This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Governance Risk and Compliance Specialist here at Airwallex, you will be a trusted member of the Information Security team. Reporting to the InfoSec GRC Manager, this role will see you becoming a critical part of Airwallex’s global mission, helping to proactively identify and mitigate information security risks to the organisation, as well as designing and implementing policies and procedures that are innovative, challenging the traditional norms of the industry. You’ll work closely with Legal, Engineering, and senior leadership regarding international regulatory compliance, data privacy and other aspects of risk and data governance.
Job Responsibility:
Manage the body of security controls and documentation
Implement automation and monitoring information security controls, exceptions, risks, and testing
Implement an innovative security risk program that aligns to regulatory requirements
Develop and maintain security standards and policies, reporting metrics, dashboards, and evidence artefacts
Develop resources to help non-technical employees understand information security and compliance requirements
Partner with other Airwallex teams to build collaboration, and establish shared responsibilities and resources for security, data protection and governance, risk management, and privacy
Requirements:
Deep knowledge of relevant compliance, regulatory and control frameworks including PCI-DSS, ISO 27001, SOC2 and similar standards
Involved in at least one completed security audit
Working knowledge of technology policy creation and maintenance
A strong familiarity with Information Security concepts, practices, and solutions
A working understanding of complex cloud environments
An understanding of financial services or payments, especially prior work experience with the fintech industry
A passion for solving the complex challenges of high-growth startups
An industry-leading security degree or certification is highly desired (e.g., BS or MS in Cybersecurity
or a CISSP, CEH, CISA)
Professional or native level of Portuguese language skills
Nice to have:
Engineering experience of any kind
Software development or IT background
Experience in project management and robust design