SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior IT GRC

Timo - Ho Chi Minh City, Vietnam - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Timo is seeking a Senior IT GRC professional to build and maintain a robust Governance, Risk, and Compliance framework across Timo and Kredivo Group's fintech operations. This role sits at the intersection of security governance, risk mitigation, and regulatory alignment, with responsibility for ensuring all products, systems, and third-party partnerships meet international and Vietnamese regulatory standards. Key responsibilities include: • Regulatory Compliance Management: Monitor and maintain continuous compliance with Vietnamese Banking regulations and Personal Data Protection laws. • Audit & Assessment Coordination: Lead internal and external audit cycles, including regulatory inspections and critical compliance assessments (minimum annual cadence). • Governance & Policy Oversight: Conduct regular policy compliance monitoring, internal control reviews, and governance updates; continuously refine policies and procedures to ensure strict regulatory adherence. • International Standards: Prepare evidence and drive annual assessments to maintain PCI DSS Level 1 certification. • Identity & Access Governance: Lead comprehensive User Access Review (UAR) programs across internal and external core systems. • Third-Party Risk Management: Conduct comprehensive risk assessments and mitigation plans for all vendors and third-party partners. • Security Culture: Drive and plan security awareness training across business and technical units. You will report to the Infosec Lead and work closely with IT, engineering, and business stakeholders to drive systemic security resilience and protect Timo's digital banking platform and customers. Required qualifications: 3+ years hands-on IT Security GRC experience; proven track record implementing and assessing international governance frameworks (PCI-DSS, ISO-27001); experience in highly regulated, production-scale fintech, banking, or digital services environments; strong cross-functional collaboration skills. Required expertise: Deep practical knowledge of GRC frameworks and security audit methodologies; strong fundamental knowledge of network security, IAM, and enterprise security tools (Antivirus, Firewalls, SIEM, IDS/IPS, Cloud Security); strong vendor risk assessment capabilities; professional working English. Desired attributes: Proactive and highly responsible approach to compliance; pragmatic communication skills translating complex security regulations into actionable steps; exceptional analytical and structured thinking; professional security/auditing certifications (CRISC, CISA, CISM, CISSP, CGRC); prior SBV and MPS regulatory experience; cloud environment and automated GRC workflow experience. Hybrid arrangement: 4 days in Ho Chi Minh City office, 1 day remote.

Similar roles