Staff GRC Specialist, APAC
Singapore
About Airwallex
Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 250,000 businesses worldwide – including Brex, Rippling, Navan, Qantas, SHEIN and many more – with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale.
Proudly founded in Melbourne, we have a team of over 2,300 of the brightest and most innovative people in tech across 27 offices around the globe. Valued at US$11 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you’re ready to do the most ambitious work of your career, join us.
Attributes We Value
We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you’re motivated by our mission and operating principles. You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor.
You're humble and collaborative; turn zero‑to‑one ideas into real products, and you “get stuff done” end-to-end. You use AI to work smarter and solve problems faster. Here, you’ll tackle complex, high‑visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let’s build what’s next.
About the team
Airwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data, and employees while enabling the business to move quickly. The team helps build and maintain strong security practices across the company—from secure product and infrastructure design to risk reduction, incident response, audits, and compliance—so security is built into how we operate, not treated as a blocker.
What you'll do
As an INFOSEC Governance Risk and Compliance Regional Specialist at Airwallex, you will be a trusted member of the Information Security team. Reporting to the Senior GRC Manager, this role will see you becoming a critical part of Airwallex’s global mission, acting as a regional hub for the team while proactively working as part of the global department. You will be named as a regional contact for government or regulatory bodies, and must be comfortable speaking with those entities and delivering information as required. You will help to design and implement policies and procedures that challenge the traditional norms of the industry, while still meeting the set standards of the region and the global industry; the best candidates will embrace and balance that conflict.
You’ll work largely remotely, coordinating with the rest of Information Security as well as with other teams across the enterprise, to cover international regulatory compliance, data privacy, risk, and other aspects of security governance. Both engineering and legal experience will serve you well; this role would be best suited for someone with an IT engineering or technology-focused legal background, who has moved into the world of information security compliance and retains some practical security skills. You will execute necessary security tasks in your region; a great candidate will be eager to jump in and get their hands on the work.
This is a dynamic and independent role which will anchor a geographic region for the Security team, supporting individual regional entities as well as the greater global team. The role will require a great deal of autonomy and self-reliance, leveraging your experience in project management without being tied up in traditional solutions and methodologies. An ideal candidate will see compliance and security as a challenge to iterate on, rather than a box to be checked.
This role can be based in "Shanghai" and "Singapore".
Responsibilities
Act as a regional anchor for the security compliance team, focusing your efforts and communications first on the requirements specific to your designated regions, while integrating to the global effort.
Become a trusted contact for regulatory bodies, customers, partners, and vendors; control external perception of the security of the enterprise
Manage the implementation and monitoring of security controls, executing to a high standard while always refining and iterating.
Implement AI and other automation wherever possible to streamline everyday compliance and security work, including reporting and communications.
Develop and maintain security documentation; including standards and policies, reporting metrics, dashboards, and evidence artefacts to support both internal and external stakeholders
Become a subject matter expert, relied upon by Airwallex teams as a regional expert and a generalist
Who you are
Minimum qualifications
Deep knowledge of relevant compliance, regulatory and control frameworks such as PCI-DSS, ISO 27001, SOC2 and similar standards. You should understand what makes for a successful information security audit, and be intimately familiar with their process. Knowledge of security compliance specific to the finance industry or your geographic region is highly valued.
A strong familiarity with Information Security concepts, practices, and solutions; you might have a technical background yourself, or just have spent a lot of time working closely with engineering teams. Regardless, tech doesn’t scare you and you can speak the language fluently.
Working knowledge of policy creation and maintenance, especially in the context of security. Some experience with tuning policies to meet complex regulatory requirements.
A working understanding of complex cloud environments and the way they impact modern security and compliance operations.
An understanding of financial services or payments, especially prior work experience with the fintech industry.
A passion for solving the complex challenges of high-growth startups, and for thinking creatively about ‘solved’ problems.
Preferred qualifications
6+ years of cybersecurity experience. Proven experience working and executing independently, and experience working in the fintech industry specifically, are highly desired.
An industry-leading security degree or certification is a great benefit. Examples include a BS or MS in Cybersecurity; or a CISSP, CEH, CISA, etc.
Applicant Safety Policy: Fraud and Third-Party Recruiters
To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @airwallex.com email address. Please apply only through careers.airwallex.com or our official LinkedIn page.
Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary.
Equal opportunity
Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don’t regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know.