L

Head of Security & Compliance

la voie • Indonesia
Visa Sponsorship Relocation
Apply
AI Summary

Lead trust, security, and compliance for a fast-growing B2B HRTech SaaS company. Manage a team of 3 and drive SOC 2 Type 2 compliance, security incident response, and sales enablement. 6+ years of experience in information security, trust & safety, or GRC required.

Key Highlights
Manage trust, security, and compliance posture of the company's platform
Drive SOC 2 Type 2 compliance and security incident response
Lead sales enablement through security questionnaires and RFI/RFP support
Key Responsibilities
Own the end-to-end account verification workflow (KYB) after subscription
Define and continuously improve fraud detection processes
Act as project manager for fraud detection automation
Technical Skills Required
Cloud infrastructure security Web application security SOC 2 Type 2 compliance
Benefits & Perks
Social Security
Comprehensive health insurance + telemedicine
15 days paid annual leave (pro-rated)
Nice to Have
Experience with KYB/KYC processes
Familiarity with privacy regulations (GDPR, PDPA, CCPA)
Professional certifications (CISM, CISSP, CISA)

Job Description


Work Conditions

  • Location: Bangkok, Thailand (on-site, city-center office)
  • Type: Full-time
  • Relocation support available: flight reimbursement (post-probation), 7 days paid accommodation on arrival, visa & work permit sponsorship
  • Benefits: Social Security, comprehensive health insurance + telemedicine, 15 days paid annual leave (pro-rated), ~13 national holidays, 2 weeks/year work-from-anywhere (post-probation), monthly new-hire & birthday lunches, personal development allowance



Company Overview

This role is with a La Voie client — a fast-growing B2B HRTech SaaS company headquartered in Bangkok, Thailand. The company builds AI-powered recruitment technology trusted by thousands of businesses across 135+ countries, and is backed by top-tier global venture capital investors. It's one of the fastest-growing B2B SaaS startups in the APAC region.


The Role

Reporting to the CTO, the Head of Security & Compliance owns the trust, security, and compliance posture of the company's platform. This is a cross-functional leadership role spanning trust & safety operations (KYB, fraud detection, platform abuse), security compliance (SOC 2, penetration testing, bug bounty), IT management, and sales enablement through security questionnaires and RFI/RFP support.

The role manages a team of 3 and acts as the primary interface between security/trust operations and the engineering organization. The candidate is not expected to write code but must be technical enough to define automation projects, write clear requirements, and hold productive conversations with engineers — while also partnering with sales and finance teams to help clients feel confident in the company's security posture.


Job Responsibilities & Requirements

Responsibilities:

Trust & Safety

  • Own the end-to-end account verification workflow (KYB) after subscription, ensuring legitimate use of the platform
  • Define and continuously improve fraud detection processes: fraudulent job postings, general abuse, and misuse
  • Act as project manager for fraud detection automation — define requirements, timelines, and deliverables with Engineering
  • Establish and maintain Trust & Safety policies, escalation paths, and response playbooks

Security & Compliance

  • Own and drive SOC 2 Type 2 compliance: audit preparation, evidence collection, control monitoring, remediation tracking
  • Orchestrate the penetration testing program end-to-end: vendor selection, scoping, tooling setup, intake of findings into Jira, report negotiation, remediation coordination
  • Orchestrate the bug bounty program: vendor management, triage workflow, severity assessment coordination, remediation tracking
  • Own security incident response for non-product incidents (data breaches, unauthorized access, credential compromise) — product availability incidents remain with Engineering
  • Proactively identify security risks and implement mitigation strategies that balance security with operational velocity

Sales Enablement

  • Directly answer complex or non-standard questions requiring deep knowledge of the company's security posture
  • Lead technical response for security questionnaires, RFIs, and RFPs as subject matter expert supporting enterprise sales cycles

IT Management

  • Manage the IT function (helpdesk, device management, access control, internal tooling)
  • Define and oversee lifecycle management of all company IT assets, ensuring hardware/software inventory is secure, tracked, and compliant
  • Ensure IT-related policies and operations align with SOC 2 and broader security requirements

Culture & Cross-Functional Collaboration

  • Partner with Engineering to scope and prioritize security and trust-related automation projects
  • Provide security input during product and architecture reviews when trust or compliance implications exist
  • Foster a culture of security awareness across departments through training and clear policy definitions
  • Report on trust, security, and compliance posture to the CTO on a regular cadence

Requirements:

  • 6+ years of experience in information security, trust & safety, or GRC, including 2+ years in a leadership role within a technology company
  • Hands-on experience owning a SOC 2 Type 2 program (audit prep, evidence collection, remediation tracking)
  • Experience managing external security vendors (penetration testing firms, auditors, bug bounty platforms)
  • Ability to define security/trust workflows and translate them into actionable engineering projects
  • Strong understanding of cloud infrastructure security and web application security
  • People management experience
  • Excellent English communication skills, written and verbal — will negotiate with vendors, write policies, and interface with clients
  • Technical fluency: able to read a vulnerability report, understand API-level risks, and write engineer-actionable requirements

Nice to have:

  • Experience with KYB/KYC processes
  • Familiarity with privacy regulations (GDPR, PDPA, CCPA)
  • Professional certifications (CISM, CISSP, CISA)
  • Familiarity with compliance automation tools (Vanta, Drata, or similar)
  • Background in recruitment technology or HR tech

Tech stack exposure: AWS, Kubernetes, ArgoCD, GitHub Actions, Terraform; Python (Django, FastAPI); PostgreSQL, MongoDB, ElasticSearch, Redis; Celery, RabbitMQ


Hiring Process

  1. Introduction interview with HR team
  2. Introduction interview with CTO and/or Director of Engineering
  3. Technical interview with technical assessment
  4. Cultural fit interview with top management team

Similar Jobs

Explore other opportunities that match your interests

APAC Travel Security Manager

Cyber Security
•
19h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

OpenAI

Singapore

System Security Engineer II – Embedded Product Cybersecurity

Cyber Security
•
19h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Collins Aerospace

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

coretech security

United Kingdom

Subscribe our newsletter

New Things Will Always Update Regularly