DevSecOps Engineer (GRC)

Respond.io


Job Location:

Kuala Lumpur - Malaysia

Monthly Salary: Not Disclosed
Posted on: 12 hours ago
Vacancies: 1 Vacancy

Job Summary

Location: Kuala Lumpur Malaysia

Role: DevSecOps Engineer (GRC)

Department: Backend

About

Founded in Hong Kong in early 2017 is an AI-powered business messaging platform that helps companies manage customer conversations across chat calls and email all in one place.

Trusted by businesses in over 127 countries and recognized by G2 and SME100 enables fast-growing companies around the world to capture convert and retain customers at scale.

We operate as a globally distributed team with employees based around the world contributing to a diverse and inclusive culture. Join us and be part of a team that is shaping the future of customer conversation management!

Our Culture

At we move fast work smart and always keep our customers at the heart of what we do. Heres what we stand for:

  • Solve Customer Problems: Every effort must solve real customer pain points. No guessworkjust real feedback and clear value!
  • The 80/20 Rule: We focus on 20% of actions that create 80% of the value. Simple is powerfulit gets us moving fast.
  • 100% Alignment 80% Accuracy: We aim 100% team alignment and 80% accuracy. Perfect plans can waitclear goals come first.
  • Be Direct: We give honest feedback and tackle problems head-on. Clarity moves us forward!
  • Own It and Support Each Other: We step up help out and drive outcomestogether.
  • Build Human Connections: Work is better when we trust care and celebrate wins together. Were a team!

Role Description

At compliance is an engineering discipline not a paperwork exercise. We are hiring a DevSecOps Engineer (GRC) to own our governance layer end to end: our continuous compliance platform our external audit pipeline (ISO 27001 GDPR) SaaS vendor risk and enterprise customer trust. You will be the control owner and the primary audit subject for our security certifications and the translator who turns abstract framework controls into requirements our engineers can implement without confusion.

What You Will Be Doing

Continuous Compliance Architecture

  • Own scale and optimize our compliance automation platform.
  • Orchestrate automated evidence collection control validation and policy-to-framework mapping so evidence holds up in audit without manual scrambles.
  • Continuously verify endpoint fleet compliance scores and drive them up over time.
  • Apply AI-driven tooling to automate compliance checks control monitoring evidence collection and policy drafting.

Signal Routing & Operations

  • Monitor continuous compliance drift alerts; isolate and eliminate false positives so engineers only ever see real work.
  • Write tight well-scoped remediation issues and route them into engineering backlogs via Linear sized so a developer can pull one into a single cycle without clarification.
  • Track remediation milestones identify blockers and escalate early and clearly.

Governance & Enterprise Trust

  • Command our external audit pipeline: drive ISO 27001 and GDPR audits end to end (scoping auditor management evidence delivery findings remediation retest) and own our multi-month SOC 2 Type 2 readiness window.
  • Act as the control owner and main audit subject for our technology controls.
  • Serve as the technical expert behind enterprise customer security questionnaires and due-diligence reviews.
  • Run continuous security gap assessments against current and upcoming EU/US mandates to keep us ahead of regulation not behind it.

SaaS Vendor Risk Management

  • Gatekeep our third-party stack: run formal SaaS security vetting perform Data Privacy Impact assessments on incoming vendors and maintain the vendor risk register.
  • Author and maintain corporate governance and security policy definitions and keep policies synchronized with enforced configuration (the policy-to-configuration handshake).

Security Incident Response

  • Act as the regulatory and communication anchor during incidents: breach disclosure tracking (e.g. GDPR 72-hour constraints) post-mortem logging and external compliance reporting in partnership with the technical responder.

Qualifications

  • 3-5 years in GRC or security compliance roles with a proven track record implementing and maintaining ISO 27001 and GDPR and managing operational audit timelines for SOC 2 Type 2.
  • Compliance automation native: strong hands-on experience with API-driven platforms like Sprinto Drata or Vanta. You prefer live continuous evidence pipelines over manual screenshots and youve administered one at scale (ideally including a platform migration).
  • Technical fluency: you dont need to write production code but you must understand how modern microservice environments AWS IAM GitHub Actions CI/CD and identity layers (SSO/MFA) actually work so your controls stay pragmatic and enforceable.
  • Audit management: experience running external auditors end to end covering scoping evidence findings triage remediation tracking and cross-functional stakeholder engagement.
  • Masterful agile translator: the rare ability to read an abstract compliance control or rigorous enterprise requirement and turn it into a clear actionable well-scoped engineering issue.
  • Clear written and spoken English: able to hold your own with auditors enterprise customers security teams and backend engineers alike.
  • Certifications such as ISO 27001 Lead Auditor/Implementer CISA CRISC or CISSP.

Whats in it for you

  • You will become part of an amazing culture with smart collaborative teammates who actually care about each others growth and success.
  • You will grow more here than you would anywhere else that is a promise.
  • Virtual events like talent shows Among Us nights and online game sessions to keep the fun going no matter where you are!
  • We offer a highly competitive compensation package.
  • Youll receive a mental health allowance to support your health and wellness needs.
  • Flexible working environment and working hours that fit your lifestyle wherever youre based.

Required Experience:

IC

Location: Kuala Lumpur MalaysiaRole: DevSecOps Engineer (GRC)Department: BackendAbout Founded in Hong Kong in early 2017 is an AI-powered business messaging platform that helps companies manage customer conversations across chat calls and email all in one place.Trusted by businesses in over 127 co...

About Company

Company Logo

*Resume MUST be in English Location: EMEA Role: Partnerships Manager (EMEA) Department: Sales Mode: Full-time About Respond.io Founded in Hong Kong in early 2017, Respond.io is a pioneering Business Messaging platform that seamlessly unifies customer communication across instant messa ... View more

View Profile View Profile