About this role
About the Role Join Honest as an IT GRC Specialist to build a secure, compliant, and resilient technology environment. You’ll be at the forefront of governance, risk management, and regulatory compliance, partnering with teams across the organization to strengthen controls, manage IT risks, support audits, and ensure adherence to industry regulations. What You'll Do
- Lead annual audits including PCI-DSS, ISO 27001, and regulator-specific audits.
- Draft and maintain IT policies and procedures aligned with ISO 27001 and local regulations.
- Produce monthly cybersecurity Key Risk Indicators (KRI) and tell the story of our cyber risk posture to stakeholders.
- Own our security culture by managing and conducting annual cybersecurity training and running phishing campaigns.
- Identify IT risks before they become problems and advise on mitigations with key stakeholders.
- Enforce IT governance by coordinating with stakeholders to follow proper processes such as incident lessons learned and annual user access reviews.
- Review vendors and partners to ensure their security standards match ours. What We're Looking For
- Framework knowledge: ISO, NIST, PCI-DSS.
- Audit experience in high-stakes environments including regulatory audits, PCI-DSS, or ISO 27001.
- Meticulous attention to detail in risk assessments.
- Strong communication skills; ability to translate compliance or technical terms into plain English.
- English proficiency to collaborate with diverse multinational teams. Compensation & Benefits
- ESOP for all employees.
- Training course and book subsidies.
- Opportunity to work with some of the sharpest people in the industry.
- Top-of-the-line medical healthcare plan.
- Monthly wellness allowance.
- Be part of one of the best-funded startups in Southeast Asia, backed by Silicon Valley investors.
- No titles or hierarchy; a culture of contribution and collaboration.