Lead and perform technology risk assessment and security compliance activities for global operations.
Coordinate annual internal and external IT audits for ISO and SOC 2 certifications across key markets to support onboarding and regulatory readiness.
Run regulator-mandated employee security awareness training globally and report on progress.
Automate evidence collection and compliance workflows to scale operations.
Identify compliance gaps, support remediations, and provide technical guidance across business units.
Requirements
2-5 years in information security, privacy, IT audit, or IT risk management.
Experience conducting IT internal and/or external audits (ISO 27001, ISO 27701, ISO 22301, ISO 42001, SOC 1, SOC 2, PCI-DSS, SOX) and with cloud technologies and data protection or equivalent certifications/regulations.
Experience running compliance training programs for a global workforce.
Hands-on experience with evidence collection automation or compliance workflow tooling; AI tooling is a strong advantage.
Experience with external auditors/regulators and regulator relationships; understanding global regulatory frameworks (GDPR, DORA, CFTC, MiCA, HKMA, HK SFC). for information security/privacy frameworks to meet local requirements.