SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Analyst, APAC

Rogo - Singapore, Singapore - In-office - posted 2026-09-07

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Rogo is an enterprise AI company transforming financial workflows for investment banks, private equity funds, and investment firms. The company has achieved product-market fit with a rapidly growing global client base and backing from world-class investors. As a GRC Analyst supporting APAC, you will be the central point of contact for Rogo's customer trust, security assurance, and compliance programs as the company scales globally. You'll work cross-functionally with security, engineering, legal, and go-to-market teams to ensure Rogo's controls, risk posture, and security practices are clearly communicated to customers, partners, and internal stakeholders. Key responsibilities include: supporting customer-facing security assurance processes and responding to customer security inquiries and risk assessments; serving as the primary contact for customer security reviews and providing accurate, consistent, timely responses; maintaining and improving security documentation and response materials aligned with current systems and controls; collaborating with security and engineering teams to translate technical controls into customer-facing language; supporting compliance initiatives across SOC 2, ISO 27001, ISO 42001, EU AI Act, UK Cyber Essentials, and GDPR frameworks; identifying themes and gaps from customer inquiries to drive continuous improvement; and helping scale trust-related workflows as customer volume and enterprise requirements grow. You should have experience supporting customer-facing security, compliance, or trust functions at SaaS or cloud-native companies, with strong ability to translate technical security concepts into clear written responses. Understanding of enterprise security expectations (cloud infrastructure, access control, data protection, incident response) is essential. You'll need strong attention to detail, ability to manage multiple parallel requests, clear communication with technical and non-technical stakeholders, and sound judgment with sensitive security questions. Bonus qualifications include experience with security questionnaires, audits, third-party risk assessments, cloud security (AWS/GCP, Kubernetes, IAM), scaling trust/GRC processes at growing organizations, enterprise customer support, and financial services security engagement.

Similar roles