team, anchoring a geographic hub for the Information Security function.
Required Qualifications
- Deep knowledge of relevant compliance, regulatory and control frameworks such as PCI-DSS, ISO 27001, SOC2 and similar standards
- A strong familiarity with Information Security concepts, practices, and solutions
- Working knowledge of policy creation and maintenance, especially in the context of security
- A working understanding of complex cloud environments and the way they impact modern security and compliance operations
- An understanding of financial services or payments, especially prior work experience with the fintech industry
Desired Qualifications
- 6+ years of cybersecurity experience
- Proven experience working and executing independently
- Experience working in the fintech industry specifically
- An industry-leading security degree or certification is a great benefit. Examples include a BS or MS in Cybersecurity; or a CISSP, CEH, CISA, etc.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.