job description
Join Respond.io as an IT Risk and Security Compliance Specialist and play a pivotal role in ensuring our systems and processes meet the highest standards of security and compliance. At Respond.io, compliance is not just about paperwork—it's an engineering discipline that drives trust and reliability in our platform.
As part of our dynamic team, you will work closely with cross-functional teams to identify risks, implement security measures, and ensure adherence to industry standards and regulations. This role is ideal for a detail-oriented professional who thrives in a fast-paced environment and is passionate about safeguarding digital assets.
Based in the vibrant locations of Canggu, Ubud, Denpasar, Jimbaran, Nusa Dua, Kuta, or Badung, you'll enjoy a collaborative work culture that values innovation, accountability, and continuous improvement.
Responsibility
- Develop, implement, and maintain IT security and compliance policies and procedures.
- Conduct regular risk assessments and audits to identify vulnerabilities and ensure compliance with industry standards (e.g., ISO 27001, GDPR, SOC 2).
- Collaborate with engineering and product teams to integrate security best practices into the development lifecycle.
- Monitor and respond to security incidents, ensuring timely resolution and documentation.
- Provide training and awareness programs to educate employees on security protocols and compliance requirements.
- Liaise with external auditors and regulatory bodies to facilitate compliance certifications and assessments.
- Maintain up-to-date knowledge of emerging threats, security trends, and regulatory changes.
- Prepare and present reports on compliance status, risks, and mitigation strategies to senior management.
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 3 years of experience in IT risk management, security compliance, or a similar role.
- Strong understanding of security frameworks and standards (e.g., ISO 27001, NIST, GDPR, SOC 2).
- Experience conducting risk assessments, audits, and security reviews.
- Familiarity with security tools and technologies (e.g., SIEM, IDS/IPS, vulnerability scanners).
- Excellent analytical, problem-solving, and communication skills.
- Relevant certifications (e.g., CISM, CISSP, CISA, ISO 27001 Lead Auditor) are a plus.
- Ability to work independently and collaboratively in a remote or hybrid environment.