← All open roles
ThailandTechnologyFull-time🏢 Onsite

Head of Security & Compliance (SaaS/HRTech)

📍 BangkokPosted Today
B2B SaaSInfrastructure SecurityInformation SecurityGRC
🔒

Confidential search. The hiring company's name is not disclosed at this stage. iKonnect will share full details after an initial screening call.

About the company

A fast-growing B2B HRTech SaaS company headquartered in Bangkok, Thailand, building AI-powered recruitment technology trusted by thousands of businesses across 135+ countries. The company is one of the fastest-growing B2B SaaS startups in the APAC region, backed by top-tier global venture capital investors. The platform serves enterprise clients globally and operates at the intersection of AI, talent acquisition, and workforce technology.

The role

Reporting directly to the CTO, the Head of Security & Compliance owns the trust, security, and compliance posture of the company's platform. This is a cross-functional leadership role spanning trust & safety operations (KYB, fraud detection, platform abuse), security compliance (SOC 2, penetration testing, bug bounty), IT management, and sales enablement through security questionnaires and RFI/RFP support.

The role manages a team of 3 and acts as the primary interface between security/trust operations and the engineering organization. The successful candidate is not expected to write code but must be sufficiently technical to define automation projects, write clear requirements, and hold productive conversations with engineers — while also partnering with sales and finance teams to help clients feel confident in the company's security posture.

Key areas of ownership include end-to-end account verification workflows (KYB), fraud detection and platform abuse prevention, SOC 2 Type 2 compliance, penetration testing and bug bounty program orchestration, security incident response for non-product incidents, IT function management, and enterprise sales enablement through security questionnaire responses and RFP/RFI support.

The role also carries a cultural mandate: fostering security awareness across departments, providing security input during product and architecture reviews, and reporting on the overall trust, security, and compliance posture to the CTO on a regular cadence.

What we're looking for

• 6+ years of experience in information security, trust & safety, or GRC, including 2+ years in a leadership role within a technology company

• Hands-on experience owning a SOC 2 Type 2 program (audit preparation, evidence collection, remediation tracking)

• Experience managing external security vendors including penetration testing firms, auditors, and bug bounty platforms

• Ability to define security and trust workflows and translate them into actionable engineering projects

• Strong understanding of cloud infrastructure security and web application security

• People management experience

• Excellent English communication skills, written and verbal — able to negotiate with vendors, write policies, and interface with enterprise clients

• Technical fluency: able to read a vulnerability report, understand API-level risks, and write engineer-actionable requirements

Nice to Have:

• Experience with KYB/KYC processes

• Familiarity with privacy regulations (GDPR, PDPA, CCPA)

• Professional certifications (CISM, CISSP, CISA)

• Familiarity with compliance automation tools such as Vanta, Drata, or similar platforms

• Background in recruitment technology or HR tech

• Tech stack exposure: AWS, Kubernetes, ArgoCD, GitHub Actions, Terraform; Python (Django, FastAPI); PostgreSQL, MongoDB, ElasticSearch, Redis; Celery, RabbitMQ

What we offer

• On-site role based in a city-center office in Bangkok, Thailand

• Relocation support: flight reimbursement (post-probation), 7 days paid accommodation on arrival, visa and work permit sponsorship

• Comprehensive health insurance including telemedicine coverage

• Social Security contributions

• 15 days paid annual leave (pro-rated) plus approximately 13 national holidays

• 2 weeks per year work-from-anywhere flexibility (post-probation)

• Personal development allowance

• Monthly new-hire and birthday lunches

• Clear and structured hiring process: HR introduction → CTO/Director of Engineering interview → Technical assessment → Cultural fit interview with senior leadership

• Opportunity to own and shape the entire security and trust function at a high-growth APAC SaaS company, reporting directly to the CTO

How to apply

Apply directly below, or reach out to our team. We review all applications personally.

job.json
{
"location": "Bangkok",
"country": "Thailand",
"sector": "Technology",
"type": "Full-time",
"workStyle": "Onsite",
"package": "THB 200,000 Gross (Negotiable)",
"posted": "Today"
}

Related jobs

Engineering Lead

VietnamTechnology

$60–80K

Senior Product Manager

ThailandTechnology

Competitive package