SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Airwallex is a unified payments and financial platform serving over 250,000 global businesses. The Information Security team is seeking a Senior GRC Specialist to anchor governance, risk, and compliance efforts across the APAC region (Shanghai or Singapore base, largely remote).
In this role, you will be a trusted regional hub for the global Information Security team, acting as the primary contact for regulatory bodies, customers, partners, and vendors in your region. You will design and implement security policies and procedures that balance regional regulatory requirements with global industry standards, challenging traditional norms while maintaining compliance.
Key responsibilities include:
- Serve as the regional anchor for the security compliance team, focusing on APAC-specific regulatory requirements while integrating with global efforts
- Become a subject matter expert and trusted advisor to regulatory bodies and internal stakeholders
- Manage implementation and monitoring of security controls (PCI-DSS, ISO 27001, SOC2, and region-specific frameworks)
- Develop and maintain security documentation, policies, standards, reporting metrics, and audit evidence artifacts
- Implement AI and automation to streamline compliance work, reporting, and communications
- Execute security tasks hands-on while maintaining strategic oversight
You bring deep knowledge of compliance frameworks (PCI-DSS, ISO 27001, SOC2) and understand what makes successful information security audits. You have strong familiarity with InfoSec concepts and practices—either from a technical background or extensive collaboration with engineering teams. You're comfortable with policy creation and maintenance in security contexts, ideally with finance-industry or regional compliance expertise. You move fast with good judgment, embrace autonomy, and see compliance as an iterative challenge rather than a checkbox exercise. The role requires fluency in security language, project management skills, and the ability to balance speed with rigor.