Compliance Engineer - APAC
The Compliance Engineer will maintain APAC compliance certifications, conduct security risk assessments, support enterprise customer and sales security requests, and automate compliance monitoring across cloud environments. Experience with regulated industries, audits, public cloud compliance, and APAC privacy frameworks is required.
About the job
Responsibilities
- Maintain compliance certifications and frameworks relevant to the APAC region, including ISO 27001, the Australian Privacy Principles (APP), and Singapore’s PDPA.
- Shape the enterprise offering for regulated APAC industries, including finance, telecommunications, and government, with a focus on Australia, New Zealand, and Singapore.
- Build technical documentation demonstrating compliance throughout the technology stack.
- Support sales by responding to client security requests and managing compliance-related queries.
- Conduct risk assessments using CIS or ISO 27000 series frameworks, document findings, and help teams achieve compliance efficiently.
- Enhance compliance-as-code tooling to automate monitoring and reporting and reduce compliance friction.
Requirements
- Experience completing vendor security assessments and client security questionnaires in regulated APAC industries, including government, defense, and finance, particularly in Australia, New Zealand, or Singapore.
- Strong technical expertise in managing and executing compliance, with hands-on experience using compliance management tools such as Vanta.
- Experience maintaining and obtaining certifications while managing audit readiness and documentation.
- Ability to collaborate with sales, engineering, and legal teams to communicate compliance requirements and ensure smooth operations.
- Experience with public cloud compliance across AWS, Google Cloud, and Azure.
- Familiarity with integrating compliance tools into CI/CD pipelines to automate monitoring and reporting.
Benefits
- Annual discretionary professional development stipend.
- Annual discretionary social travel stipend.
- Annual company offsite.
- Monthly co-working stipend for employees outside main hubs.
Skills
ISO 27001, Australian Privacy Principles, Singapore Pdpa, Vanta, AWS, GCP, Azure, CI/CD, Cis Framework, Iso 27000
Similar jobs
Security Engineering jobsOwn and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
This remote Security Incident Response Engineer detects, investigates, and resolves security incidents while improving automation, documentation, and detection capabilities. The role requires SIEM and cloud experience, Python skills or willingness to learn, and an interest in forensic investigations.
Investigates trust and safety issues while managing legal requests, anti-abuse operations, and sensitive escalations. The role requires 3–5 years of relevant ISP or hosting-provider experience, DNS knowledge, and strong collaboration and communication skills.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.